Validate trust zones
Confirm that user, server, management, guest, cloud, OT and restricted networks have the intended access boundaries.
Damocles Network Segmentation Review maps trust zones, routing, firewall enforcement and management paths to determine whether users, servers, cloud, OT, guest and restricted networks can communicate beyond the intended design.
Segmentation fails when the security boundary exists in documentation but routing, NAT, firewall rules, management networks or dual-homed systems create a bypass. It can also fail operationally when a technically strong boundary has no practical support path and is later weakened through exceptions.
Damocles maps the intended trust model and compares it with the effective traffic paths so the customer can see which boundaries are missing, porous or difficult to operate safely.
Confirm that user, server, management, guest, cloud, OT and restricted networks have the intended access boundaries.
Identify routing, NAT, dual-homing, management or policy conditions that circumvent the intended control.
Balance least privilege with support, monitoring, patching and operational requirements so the control remains maintainable.
The engagement can be focused on one sensitive environment or cover broader enterprise segmentation.
Corporate user, wireless, VDI and other user-access networks.
Application, database, infrastructure and shared-service networks.
Administrative, monitoring, backup and infrastructure-management paths.
Operational technology, SCADA, regulated or specially protected networks where applicable.
Cloud routing, private connectivity, VPN and network-security boundaries included in scope.
Guest, vendor, contractor and third-party paths into or across the environment.
Compare the intended trust model with routing, firewall policy, management access and representative traffic paths to identify missing boundaries and practical bypass paths.
Whether user, server, cloud, OT, guest and restricted environments are separated as intended.
Representative permitted and prohibited paths across key boundaries.
Routes, NAT and alternate forwarding paths that may bypass expected enforcement.
Administrative paths that cross intended trust boundaries.
Whether high-value services are reachable from locations that should not have access.
Temporary or compensating exceptions that weaken the intended model.
Whether monitoring, patching and administration can operate safely.
These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.
Damocles maps named systems and services to intended trust zones, data classifications and administrative boundaries.
Damocles compares the approved flow matrix with representative permitted source, destination, protocol and application paths.
Damocles traces each selected flow through firewall, ACL, host, cloud or identity-aware enforcement points.
Damocles examines routing and alternate paths that could bypass the intended boundary, including asymmetric return traffic.
Damocles accounts for source and destination NAT when correlating observed traffic with segmentation policy.
Damocles tests representative identity-aware decisions using supplied users, devices and expected policy context.
Showing 6 representative areas. The full governed matrix contains 12 coverage areas.
References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.
Testing is structured by the governed service profile and the procedures expressly included in the authorised scope.
Findings are reported against the governed service coverage and customer impact. Separate classification references are shown only where they are part of the approved profile.
Tests representative information-flow enforcement across selected trust boundaries using approved allowed and denied source-to-destination paths.
Reviews selected boundary architecture and enforcement points and validates representative paths across in-scope network boundaries.
Checks whether sampled boundary decisions produce usable security events with source, destination, protocol, action and policy context where logs are supplied.
+ 7 additional governed mappings in the full control matrix.
Jump to full control mapping ↓A clear segmentation map, validated traffic-path results, identified bypass conditions and prioritised remediation actions.
What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.
Damocles traces intended trust boundaries through routing and enforcement configuration and attempts approved allowed and denied paths from supplied source hosts. A tested path does not establish every possible route; scanning and traffic volume remain within agreed thresholds.
Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.
Initiates approved allowed and denied traffic from a representative trust zone.
Confirms the intended consumers, protocols and impact boundaries of sensitive destinations.
