N.4.09 Network segmentation
Control Overview
This control mandates that the organization establishes and strictly applies technical rules for segregating groups of users, information systems, and network-connected services. Network segmentation serves as a fundamental architectural barrier designed to enforce containment. By dividing a monolithic network structure into distinct, isolated compartments, the organization prevents the lateral movement of threat actors, protects high-value data environments, and limits the overall blast radius of a cyberattack.
Applicability Note: This control is fully applicable to the anDREa platform and represents a core architectural requirement for maintaining absolute separation between individual tenant data environments.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, utilizing software-defined boundaries to achieve strict logical isolation.
Because anDREa is a cloud-native platform running on Microsoft Azure, our network segmentation completely replaces traditional physical switches and routers with advanced virtual segregation mechanics. The architecture is engineered to split user traffic, administration pools, and analytical workspaces into distinct subnets, virtual networks (VNets), and isolated data planes protected by strict Network Security Groups (NSGs) and application-layer firewalls. This segmentation is baked directly into our automated tenant-provisioning deployment scripts, meaning a new research environment is logically sandboxed from the moment of creation. To ensure these boundaries are effective, we routinely validate our segregation rules through independent, third-party penetration testing.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.08.22 - Segregation of networks | Mandates that groups of information services, users, and information systems are segregated on the organization's networks. |
| Architectural Blueprint | myDRE Deployment & VNet Segmentation Schemas | Technical configuration files detailing automated network boundaries, subnet definitions, and default-deny routing paths. (myDRE Highlevel Architecture) |
| Security Validation | External Penetration Test Reports | Independent third-party audit findings confirming that lateral movement between separate client workspaces is completely blocked. Management Reports |
| Operational Governance | Tenant Security Gateways & Firewall Rules | Real-time connection constraints and access rule manifests showing active enforcement of data isolation. |
Audit Summary
- Compliance Status: Fully Compliant
- Gaps Identified: None. Automated software-defined isolation, multi-tenant VNet sandboxing, and routine external validation via penetration testing are fully operationalized and certified.