Operating modelStart with resources and required communication, not with an assumption that the inside is trusted.
A modern enterprise network spans offices, data centers, cloud platforms, remote users, SaaS services, operational technology, wireless networks, managed devices, unmanaged devices, partner connections, and internet-facing systems. Treat network location as context rather than proof of trust. NIST SP 800-207 explicitly rejects implicit trust based solely on physical or network location and instead focuses access decisions on subjects, devices, resources, and policy.
That does not make segmentation obsolete. Segmentation remains valuable because it limits reachability, reduces blast radius, creates enforceable choke points, and simplifies monitoring. The important distinction is that a VLAN or private subnet should not itself grant broad application trust. Use network boundaries to constrain possible paths while identity, device, workload, and application controls decide whether an allowed path should result in access.
For each critical service, identify the users and workloads that need it, the protocols and ports required, the direction of initiation, the data sensitivity, the authentication mechanism, the administrative path, external dependencies, expected traffic pattern, and recovery requirements. This produces a communication model that can be enforced and reviewed instead of a growing collection of firewall rules whose original purpose has been forgotten.