Traces routes, ACLs, firewall policy, NAT and identity-aware enforcement across each selected boundary.
| Coverage area | What Damocles tests | Perspective and access | Evidence produced | References and limits |
|---|---|---|---|---|
| Trust-zone definition | Damocles maps named systems and services to intended trust zones, data classifications and administrative boundaries. | Routing and enforcement-point reviewer Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for trust-zone definition. | Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to trust-zone definition. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Trust-zone definition when the boundary and representative source and destination are authorised. Limit: The conclusion is limited to the sampled trust-zone definition; only sampled paths are established; scanning volume and excluded zones remain bounded. |
| Permitted boundary flows | Damocles compares the approved flow matrix with representative permitted source, destination, protocol and application paths. | Source-zone test user or host Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for permitted boundary flows. | Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to permitted boundary flows. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Permitted boundary flows when the boundary and representative source and destination are authorised. Limit: The conclusion is limited to the sampled permitted boundary flows; only sampled paths are established; scanning volume and excluded zones remain bounded. |
| Rulebase enforcement points | Damocles traces each selected flow through firewall, ACL, host, cloud or identity-aware enforcement points. | Routing and enforcement-point reviewer Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for rulebase enforcement points. | Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to rulebase enforcement points. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Rulebase enforcement points when the boundary and representative source and destination are authorised. Limit: The conclusion is limited to the sampled rulebase enforcement points; only sampled paths are established; scanning volume and excluded zones remain bounded. |
| Routing and alternate paths | Damocles examines routing and alternate paths that could bypass the intended boundary, including asymmetric return traffic. | Routing and enforcement-point reviewer Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for routing and alternate paths. | Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to routing and alternate paths. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Routing and alternate paths when the boundary and representative source and destination are authorised. Limit: The conclusion is limited to the sampled routing and alternate paths; only sampled paths are established; scanning volume and excluded zones remain bounded. |
| NAT effects on segmentation | Damocles accounts for source and destination NAT when correlating observed traffic with segmentation policy. | Source-zone test user or host Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for nat effects on segmentation. | Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to nat effects on segmentation. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to NAT effects on segmentation when the boundary and representative source and destination are authorised. Limit: The conclusion is limited to the sampled nat effects on segmentation; only sampled paths are established; scanning volume and excluded zones remain bounded. |
| Identity-aware access paths | Damocles tests representative identity-aware decisions using supplied users, devices and expected policy context. | Destination service owner Named source and destination test points, expected flow matrix and a safe test window; customer inputs must identify the approved identity-aware access paths targets and expected behaviour. | Source-to-destination results linked to rule, route or boundary evidence; the record names the tested identity-aware access paths object, path or control and its observed result. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when representative identities and the corresponding permission or ownership boundary are included in scope. Limit: Conclusions cover only the supplied identities, roles and records; credential guessing, lockout and privileged changes stop at the agreed thresholds. |
| East-west administrative protocols | Damocles attempts approved east-west management protocols between representative zones and records allowed and denied outcomes. | Source-zone test user or host Current configuration export or read-only access, diagrams, owners and representative validation endpoints. | Configuration excerpts, object or rule identifiers and observed validation results. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review. Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised. |
| Representative path validation | Damocles sends approved test traffic from actual source hosts to destination services and records the enforcement point and result. | Source-zone test user or host Named source and destination test points, expected flow matrix and a safe test window. | Source-to-destination results linked to rule, route or boundary evidence; the record names the tested representative path validation object, path or control and its observed result. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing. Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity. |
| Sensitive-zone reachability | Damocles tests named high-value destinations and forbidden protocols from representative lower-trust zones. | Source-zone test user or host Named source and destination test points, expected flow matrix and a safe test window. | Source-to-destination results linked to rule, route or boundary evidence; the record names the tested sensitive-zone reachability object, path or control and its observed result. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing. Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity. |
