1. Cisco Systems, Inc. (2016). Cisco NFV Infrastructure Security. White Paper, Page 10.
"Segmentation is a key security control to prevent lateral movement of threats within the data center. In a virtualized environment, segmentation can be implemented at a very granular level, a concept known as microsegmentation. With microsegmentation, security policies can be applied between individual workloads..." This document directly links segmentation and micro-segmentation to the prevention of lateral movement within an NFVI context.
2. Cisco Systems, Inc. (2017). SAFE Reference Guide. Cisco Validated Design (CVD), Page 11.
In the "Threats" section, under "Malware," it states: "Once inside, it can propagate through lateral movement... The Places in the Network (PINs) are segmented from each other to limit the scope of a breach." This establishes segmentation as a core SAFE architecture principle for limiting lateral movement.
3. Gill, S., & Tredan, G. (2020). Security for Virtualized Networks. In Network and System Security (pp. 1-15). Springer, Cham. DOI: https://doi.org/10.1007/978-3-030-64302-01
This academic publication discusses security in virtualized environments, stating, "Micro-segmentation is a security technique that enables fine-grained security policies to be assigned to individual workloads... This helps in preventing the lateral movement of threats within the data center." This corroborates the industry best practice with peer-reviewed research.