# Network Segmentation

Published articles for Network Segmentation.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## AWS Security Reference Architecture: A deep dive into PCI DSS compliance

DevFeed: [AWS Security Reference Architecture: A deep dive into PCI DSS compliance](<https://devfeed.tech/articles/aws-security-reference-architecture-a-deep-dive-into-pci-dss-compliance-20819.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/security/aws-security-reference-architecture-a-deep-dive-into-pci-dss-compliance/>)

Author: Avik Mukherjee

Published: 2026-09-14T17:46:56Z

Content type: article

Language: en

Sources: [AWS Security Blog](<https://devfeed.tech/sources/aws-security-blog.md>)

Topics: [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Network Segmentation](<https://devfeed.tech/topics/network-segmentation.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [amazon-web-services](<https://devfeed.tech/tags/amazon-web-services.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [foundational-100](<https://devfeed.tech/tags/foundational-100.md>), [logging](<https://devfeed.tech/tags/logging.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [security-blog](<https://devfeed.tech/tags/security-blog.md>), [security-identity-compliance](<https://devfeed.tech/tags/security-identity-compliance.md>)

### AI overview

AWS announces the AWS Security Reference Architecture (AWS SRA) PCI DSS Deep Dive, a guide that extends the core AWS SRA with prescriptive architecture-level guidance for organizations handling cardholder data on AWS. It explains how AWS SRA patterns address PCI DSS concerns including account scoping, network segmentation, encryption, logging, and access control.

### Source excerpt

Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data Security Standard (DSS) Deep Dive. This new guide extends the core AWS SRA to provide prescriptive, architecture-level guidance for organizations that store, process, or transmit cardholder data on AWS. Organizations subject to [...]

## The Unexpected Winner of Cisco IT's Wi-Fi 7 Upgrade? Security.

DevFeed: [The Unexpected Winner of Cisco IT's Wi-Fi 7 Upgrade? Security.](<https://devfeed.tech/articles/the-unexpected-winner-of-cisco-it-s-wi-fi-7-upgrade-security-10933.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/cisco-on-cisco/the-unexpected-winner-of-cisco-its-wi-fi-7-upgrade-security>)

Author: Chris Tomazic

Published: 2026-09-11T12:30:05Z

Content type: article

Language: en

Sources: [Cisco Blogs](<https://devfeed.tech/sources/cisco-blogs.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Network](<https://devfeed.tech/topics/network.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>)

Tags: [agenticops](<https://devfeed.tech/tags/agenticops.md>), [ai-in-it-operations](<https://devfeed.tech/tags/ai-in-it-operations.md>), [cisco-it](<https://devfeed.tech/tags/cisco-it.md>), [cisco-on-cisco](<https://devfeed.tech/tags/cisco-on-cisco.md>), [cisco-secure-networking](<https://devfeed.tech/tags/cisco-secure-networking.md>), [enterprise-networking](<https://devfeed.tech/tags/enterprise-networking.md>), [network](<https://devfeed.tech/tags/network.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [security](<https://devfeed.tech/tags/security.md>), [wi-fi-7](<https://devfeed.tech/tags/wi-fi-7.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

Cisco IT's Wi-Fi 7 upgrade delivered expected improvements in connectivity, availability, and performance, but its most significant result was stronger security. The article argues that networking and security should be designed and operated as one system, highlighting zero trust access and Cisco Secure Networking as practical outcomes of that approach.

### Source excerpt

Cisco IT's Wi-Fi 7 upgrade delivered more than faster connectivity -- it transformed enterprise security. Discover how Zero Trust Access, AI agents, and secure-by-design infrastructure are redefining what a modern network can do.

