# SP-017 Secure Network Zone Module

Status: active. Release 26.02. Modified 2026-02-07. Licence: CC BY-SA 4.0.

Scope: Network segmentation and zone architecture module covering trust boundary design, micro-segmentation, firewall rule management, east-west traffic controls, zone classification, inter-zone policy enforcement, and network access control. Addresses the architectural foundation for containing lateral movement, enforcing least-privilege network access, and providing the segmentation layer that supports Zero Trust and...
Use when: This pattern applies to every organisation with more than a trivially small network. It is particularly critical for: organisations with regulatory segmentation requirements (PCI DSS requires network segmentation for scope reduction), financial services firms where regulators expect defence-in-depth network architecture, organisations running mixed-trust workloads on shared infrastructure (production and...
Not when: Very small organisations (under 20 devices) may not need formal zone architecture -- a single flat network with endpoint protection and cloud-based security may suffice.

## Controls (23, NIST SP 800-53 ids)
- Critical (5): AC-04, CM-03, SC-07, SC-32, SI-04
- Important (14): AC-17, AU-02, AU-06, CA-07, CM-02, CM-06, CM-08, IA-03, IR-04, PL-08, RA-03, SA-08, SC-03, SC-08
- Standard (4): IA-02, PL-02, PM-11, SA-09

## What each critical control mitigates (5)
- AC-04 Information Flow Enforcement: T-NZ-001, T-NZ-003, T-NZ-006, T-NZ-007
- CM-03 Configuration Change Control: T-NZ-006
- SC-07 Boundary Protection: T-NZ-001, T-NZ-002, T-NZ-003, T-NZ-004, T-NZ-005, T-NZ-007, T-NZ-008, T-NZ-009, T-NZ-010
- SC-32 System Partitioning: T-NZ-001, T-NZ-002, T-NZ-010
- SI-04 System Monitoring: T-NZ-001, T-NZ-002, T-NZ-003, T-NZ-004, T-NZ-007

## Threats and the controls that mitigate them (10)
- T-NZ-001 Lateral movement across flat network after initial compromise: SC-07, AC-04, SC-32, SI-04
- T-NZ-002 Ransomware propagation across unsegmented network encrypting entire environment: SC-07, SC-32, SI-04, IR-04
- T-NZ-003 Data exfiltration from data tier directly to internet due to missing egress controls: AC-04, SC-07, AU-02, SI-04
- T-NZ-004 Rogue device placement on privileged network zone: IA-03, CM-08, SC-07, SI-04
- T-NZ-005 Management plane compromise via unrestricted management access: SC-07, SC-03, AC-17, AU-02
- T-NZ-006 Firewall rule bloat creating unintended connectivity paths between zones: CM-03, CM-06, AC-04, CA-07
- T-NZ-007 Zone bypass through application-layer tunnelling (HTTP tunnels, DNS exfiltration): SC-07, SI-04, AC-04, AU-06
- T-NZ-008 Cloud security group misconfiguration exposing internal services to internet: CM-02, CA-07, SC-07, CM-06
- T-NZ-009 VLAN hopping or other layer-2 attacks crossing zone boundaries: SC-07, CM-06, SC-08, IA-03
- T-NZ-010 Compliance scope expansion due to inadequate network segmentation (PCI, SWIFT): SC-07, SC-32, PL-02, RA-03

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-017/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-017/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 30 KB: /api/v1/patterns/SP-017
- Page for people: /patterns/sp-017/
- Related: SP-016 DMZ Module; SP-023 Industrial Control Systems; SP-029 Zero Trust Architecture; SP-031 Security Monitoring and Response; SP-015 Secure Remote Working

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