| Logging at boundaries | Damocles confirms whether boundary decisions create usable logs with source, destination, protocol, action and policy identity. | Routing and enforcement-point reviewer Log-source inventory, representative event identifiers, workflow records and responsible contacts. | Source-health state, event timestamps, investigation timeline and linked action or escalation record. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when the relevant telemetry and analyst or customer workflow can be observed during the review window. Limit: Absent or delayed telemetry prevents a detection conclusion, and observation of one event cannot prove continuous detection of all attacks. |
| Third-party and remote access | Damocles traces third-party and remote-access routes into internal zones and compares them with intended access restrictions. | Destination service owner Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for third-party and remote access. | Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to third-party and remote access. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Third-party and remote access when the boundary and representative source and destination are authorised. Limit: The conclusion is limited to the sampled third-party and remote access; only sampled paths are established; scanning volume and excluded zones remain bounded. |
| Exceptions and compensating controls | Damocles records segmentation exceptions, owners, expiry, compensating controls and validation evidence. | Source-zone test user or host Assessment requires trust-zone definitions, flow matrix, routing and policy exports, source hosts and destination test services, selected specifically for exceptions and compensating controls. | Evidence records the flow, enforcement point, route, NAT, policy, log or allowed/denied connectivity result relevant to exceptions and compensating controls. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Exceptions and compensating controls when the boundary and representative source and destination are authorised. Limit: The conclusion is limited to the sampled exceptions and compensating controls; only sampled paths are established; scanning volume and excluded zones remain bounded. |
| Framework and controls | Mapping type | What Damocles assesses | Evidence produced | Applicability and limits |
|---|---|---|---|---|
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 AC-4 | Directly assessed | Tests representative information-flow enforcement across selected trust boundaries using approved allowed and denied source-to-destination paths. | Expected flow matrix, source and destination context, enforcement-point evidence and observed connectivity results. | Applies: Applies where representative trust zones, test hosts, destinations and expected flows are included. Limit: Only sampled paths are established; alternate routes, excluded zones and unsampled protocols remain outside the conclusion. |
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 SC-7 | Directly assessed | Reviews selected boundary architecture and enforcement points and validates representative paths across in-scope network boundaries. | Trust-zone and enforcement map, routes, firewall or ACL evidence, alternate-path observations and validated boundary results. | Applies: Applies to selected network boundaries and enforcement points within the authorised segmentation scope. Limit: Does not establish every network boundary, route, enforcement point or continuous boundary operation. |
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 AU-2AU-3 | Supporting evidence | Checks whether sampled boundary decisions produce usable security events with source, destination, protocol, action and policy context where logs are supplied. | Generated or observed test flows correlated to supplied boundary event records. | Applies: Applies only where relevant boundary logging is included and accessible. Limit: Does not establish complete logging policy, event content, retention, analysis or continuous monitoring coverage. |
| Information Security Manual June 2026 ISM-1181 | Directly assessed | Tests representative segregation between customer-defined network zones according to the supplied trust model and expected flow matrix. | Trust-zone map, approved source and destination test points, observed allowed and denied traffic results and enforcement evidence. | Applies: Applies where the organisation has defined network zones and representative paths are included for validation. Limit: Testing proves only sampled zone relationships and does not establish that every network segment or path satisfies ISM-1181. |
| Information Security Manual June 2026 ISM-0631 | Directly assessed | Where an in-scope boundary uses a gateway, tests whether representative gateway paths permit only explicitly authorised flows from the approved flow matrix. | Gateway policy identifiers, expected flow matrix and observed allowed or denied connectivity results. | Applies: Applies only to selected gateway-enforced boundaries with representative test points and authorised flow expectations. Limit: Does not establish every gateway data flow, non-gateway boundary or continuous conformity with ISM-0631. |
| Prudential Standard CPS 234 Information Security effective 1 July 2019 CPS 234 paragraph 27 | Supporting evidence | Produces scoped network segmentation-review evidence that may support an APRA-regulated entity's systematic testing of information-security control effectiveness. | Governed scope, trust-zone and enforcement evidence, sampled path results, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed segmentation controls and evidence are applicable to its assurance or compliance scope. For APRA-regulated entities, the customer determines how the engagement contributes to its broader systematic control-testing program. Limit: A scoped engagement does not by itself establish the customer's systematic testing program, testing frequency, full control population, specialist independence, governance, reporting or compliance with other CPS 234 requirements. |
