Microsegmentation
Finer network division at workload or application level, not just VLANs.
Term
description · examples · notesFiner network division at workload or application level, not just VLANs.
Description
Defines communication policies between individual services and processes.
Prevents lateral movement even within the same network segment.
Implemented via software (SDN) or host-based firewalls.
Key element of zero-trust architecture for data center and cloud.
What people often say
- Differs from network-segmentation: micro is per-workload, macro is per-VLAN/subnet.
- Implementation requires prior mapping of communication flows — cannot be turned on overnight.
Covers / does not cover
Covers
- Granular east-west traffic control
- Per-workload security policies
- Communication flow visualization
Does not cover
- North-south protection (that is firewall/WAF)
- Endpoint malware protection
- Traffic encryption (that is a separate control)
Mentioned in the news
Threats
reduces 3Threats it reduces. Select one to open its page.
Techniques
neutralizes 5Techniques it neutralizes. Select one to open its page.