Technical controls enforce network boundaries and restrict traffic between zones based on policy
Enforcing zone boundaries with VLANs and firewall rules blocking traffic unless explicitly allowed is the segmentation slice of A.8.20, which also covers encrypted transit, remote access and wireless protection.
The technical facet enables VLANs and firewall rules to enforce zone boundaries by default-deny, the mechanism that turns A.8.22's segmentation policy into a real barrier.
https://sekit.ai/api/mcp/crosswalk