I would create a separate server farm for each BU. Their default gateway would be on an ASA5585-X. Those firewalls would hang off of the core and provide filtering between the clients and each server farm. Your server farm switches still connect to the 4500, but I would move the SVI's to the ASA. That allows "open" communication between the users (ie VoIP) but firewalling the users from the BU server farms. Servers in a BU have open communication between them, but inter-BU communication would also be filtered.