So many times I see the crown jewels of a company wide open on the internal network for all users to probe and access. Going a step further you could have a database admin VLAN only only allow systems within this VLAN permission to access the databases (apart from the application that needs to access it from the DMZ of course). Hope this helps. More @Wikipedia
Hover over any link to get a description of the article. Please note that search keywords are sometimes hidden within the full article and don't appear in the description or title.