
CSA Zero Trust Microsegmentation Guidance - formalizes topology-defined vs. connection-defined segmentation models
The Cloud Security Alliance published new guidance on Zero Trust Microsegmentation that formally separates two segmentation models: topology-defined (enforcement based on network position like zones, VLANs, and firewalls) and connection-defined (enforcement based on identity, device posture, and context at session establishment). The paper positions these models as complementary rather than competing, and covers scope including IT, OT, IoT, cloud, edge, and AI workloads with distinct granularities of macro/micro/nano-segmentation. The guidance outlines an operational model of continuous visibility, policy derivation, simulation, enforcement, drift monitoring, and exception management rather than treating segmentation as a one-time deployment milestone.