Cyber Resilience

← ISO 27001 Annex A

A.8.22 Technological

Segregation of networks

AttributesPreventiveC·I·AProtectSystem and network securityProtection

Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?

The implementation guidance for this control is published in ISO/IEC 27002:2022 and is not reproduced here. The structured attributes and the cross-walk rationales below are derived facts and our own AI-authored analysis.

Mapped NIST 800-53 r5 controls (14)

Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Aligned NIST CSF 2.0 outcomes (14)

NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related OWASP ASVS 5.0 requirements (10)

Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Related weaknesses / CWE (38)

Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Mitigated MITRE ATT&CK techniques (534)

Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

T1001←MT1001.001←MT1001.002←MT1001.003←M →PT1003→PT1003.003→PT1003.006→PT1003.008→PT1006←MT1008←M →PT1011←M →PT1011.001←M →PT1014←MT1016.001→PT1016.002→PT1018←M →PT1020←M →PT1020.001←M →PT1021←M →PT1021.001←M →PT1021.002←M →PT1021.003→PT1021.004←M →PT1021.005←M →PT1021.006←P →PT1021.007←MT1021.008←M →PT1027.002←MT1027.003←PT1027.006←MT1027.008←PT1027.010←MT1027.011←PT1027.014←MT1027.017←PT1029←MT1030←M →PT1036.003←MT1036.005←MT1036.008←MT1036.009←MT1036.012←MT1037.003←P →PT1039←M →PT1040→PT1041←M →PT1046←M →PT1047←M →PT1048←M →PT1048.001←M →PT1048.002←M →PT1048.003←M →PT1052←M →PT1052.001←M →PT1055←M →PT1055.001←MT1055.002←MT1055.003←M →PT1055.004←MT1055.005←MT1055.008←MT1055.009←MT1055.011←MT1055.012←MT1055.013←MT1055.014←MT1055.015←MT1059→PT1059.004→PT1059.007→PT1059.008←PT1059.009→PT1068←MT1070←MT1070.010←MT1071←M →PT1071.001←M →PT1071.002←M →PT1071.003←M →PT1071.004←M →PT1071.005←M →PT1072→PT1074→PT1074.001→PT1074.002←M →PT1078←P →PT1078.001←PT1078.002←P →PT1078.003←PT1078.004←MT1080←M →PT1090←M →PT1090.001←M →PT1090.002←M →PT1090.003←M →PT1090.004←MT1091←M →PT1092←M →PT1095←M →PT1098.001←MT1098.005←MT1102←M →PT1102.001←M →PT1102.002←M →PT1102.003←M →PT1104←MT1105←M →PT1110←P →PT1110.001→MT1110.003←M →PT1110.004←M →PT1111←PT1114.002←P →PT1119→PT1127←MT1132←PT1132.001←MT1132.002←MT1133→PT1134←MT1134.001←MT1134.002←PT1134.003←MT1134.004←PT1134.005←MT1135←P →PT1185←M →PT1187←M →PT1189←M →PT1190←M →MT1199←M →PT1200←MT1202←PT1203←P →PT1204←MT1204.001←MT1204.002←MT1204.004←PT1205←M →PT1205.001←M →PT1205.002←MT1207←MT1210←M →PT1211←PT1213→PT1213.001←MT1213.002←MT1213.003→PT1213.006→PT1216←PT1218←MT1218.005←MT1218.007←PT1218.012←PT1218.013←MT1219←M →PT1219.001←M →PT1219.002←M →PT1219.003←M →PT1221←PT1222←MT1222.001←PT1222.002←MT1480←PT1480.001←PT1484←MT1484.001←PT1484.002←M →PT1485→PT1486→MT1496→PT1496.001→PT1496.002→PT1497←PT1498←M →PT1498.001←M →PT1498.002→PT1499←P →PT1499.001→PT1499.002←M →PT1499.003→PT1505.003←M →PT1528←MT1530→PT1534←PT1535←MT1537←M →PT1539←MT1542←MT1542.002←MT1542.005→PT1546.003→PT1548←PT1550←MT1550.001←MT1550.002←MT1550.003←M →PT1550.004←FT1552.005←M →PT1552.007→PT1552.008←M →PT1553.002←PT1553.003←MT1553.004←PT1553.005←MT1556←MT1556.001←MT1556.006←MT1556.007←MT1556.009←MT1557←M →PT1557.001←M →PT1557.002←M →PT1557.003←M →PT1557.004←M →PT1558←P →PT1558.001←MT1558.002←MT1560←PT1560.003←PT1561→PT1561.001→PT1561.002→MT1563→PT1563.001→PT1563.002←M →PT1565.002→PT1566.002←MT1566.003←MT1566.004←PT1567→PT1567.001←M →PT1567.002←M →PT1567.003←M →PT1567.004←M →PT1568←M →PT1568.001←MT1568.002←MT1568.003←M →PT1570←M →PT1571←M →PT1572←M →PT1573←MT1574←MT1574.001←MT1574.004←MT1574.008←PT1578←MT1578.001←MT1578.002←MT1578.003←M →PT1578.004←MT1578.005←MT1580→PT1583←MT1583.003←MT1583.007←MT1584←MT1584.003←MT1584.004←MT1584.007←MT1584.008←MT1587.004←PT1590.003←PT1590.004→PT1595←M →PT1595.001→PT1595.002→PT1595.003→PT1599→MT1599.001←M →PT1600←PT1600.001←PT1601←PT1601.001←MT1601.002←MT1602→PT1602.001→PT1602.002→PT1606←MT1606.001←MT1606.002←MT1608.004←MT1610←P →PT1611←M →PT1612←PT1620←MT1621←PT1647←PT1649←PT1659←M →PT1665←MT1666←MT1669←M →MT1678←PT1685←MT1685.002←MT1685.003←MT1685.005←MT1686←M →PT1686.001←M →PT1686.002←M →PT1686.003←M →PT1687←PT1688←MT1689←P
Why these map — AI rationale (under review)

Prevented OWASP Web Top 10 (2025) risks (9)

OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).

Direction: ← other covers this; → this covers other (F/M/P = full / mostly / partial). gov = governs / implements (a mandate, not coverage).

Why these map — AI rationale (under review)

Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.