## Zero trust architecture for platform engineers: Securing modern developer platforms

DevFeed: [Zero trust architecture for platform engineers: Securing modern developer platforms](<https://devfeed.tech/articles/zero-trust-architecture-for-platform-engineers-securing-modern-developer-platforms-12288.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/zero-trust-architecture-for-platform-engineers-securing-modern-developer-platforms>)

Author: Ajay Chankramath

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Network Segmentation](<https://devfeed.tech/topics/network-segmentation.md>), [SPIFFE](<https://devfeed.tech/topics/spiffe.md>), [SPIRE](<https://devfeed.tech/topics/spire.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [developer](<https://devfeed.tech/tags/developer.md>), [identity](<https://devfeed.tech/tags/identity.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [platform](<https://devfeed.tech/tags/platform.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [policy](<https://devfeed.tech/tags/policy.md>), [security](<https://devfeed.tech/tags/security.md>), [spiffe](<https://devfeed.tech/tags/spiffe.md>), [spire](<https://devfeed.tech/tags/spire.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

This article explains how zero-trust architecture secures cloud-native developer platforms. It describes continuous authentication and authorization, cryptographic service identity through SPIFFE/SPIRE, network segmentation, policy-as-code enforcement, and runtime verification for Kubernetes-based, multi-tenant environments.

### Source excerpt

Secure your cloud-native platform with Zero Trust Architecture. Explore ZTA principles, service identity (SPIFFE/SPIRE), and policy-as-code for automated, developer-friendly security

## Isovalent Networking for Virtualization: Enterprise-Grade Network Segmentation and Multi-Tenancy for VMs in Kubernetes

DevFeed: [Isovalent Networking for Virtualization: Enterprise-Grade Network Segmentation and Multi-Tenancy for VMs in Kubernetes](<https://devfeed.tech/articles/isovalent-networking-for-virtualization-enterprise-grade-network-segmentation-and-multi-tenancy-for-vms-in-kubernetes-31332.md>)

Original publisher: [Read original article](<https://isovalent.com/blog/post/isovalent-networking-for-virtualization/>)

Author: Marcos Hernandez

Published: 2026-06-02T12:59:28Z

Content type: release

Language: en

Sources: [Isovalent - The latest articles covering eBPF-based Networking, Observability, and Security](<https://devfeed.tech/sources/isovalent-the-latest-articles-covering-ebpf-based-networking-observability-and-security.md>)

Topics: [virtualization](<https://devfeed.tech/topics/virtualization.md>), [Network Segmentation](<https://devfeed.tech/topics/network-segmentation.md>), [Multi-tenancy](<https://devfeed.tech/topics/multi-tenancy.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [cilium](<https://devfeed.tech/tags/cilium.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [hubble](<https://devfeed.tech/tags/hubble.md>), [isovalent](<https://devfeed.tech/tags/isovalent.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-networking](<https://devfeed.tech/tags/kubernetes-networking.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [mesh-networking](<https://devfeed.tech/tags/mesh-networking.md>), [migrations](<https://devfeed.tech/tags/migrations.md>), [multi-tenancy](<https://devfeed.tech/tags/multi-tenancy.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [policy](<https://devfeed.tech/tags/policy.md>), [product](<https://devfeed.tech/tags/product.md>), [runtime-security](<https://devfeed.tech/tags/runtime-security.md>), [tetragon](<https://devfeed.tech/tags/tetragon.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

Isovalent announced the general availability of Isovalent Networking for Virtualization, a product that provides network segmentation, multi-tenancy, and policy enforcement for virtual machine workloads running in Kubernetes. It also streamlines migrations to KubeVirt.

### Source excerpt

We're formally announcing the General Availability of Isovalent Networking for Virtualization (INV), a purpose-built product that brings full network segmentation, multi-tenancy, and policy enforcement to virtual machine workloads running in Kubernetes, in addition to streamlining migrations to KubeVirt.

