Show pageOld revisionsBacklinksAdd to bookExport to PDFODT exportBack to top This page is read only. You can view the source, but not change it. Ask your administrator if you think this is wrong. ====== Network Isolation ====== [[dido:99_annexes:annex-b-terms-and-definitions:start|Go to Terms and Definitions]] ===== Discussion ===== Network Isolation separates a network, network segment, service, system, or [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_environment|Infrastructure Environment]] from other network-connected subjects by preventing or restricting network communication. Network Isolation may apply to: * An Infrastructure Environment * A network segment * A security zone * A computing resource * A service * A workload * A device * A management interface * A deployment environment * A classified environment Network Isolation may be established through: * Physical separation * Logical network segmentation * Routing restrictions * Firewall rules * Access-control policies * Virtual networks * Security groups * Network namespaces * Software-defined networking controls * Disabled network interfaces * Removal of direct network paths Network Isolation may restrict: * All network communication * Inbound communication * Outbound communication * Communication with identified networks * Communication using identified protocols or ports * Communication between security zones * Communication across administrative or security boundaries Network Isolation differs from an [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environment]]: * Network Isolation may use physical or logical controls to restrict network communication * An Air-Gapped Environment has no direct network connection to external environments within the defined scope Network Isolation also differs from a [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]]: * Network Isolation is a control applied to restrict network communication * A Disconnected Environment is an environment whose operating state lacks a direct network connection to an identified external network A network-isolated subject may retain permitted network communication within its isolation boundary. ===== Definition ===== //separation of a network-connected subject from other subjects through controls that prevent or restrict network communication// ===== Source ===== Dido Solutions, Inc. and Jackrabbit Consulting, Inc. ===== Note ===== Network Isolation may be: * Physical * Logical * Permanent * Temporary * Complete * Selective * Policy-based * Dynamically applied Network Isolation does not by itself establish: * Physical security * Data confidentiality * Data integrity * Authorization * Freedom from malicious content * Compliance with a [[dido:99_annexes:annex-b-terms-and-definitions:s:security_baseline|Security Baseline]] Applicable requirements should identify: * The isolated subject * The isolation boundary * The subjects or networks from which it is isolated * Permitted communication * Prohibited communication * The controls that establish isolation * The conditions under which isolation may change * The evidence required to verify isolation The term does not prescribe a particular network architecture, firewall, virtualization platform, cloud provider, protocol, or implementation technology. ===== Example ===== A production Infrastructure Environment uses separate virtual networks, routing restrictions, and firewall policies to prevent direct communication with development and test environments while permitting authorized communication with designated identity, logging, and monitoring services. ---- <WRAP centeralign> © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. </WRAP> dido/99_annexes/annex-b-terms-and-definitions/n/network_isolation.txt Last modified: 2026/07/16 09:54by nick_dido