In this ultimate how to audit guide to ISO 27001 Annex A 8.22 Segregation of Networks, you will learn directly from an ISO 27001 Lead Auditor:
- 10 Key Audit Steps
- Verification Criteria
- Required Evidence
- The Pass / Fail Test
I am Stuart Barker, the ISO 27001 Lead Auditor and author of the Ultimate ISO 27001 Toolkit.
Using over 30 years of industry experience across hundreds of audits, I’m giving you the exact templates, walkthroughs, and practical examples you need to achieve ISO 27001 certification.
Table of contents
- ISO 27001 Annex A 8.22 Segregation of Networks Audit Checklist
- 1. Network Segregation Policy Formalisation Verified
- 2. Logical Zone Isolation via VLANs Confirmed
- 3. Perimeter Segregation (DMZ) Integrity Validated
- 4. Wireless Network Traffic Segregation Verified
- 5. Micro-segmentation for Critical Assets Confirmed
- 6. Cross-Zone Traffic Filtering (ACLs) Validated
- 7. Management Network Segregation Verified
- 8. Third-Party/Contractor Network Segregation Confirmed
- 9. Cloud VPC/VNet Isolation Validated
- 10. Periodic Segregation Efficacy Audits Recorded
ISO 27001 Annex A 8.22 Segregation of Networks Audit Checklist
Auditing ISO 27001 Annex A 8.22 Segregation of Networks is the technical verification of traffic isolation and boundary protection mechanisms within the organisational infrastructure. The Primary Implementation Requirement is the logical or physical separation of security zones, providing the Business Benefit of preventing lateral threat movement and protecting sensitive information assets from unauthorised access.
This technical verification tool is designed for lead auditors to establish the security integrity of network boundaries and traffic isolation. Use this checklist to validate compliance with ISO 27001 Annex A 8.22.
1. Network Segregation Policy Formalisation Verified
Verification Criteria: A documented policy or architectural standard exists defining the criteria for segregating networks into distinct security zones based on risk, business function, and data sensitivity.
Required Evidence: Approved Network Architecture Standard or Segregation Policy with defined trust boundaries.
Pass/Fail Test: If the organisation cannot produce a formal document defining the logical or physical boundaries of its network zones, mark as Non-Compliant.
2. Logical Zone Isolation via VLANs Confirmed
Verification Criteria: Logical segregation is implemented using Virtual Local Area Networks (VLANs) to separate functional departments and sensitive asset classes (e.g., HR, Finance, Production).
Required Evidence: Running configurations from core and distribution switches showing defined VLAN IDs and associated port assignments.
Pass/Fail Test: If critical servers and general staff workstations reside on a single, unsegmented “flat” network, mark as Non-Compliant.
3. Perimeter Segregation (DMZ) Integrity Validated
Verification Criteria: Public-facing services (Web, Mail gateways) are isolated within a Demilitarised Zone (DMZ), preventing direct external access to the internal trusted network.
Required Evidence: Firewall rule base and topology diagrams showing three-pronged or back-to-back firewall architecture isolating the DMZ.
Pass/Fail Test: If a public-facing web server has direct, unfiltered routing to the internal production database, mark as Non-Compliant.

