CSA Zero Trust Microsegmentation Guidance - formalizes topology-defined vs. connection-defined segmentation modelshttps://www.reddit.com/r/netsec/comments/1wdaeny/csa_zero_trust_microsegmentation_guidance
Disclosure: I led this workstream at the Cloud Security Alliance. CSA published new guidance on Zero Trust Microsegmentation. Sharing here because the framing is more precise than most vendor material on this topic, and I think the model split is useful even if you disagree with parts of the paper. Core definition used throughout: a communication is "segmented" only if it's explicitly permitted, enforceable, observable, and governable over time - not just blocked by default or isolated by network position. Two models, formally separated: Topology-defined segmentation: enforcement based on netβ¦