What is network segmentation?
Network segmentation divides a network into isolated zones so that traffic between them can be controlled. It limits how far an attacker can move after compromising one system, which is called lateral movement. In the cloud it is built with VPCs, subnets, and security groups.
What the buyer is really asking
If one part of your network is compromised, how far can an attacker move? Describe how production is separated from everything else and how tiers within production are split (public, application, database).
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you segment your network?”
- “Are databases reachable from the internet?”
- “Is the production network separated from corporate networks?”
Evidence to have ready
- A network diagram showing segments
- VPC, subnet, and security group configuration
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.