GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

INF-004 Network Segmentation

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Network environments are segmented to isolate systems by function and sensitivity. Production systems are isolated from development, test, and administrative networks. Tenant workloads are logically separated from one another. Segmentation is enforced at the network layer and is documented.

Rationale

Segmentation limits the blast radius of a network compromise and prevents lateral movement between environments or between tenants.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore

The tenant separation clause is the provider's. Segmentation of the deployer's own estate is its own.

GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore

The tenant separation clause is the provider's. Segmentation of the deployer's own estate is its own.

DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (11)

I&S-05Production and Non-Production Environmentsfull
I&S-06Segmentation and Segregationfull
I&S-05Production and Non-Production Environmentsfull
I&S-06Segmentation and Segregationfull
8.22Segregation of networksfull
NIS2-CIR-6.8Network Segmentationpartial
AC-4Information Flow Enforcementpartial
AC-4(21)Information Flow Enforcement | Physical or Logical Separation of Information Flowsfull
SC-32System Partitioninginformative
SC-7Boundary Protectioninformative
SC-7(21)Boundary Protection | Isolation of System Componentsfull

Evidence (2)

configurationtechnicalautomated

Network segmentation configuration showing production, development, test, and administrative environments are isolated at the network layer, and tenant workloads are logically separated.

Example: AWS VPC routing table, security group, and network ACL export; GCP VPC firewall rules export; or equivalent cloud network configuration showing environment isolation and inter-VLAN traffic restrictions

Test: Export network configuration from the cloud provider. Verify: (1) separate VPCs, subnets, or network zones exist for production, development, test, and admin; (2) security groups or firewall rules prohibit unrestricted lateral traffic between zones; (3) tenant isolation is implemented (separate VPCs, namespaces, or equivalent); (4) attempt to trace a permitted traffic path between production and dev, confirming that no default allow rule exists.

policydocumentmanual

Network segmentation policy or architecture document that specifies environment boundaries, tenant isolation requirements, and enforcement mechanisms.

Example: Network Segmentation Policy or Network Architecture Design document (version-controlled, approved within the last 12 months) with a network diagram showing defined trust zones

Test: Request the network segmentation policy and supporting architecture diagram. Verify: (1) the document defines trust zones and permitted traffic flows between zones; (2) tenant isolation requirements are explicitly stated; (3) the diagram reflects the current deployed architecture; (4) the document has been approved by an accountable owner within the last 12 months.

Questions (2)

boolean

Are production systems isolated from development, test and administrative networks at the network layer?

Isolation should be enforced via VPC boundaries, security groups, network ACLs, or equivalent cloud-native controls, not only by naming convention or access policy.

multi

Which mechanisms are used to enforce network segmentation between environments and between tenants?

Separate VPCs or virtual networks per environmentSecurity groups or network ACLs restricting inter-environment trafficSeparate cloud accounts or projects per environmentService mesh with mutual TLS for inter-service isolationNamespace-level isolation in KubernetesTenant-specific VPC or account per customerNone of the above

Multiple enforcement layers are expected for a strong segmentation posture. At minimum, expect separate network boundaries and explicit deny rules for cross-environment traffic.