What problem does it solve?
Prevents overly flat, permissive network designs by evaluating whether segmentation and trust boundaries truly enforce NIST SP 800-207 (Zero Trust Architecture) and CIS Controls v8 Control 12.
Core Features & Use Cases
- Structured segmentation assessment: Maps zones, trust boundaries, and enforcement points to identify where implicit trust or bypass paths exist.
- East-west and micro-segmentation evaluation: Reviews intra-zone controls, workload isolation, and readiness for policy enforcement.
- DMZ and PCI CDE validation: Checks DMZ architecture soundness and verifies PCI DSS v4.0 Requirement 1.3-style CDE segmentation expectations.
Use case: reviewing a cloud VPC, Kubernetes network policies, or an on-prem VLAN/DMZ design after a change (or suspected lateral movement) to produce a prioritized set of segmentation gaps and fixes.
Quick Start
Run the segmentation skill against the relevant network configuration directory to generate a maturity assessment and remediation plan.