<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Policy-Validation on microsegment.io</title>
    <link>https://microsegment.io/tags/policy-validation/</link>
    <description>Recent content in Policy-Validation on microsegment.io</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 08 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://microsegment.io/tags/policy-validation/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Your Microsegmentation Policy Is Not Proven Until You Test The Deny</title>
      <link>https://microsegment.io/post/2026-09-08-test-the-deny/</link>
      <pubDate>Tue, 08 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://microsegment.io/post/2026-09-08-test-the-deny/</guid>
      <description>&lt;p&gt;Most segmentation reviews prove that allowed traffic still works.&lt;/p&gt;&#xA;&lt;p&gt;The application opens. The database responds. Monitoring is green. The change ticket closes.&lt;/p&gt;&#xA;&lt;p&gt;None of that proves containment.&lt;/p&gt;&#xA;&lt;p&gt;Containment depends on the traffic that must &lt;strong&gt;not&lt;/strong&gt; work: the workstation that cannot reach the database, the web tier that cannot administer the hypervisor, the compromised build runner that cannot query production secrets, and the ransomware process that cannot discover every file server.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
