Glossary

    Network Segmentation

    Network Security

    Network Segmentation is the practice of dividing your network into smaller, isolated segments to limit an attacker's ability to move laterally after an initial compromise. In AWS, this is implemented through VPCs, subnets, security groups, and NACLs.

    AWS Segmentation Strategies

    • Multi-VPC: separate VPCs for production, staging, development
    • Public/private subnets: internet-facing resources in public subnets, everything else in private
    • Multi-account: separate AWS accounts per workload or environment (strongest isolation)
    • Security groups: micro-segmentation at the instance level
    • Transit Gateway: controlled routing between VPCs

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.