Create the objects you need in this order.
- Virtual router - Routing > Virtual Router
- Zones - Network > Zones
- assign the new internet and business zones to your virtual routers
- Interfaces - Network > interfaces
- Create the interfaces and sub interfaces that you are using on the ISG and assign them to the zone you need them to be created above
- Security Policy - Policy > Policies
- Create the business to internet zone policy and add nat for their outbound access
- If inbound access is needed create the reverse zone policies and destination nat