## PCI DSS Compliance: What Digital Businesses Need to Know

DevFeed: [PCI DSS Compliance: What Digital Businesses Need to Know](<https://devfeed.tech/articles/pci-dss-compliance-what-digital-businesses-need-to-know-10274.md>)

Original publisher: [Read original article](<https://dodopayments.com/blogs/pci-dss-compliance-digital-business/>)

Author: Ayush Agarwal

Published: 2026-04-15T00:00:00Z

Content type: tutorial

Language: en

Sources: [Dodo Payments Blog](<https://devfeed.tech/sources/dodo-payments-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Network Segmentation](<https://devfeed.tech/topics/network-segmentation.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [tokenization](<https://devfeed.tech/topics/tokenization.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [digital-products](<https://devfeed.tech/tags/digital-products.md>), [firewalls](<https://devfeed.tech/tags/firewalls.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [saas](<https://devfeed.tech/tags/saas.md>), [scope](<https://devfeed.tech/tags/scope.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [tls](<https://devfeed.tech/tags/tls.md>), [tokenization](<https://devfeed.tech/tags/tokenization.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This guide explains how PCI DSS applies to digital businesses that accept card payments, including SaaS companies and sellers of digital products. It outlines the standard's 12 requirements and discusses controls for networks, account data, vulnerabilities, access, monitoring, and information security. It also covers card-not-present transactions, recurring billing, and tokenization.

### Source excerpt

PCI DSS compliance explained for digital businesses. Understand the 12 requirements, compliance levels, and how to reduce your scope when selling digital products online.

## Kubernetes for Agentic AI: Best Practices for Security and Observability

DevFeed: [Kubernetes for Agentic AI: Best Practices for Security and Observability](<https://devfeed.tech/articles/kubernetes-for-agentic-ai-best-practices-for-security-and-observability-29742.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/kubernetes-for-agentic-ai/>)

Author: info@goteleport.com (Boris Kurktchiev, Jack Pitts)

Published: 2026-04-01T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [AI Platform](<https://devfeed.tech/topics/ai-platform.md>)

Tags: [availability](<https://devfeed.tech/tags/availability.md>), [container](<https://devfeed.tech/tags/container.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-security](<https://devfeed.tech/tags/kubernetes-security.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [observability](<https://devfeed.tech/tags/observability.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [recommendations](<https://devfeed.tech/tags/recommendations.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article presents 18 Kubernetes best practices for securing and monitoring containerized agentic AI workloads. It emphasizes foundational controls such as least privilege, access control, network policies, image assurance, network segmentation, and continuous monitoring, while noting that many practices also apply to other containerized and serverless environments.

### Source excerpt

Discover 18 Kubernetes security, observability, and availability best practices for container-based agentic workloads.

## Data Inventory

DevFeed: [Data Inventory](<https://devfeed.tech/articles/data-inventory-15451.md>)

Original publisher: [Read original article](<https://medium.com/wise-engineering/data-inventory-4eff3f015553?source=rss----f2565bbe9c46---4>)

Author: Ritesh Modi

Published: 2025-02-19T14:24:14Z

Content type: tutorial

Language: en

Sources: [Wise Engineering - Medium](<https://devfeed.tech/sources/wise-engineering-medium.md>)

Topics: [data-governance](<https://devfeed.tech/topics/data-governance.md>), [data-architecture](<https://devfeed.tech/topics/data-architecture.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [backend](<https://devfeed.tech/tags/backend.md>), [data](<https://devfeed.tech/tags/data.md>), [data-governance](<https://devfeed.tech/tags/data-governance.md>), [databases](<https://devfeed.tech/tags/databases.md>), [frontend](<https://devfeed.tech/tags/frontend.md>), [governance](<https://devfeed.tech/tags/governance.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [platform](<https://devfeed.tech/tags/platform.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [security](<https://devfeed.tech/tags/security.md>), [security-privacy](<https://devfeed.tech/tags/security-privacy.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

Wise's Data Governance team describes Data Inventory, a catalog of data assets that records their locations and security or privacy controls. The article explains the system's constraints, design outcomes, and process for discovering operational databases and their metadata.

