NETWORK SEGREGATION
This is a valuable aspect of network security architecture. As the name implies, it is the principle of configuring networks in separate chunks where few machines / clients are connected on the same broadcast domain, while still accessing the same general network resources.
One main method of achieving this is implementation of (Virtual Local Area Network) VLAN technology with the associated inter-vlan routing protocols on the network.
This concept does not only improve the network security posture of the company but also increases the network access speed by optimizing the effects of multiple broadcast on a network system.
All employees, contractors, and anyone accessing company information systems must understand how to protect the CIA (Confidentiality, Integrity and Accessibility) of information and information systems of their company. As a result, companies will ensure that all employees and contractors are given security and privacy awareness training during the new hire process and before accessing any company information and or system.
The security method provided by network segregation provides logical ways to regulate the level of accessible information available to employees, contractors, and other individuals that may be given access to company network.
Guest network domains are often created for visitors with vitrually no access to the company information resources except for internet connection, since they are available only for a period of time.
All users are normally Authenticated, Authorized and Accountable for their network access activities.
Otherwise a malicious actor can use someone’s account as an entry point and transverse the network and this can lead to the dreaded privilege escalation attack with possibility of company’s CIA breach. With good network segregation configurations, your can restrict unnecessary communication to your finance department or any other section that may be attributed with high confidential rating.