Communication network segmentation and filtering rules shall be implemented in accordance with the principle of minimum access rights in the relevant security class.
In processing environments of security classes IV to II, the requirement may be met by implementing the following measures in addition to those mentioned above:
4) Monitor and restrict data flows between network zones, allowing only pre-approved, operationally essential data exchanges (default-deny)