| Prudential Practice Guide CPG 234 Information Security published June 2019 Framework-level context | Contextual | Produces scoped network segmentation-review evidence consistent with CPG 234 guidance that testing techniques should be selected for the control and risk being assessed. | Governed scope, trust-zone and enforcement evidence, sampled path results, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed segmentation controls and evidence are applicable to its assurance or compliance scope. APRA-regulated customers determine how this evidence contributes to their broader assurance program. Limit: CPG 234 is prudential guidance rather than a standalone certification target; this mapping does not claim assessment of the complete guidance or customer compliance. |
| ISO/IEC 27001 2022 with Amendment 1:2024 Framework-level context | Contextual | Produces scoped network segmentation-review evidence that may support customer assurance activities organised around ISO/IEC 27001 where the assessed systems and behaviours are relevant. | Governed scope, trust-zone and enforcement evidence, sampled path results, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed segmentation controls and evidence are applicable to its assurance or compliance scope. Limit: Licensed ISO/IEC 27001 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27001 certification, attestation or whole-framework conformity. |
| ISO/IEC 27002 2022 Framework-level context | Contextual | Produces scoped network segmentation-review evidence that may support customer assurance activities organised around ISO/IEC 27002 where the assessed systems and behaviours are relevant. | Governed scope, trust-zone and enforcement evidence, sampled path results, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed segmentation controls and evidence are applicable to its assurance or compliance scope. Limit: Licensed ISO/IEC 27002 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27002 certification, attestation or whole-framework conformity. |
| Payment Card Industry Data Security Standard 4.0.1 Framework-level context | Contextual | Produces scoped network segmentation-review evidence that may support customer assurance activities organised around PCI DSS where the assessed systems and behaviours are relevant. | Governed scope, trust-zone and enforcement evidence, sampled path results, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed segmentation controls and evidence are applicable to its assurance or compliance scope. Limit: Licensed PCI DSS control or requirement identifiers and text are intentionally withheld. The engagement does not establish PCI DSS certification, attestation or whole-framework conformity. |
Assurance boundary: Damocles maps assessed coverage and observations to agreed objectives as traceable technical evidence. The review is not a certification, does not establish complete compliance, and does not confirm controls outside the authorised scope.
Records authorised scope and rules of engagement produced from the authorised Network segmentation review work.
Records coverage matrix produced from the authorised Network segmentation review work.
Records retest and residual-risk record produced from the authorised Network segmentation review work.
Records trust-zone and enforcement map produced from the authorised Network segmentation review work.
Records allowed and denied path results produced from the authorised Network segmentation review work.
Records segmentation exception register produced from the authorised Network segmentation review work.
A clear segmentation map, validated traffic-path results, identified bypass conditions and prioritised remediation actions.
The review looks at both technical bypass and control designs that are unlikely to survive day-to-day operations.
Routing, NAT, direct links or dual-homing that circumvent the intended enforcement point.
Large network-to-network rules that provide more reach than the application or support requirement.
Administrative and infrastructure-management paths shared with lower-trust networks.
Paths between business IT, remote access, management and operational networks beyond the intended model.
Temporary rules and support exceptions that gradually erode the segmentation boundary.
A boundary that blocks necessary monitoring, patching, backup or support and therefore encourages insecure workarounds.
The scope identifies zones, routers, firewalls, cloud networks, critical applications and management dependencies.
Review business-to-OT, management, vendor and security-tool access around operational networks.
Review application, database, management and shared-service boundaries and east-west access.
Review on-premises-to-cloud and cloud-internal routing and enforcement boundaries.
Map and redesign broader trust zones across sites, data centres and cloud environments.
Outputs are suitable for security architecture and the network engineers who must implement the boundary.
Trust zones, routing domains, enforcement points and major cross-zone dependencies.
Unintended paths, broad access, management crossover and bypass conditions.
Required application and support flows used to distinguish legitimate access from excess reach.
Recommended trust zones, enforcement locations and access principles where redesign is included.
Sequenced changes based on risk, application dependency and operational complexity.
Traffic and access tests required to prove intended communication works and prohibited paths are blocked.
Implementation work identifies the affected firewalls, routers, security groups, routes, NAT, maintenance windows, application owners and rollback approach before production change.
Post-change validation checks both permitted business traffic and the boundaries the project was intended to enforce.
Full application dependency mapping, host hardening and endpoint security are separate services unless included because they are required to validate the segmentation design.
A design recommendation does not imply implementation unless production change is explicitly scoped.
We will scope the zones, routing, enforcement points, dependency information, target design and implementation support required.