Most segmentation programmes stall because the design assumes a maintenance window nobody will ever approve. Here is the sequencing that works instead.
The standard advice is to zone the plant according to the Purdue model, place conduits between the levels, and enforce them at a firewall. The advice is correct and almost useless on its own, because it says nothing about how to get there on a live asset that has not had an unplanned outage in four years.
The sequencing that works starts with visibility rather than enforcement. Before a single rule is written, you need a passive inventory of what talks to what, gathered over a period long enough to include month-end batch jobs, vendor maintenance sessions and seasonal operating modes. Two weeks is not long enough. Six is usually close.
Second, enforce in monitor mode first. Every rule you intend to apply should run for a full operating cycle in a mode that logs violations without dropping traffic. The violations are your real inventory of undocumented dependencies, and they will surprise you.
Third, cut over conduit by conduit, aligned to whatever maintenance windows already exist. A programme that asks for its own window will wait. A programme that fits inside scheduled work will move.
Finally, hand the ruleset to operations with a change process they helped design. A segmentation programme that only the consultants understand degrades to permissive within eighteen months.
