Secure Integration of IoT Devices into Enterprise NetworksUsing VLAN Segmentation and Access Control Policies

Authors

  • Zainab Abbas Fadhil Network Department, Faculty of Engineering, Al- Iraqia University, Baghdad, Iraq

DOI:

https://doi.org/10.71229/517dwy66

Keywords:

Internet of Things, , enterprise networks, , VLAN segmentation,, access control lists,, network security

Abstract

The explosion in number of IoT devices in enterprise network has presented an interesting security problem. The smart cameras, environment monitors, printers, access control units, building controllers, and other devices are commonly placed near corporate devices but are generally less protected by more vulnerable firmware, less monitored and have different patch schedules. This paper provides a secure integration framework for IoT devices based on VLAN segmentation and access control policies.

This framework, referred to here as SIVAC-IoT, classifies devices into role-based VLANs, assigns least-privilege access policy to each VLAN, and controls communications between VLANs using Layer-3 ACLs, firewall policies, and logging controls. The paper presents a structured enterprise-network implementation framework supported by clear topology design, policy engineering, validation procedures, and measurable security outcomes suitable for professional deployment planning.

The evaluation criteria include the reduction of lateral movement, prevention of unauthorized flows, broadcast-domain control, policy overhead, and maintainability. The experimental results show that moving from a traditional flat enterprise design to a VLAN-based architecture with clearly defined access control significantly reduces unnecessary connectivity between IoT devices and corporate resources while maintaining a modest latency overhead. Most importantly, secure integration of IoT into enterprise networks requires intentional design rather than simply connecting devices to switch ports.

References

[1] NIST, Zero Trust Architecture, Special Publication 800-207, National Institute of Standards and Technology, 2020.

[2] NIST, Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks, NISTIR 8228, National Institute of Standards and Technology, 2019.

[3] NIST, Guide to Operational Technology (OT) Security, Special Publication 800-82 Rev. 3, National Institute of Standards and Technology, 2023.

[4] NIST, Guidelines on Firewalls and Firewall Policy, Special Publication 800-41 Rev. 1, National Institute of Standards and Technology, 2009.

[5] Center for Internet Security, CIS Critical Security Controls Version 8, Center for Internet Security, 2021.

[6] IEEE, IEEE Standard for Local and Metropolitan Area Networks--Bridges and Bridged Networks, IEEE Std 802.1Q, Institute of Electrical and Electronics Engineers.

[7] IEEE, IEEE Standard for Local and Metropolitan Area Networks--Port-Based Network Access Control, IEEE Std 802.1X, Institute of Electrical and Electronics Engineers.

[8] E. Lear, R. Droms, and D. Romascanu, Manufacturer Usage Description Specification, IETF RFC 8520, 2019.

[9] M. S. Zamani, M. M. Moghaddam, and M. A. Azgomi, A survey of network segmentation and access-control mechanisms in enterprise security, Journal of Network and Computer Applications, 2020.

[10] M. Miettinen et al., IoT Sentinel: Automated Device-Type Identification for Security Enforcement in IoT, IEEE ICDCS, 2017.

[11] V. Sivaraman et al., Network-level security and privacy control for smart-home IoT devices, IEEE International Conference on Wireless and Mobile Computing, Networking and Communications, 2015.

[12] Y. Meidan et al., N-BaIoT: Network-based detection of IoT botnet attacks using deep autoencoders, IEEE Pervasive Computing, vol. 17, no. 3, pp. 12-22, 2018.

[13] F. A. Alaba, M. Othman, I. A. T. Hashem, and F. Alotaibi, Internet of Things security: A survey, Journal of Network and Computer Applications, vol. 88, pp. 10-28, 2017.

[14] A. S. Tanenbaum and D. J. Wetherall, Computer Networks, 5th ed., Pearson, 2011.

[15] W. Stallings, Network Security Essentials: Applications and Standards, Pearson, 2017.

[16] P. Porras et al., Securing the software-defined network control layer, Network and Distributed System Security Symposium, 2015.

[17] D. Kreutz et al., Software-defined networking: A comprehensive survey, Proceedings of the IEEE, vol. 103, no. 1, pp. 14-76, 2015.

[18] S. Rose, O. Borchert, S. Mitchell, and S. Connelly, Zero Trust Architecture, NIST SP 800-207, 2020.

[19] ENISA, Baseline Security Recommendations for IoT in the Context of Critical Information Infrastructures, European Union Agency for Cybersecurity, 2017.

[20] O. Garcia-Morchon et al., Security considerations in the IP-based Internet of Things, IETF RFC 8576, 2019.

fig 3

Downloads

Published

2026-07-28

Issue

Section

Original Articles

How to Cite

Secure Integration of IoT Devices into Enterprise NetworksUsing VLAN Segmentation and Access Control Policies. (2026). Al-Noor Journal of Engineering Management and Computer Science, 2(2), 391-406. https://doi.org/10.71229/517dwy66

Similar Articles

11-20 of 20

You may also start an advanced similarity search for this article.