CSA Zero Trust Microsegmentation Guidance - formalizes topology-defined vs. connection-defined segmentation models
The Cloud Security Alliance (CSA) has released new guidance on Zero Trust Microsegmentation. This guidance offers precise framing for the topic, distinct from much vendor material. It proposes a useful model that separates two key segmentation approaches: topology-defined and connection-defined. Topology-defined segmentation relies on network position, controlling where traffic can flow using elements like zones and firewalls. Connection-defined segmentation, however, focuses on session establishment, using identity, device posture, and context to permit or deny access to services. The CSA advocates for these two models as complementary, asserting that connection-defined controls reduce the attack surface before a session begins. Conversely, topology-defined controls provide containment once a session or system is compromised. This new guidance expands the scope beyond traditional data center east-west traffic to include IT, OT, IoT, cloud, edge, and agentic AI workloads. It also distinguishes between macro, micro, and nano-segmentation granularities. The paper details various enforcement plane choices, governed egress control, control-plane resilience, and policy drift detection. The operational model outlined is a continuous cycle: visibility, policy derivation, simulation, enforcement, drift monitoring, and exception retirement. The guidance emphasizes this process as ongoing, not a one-time deployment.