Segmentation reduces unnecessary connectivity and makes security policy easier to understand and enforce.
Common zones
Users, servers, guests, voice, CCTV, IoT and management may require different controls.
Policy
Use firewall or access-control policy to define permitted flows. Avoid broad any-to-any connectivity between zones.
Maintenance
Review segmentation as applications and users change. Old rules and unused VLANs should not remain indefinitely.
This article is general technical guidance. Actual architecture should be validated against the organization's requirements, risk profile and existing infrastructure.
