What Is a Zone?
In Asset Manager, and as a best practice, assign sets of connected devices (subnets) to a single zone. Assign isolated segments to separate zones. The benefit of this practice becomes apparent when you map zones: When you group segmented zones by the first octet of the IP address, isolated segments with no connectivity between them display as a single cloud entity. You can validate that the subnets are in fact isolated from each other by regrouping the zone more granularly---by second or third octet. Zones delimit the scope of information that can be displayed on an Asset Manager map. To map a particular network view, all elements belonging to that view must be contained in a single zone. When planning a zone definition, be sure to include elements you want to see on one map as members of a single zone. Also, be thoughtful about how you name them. There are usually many zones in an enterprise, so it's a good practice to name each zone based on its unifying features and purpose. Set criteria defining zone membership and standardize your naming convention. After you have defined and planned your zones, configure them in Asset Manager. Here's an overview of the process: Asset Manager is designed to keep you continuously apprised of zone assets and activity: what's there, what's there but inactive, what's there but shouldn't be, what's behaving, what's misbehaving, what can get in from outside, what can get out from inside, what's sound, and what's vulnerable to exploitation. Managing discoveries and making decisions about how to define and categorize "discovered unknowns" is a central engagement with Asset Manager. It's how enterprises close the gap between what is known about a network and what is unknown. It the process by which the risk profile of unmanaged networks is reduced along with their vulnerability to attack. Over time, this categorization process diminishes. As it does, the quality of your network asset management and network vulnerability management increases. Ultimately, your company's use of Asset Manager will enable your network to be fairly and accurately understood and well-managed.
A Zone is any set of devices you want to monitor as a unit, for example, a subnet, an enclave, or a business unit. Typically, an organization contains multiple zones.
This definition is expressed as Known, Eligible and Internal lists.