### Source excerpt

The Data Governance team, part of Data Platform, develops and operates platform products through which autonomous teams can govern their data. The team's vision is to democratise data in a secure and compliant manner. Data Inventory was the team's first product. What is Data Inventory? A data inventory is an extensive catalog of the Wise's data assets. It helps us understand where the data is located and what kind of security / privacy controls are in place. This is also a requirement for ISO 27001:2022. What are the constraints? Any system has to work well with our controls and way-of-working. This led to following constraints: It shall be built in a way that satisfies our security controls such as network segmentation, least privilege access, secure secret management, etc. It shall be easy to integrate with other in-house platforms to provide cohesive experience. It shall be built to connect with heterogeneous and fragmented infrastructure. Many data systems are built through off-the-shelf or managed service offering but others are built & operated in-house. The system shall be integrated by default with technology provided by Data Platform. On another hand, it shall be extensible enough to integrate with data systems not maintained by Data Platform. How did we build our inventory? At high level, we split this into 4 main outcomes: 1. Register assets at correct granularity. 2. Identify the correct owner and make them accountable for the life cycle. 3. Extract the schema of the data asset. 4. Classify the asset with correct sensitivity. This is how design looks at high level: To achieve the above design and outcome, we follow the following steps: Step 0: Discover data systems network metadata Scanners need to be aware of the network metadata before doing scanning. For example: - What is the host or connection string? - What is the technology of the data system? - What is the name of the data system? Let us take an example of how we solve it in our operational datab

## Cleared for takeoff: Meeting TSA's new cybersecurity requirements

DevFeed: [Cleared for takeoff: Meeting TSA's new cybersecurity requirements](<https://devfeed.tech/articles/cleared-for-takeoff-meeting-tsa-s-new-cybersecurity-requirements-13008.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/cleared-for-takeoff-meeting-tsas-new-cybersecurity-requirements>)

Published: 2023-07-10T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Network Segmentation](<https://devfeed.tech/topics/network-segmentation.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [aviation-cybersecurity](<https://devfeed.tech/tags/aviation-cybersecurity.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [image-cve](<https://devfeed.tech/tags/image-cve.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [tsa-cybersecurity](<https://devfeed.tech/tags/tsa-cybersecurity.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article explains how updated TSA cybersecurity requirements affect aviation organizations, focusing on network segmentation, access control, continuous monitoring, threat detection, and risk-based patch management. It presents Chainguard Images as a source-built, continuously updated suite of minimal hardened container images intended to reduce known vulnerabilities and support compliance efforts.

### Source excerpt

TSA strengthens cybersecurity for airports & aircraft. Learn how Chainguard Images helps meet new software development requirements.

## Alternatives to a Corporate VPN

DevFeed: [Alternatives to a Corporate VPN](<https://devfeed.tech/articles/alternatives-to-a-corporate-vpn-29564.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/alternative-to-corporate-vpn/>)

Author: info@goteleport.com (Shivashish Yadav)

Published: 2022-04-20T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Virtual Private Network](<https://devfeed.tech/topics/vpn.md>), [network security](<https://devfeed.tech/topics/network-security.md>), [remote access](<https://devfeed.tech/topics/remote-access.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Network Segmentation](<https://devfeed.tech/topics/network-segmentation.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>)

Tags: [corporate](<https://devfeed.tech/tags/corporate.md>), [firewalls](<https://devfeed.tech/tags/firewalls.md>), [network-segmentation](<https://devfeed.tech/tags/network-segmentation.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [vpn](<https://devfeed.tech/tags/vpn.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

This article explains why corporate VPNs can create security and access-control risks, particularly for remote work and third-party connections. It discusses data-leak exposure, shared passwords, insufficient resource-level access controls, and the need for network segmentation, firewalls, least-privilege access, or a zero-trust model as alternatives or safeguards.

### Source excerpt

VPNs were once the gold standard for network security, but they have limits. This post dives into perimeter-based security limits and offers modern VPN alternatives.