> Moreover, zero trust security can also take advantage of micro-segmentation to isolate parts of a network into smaller, more manageable segments. These segments can then be subjected to specific security controls and policies depending on the nature of the processes and data they are handling.
No. Access control should be implemented on a per-resource basis. Even legacy apps can be secured by a reverse proxy.