ISO27001:2022 – A8.21
Security of network services
Want to fast track your ISO 27001 journey?
Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon).
Introduction to ISO 27001 – A8.21
This is one of those ISO27001 controls that looks like it’s in the correct place, but when you dig into what its required. It feels out of step from the rest of the technological Annex A controls. This is because at the heart of it, this control is talking about network service providers and how they are managed.
Although this control is important, one can’t help but feel that if you have already considered IO27001 controls related to supplier management, that this would have been addressed.
But perhaps it is the importance of network security that this control deserves its own control, along side other ISO27001 controls focused on networks.
What does the standard require?
The standard states that “Security mechanisms, service levels and service requirements of network services shall be identified, implemented and monitored.” (A8.21 – Security of network services)
Note the specific reference to service levels and service requirements, that tells us we’re talking about the network service provider, not simply the network security controls.
Why is this required?
Because the ability to communicate across the network is so important, its clearly understandable that we need to have robust security of the network service we rely upon.
Can you remember the last time your network service provider let you down? Perhaps it was your mobile phone network provider, and you couldn’t get a signal to make an important call. Or perhaps it was your network service was disrupted following routine maintenance by them, or by road-workers who accidentally cut through your network cables?
Irrespective of the cause, the loss of your network service can have significant impact on you and your business. It might affect clients and customers, leading to complaints and regulatory action.
What the auditor is looking for
For this ISO27001 control, the auditor will expect to see a variety of security measures that might include;
The auditor will be looking for the following to be in place;
- Access Control policies and procedures (A5.15 – Access Control)
- List of suppliers (A 5.19 – Information security in supplier relationships)
- Supplier assessments and questionnaires
- Supplier Agreements or contracts (A5.20 – Addressing information security within supplier agreements)
- Processes to manage ICT Suppliers (A5.21 – Managing information security in the ICT supply chain)
- Supplier reviews have been undertaken (A5.22 – Monitoring, review and change management of supplier services)
- Incident Response Plans (A5.24 – Information security incident management planning and preparation)
- Logging of activity on the network (A8.15 – Logging)
- Monitoring of activities on the network (A8.16 – Monitoring Activities)
- Encryption of network services is in place (A8.24 – Use of cryptography)
- Risk Register.
- Audit results.
- Incident Logs.
What do you need to do?
When implementing the ISO27001 Annex A control, A5.19 (Information security in supplier relationships ) you will have identified network service providers that you rely upon. This may be one or two providers, as you should include mobile network service providers, if you feel that telephony is of key interest.
Once you know who the supplier is, you need to understand how they have been engaged, and what the current contract or agreements are. What you’re particularly interested in (for this ISO27001 control) is understanding what service levels have been agreed. For example, is it the ‘5 9s’ of availability? Meaning that service up time is 99.999% of the time. Any network outages over a period of time could impact you and your business, so this is a good metric to establish and assess, if you are achieving it.
Speak to your IT team to establish what form of encryption is in place to protect network services, and how authentication is achieved. For example, is Multi-Factor Authentication (MFA) in used? If so, how is this implemented.
As part of the supplier review process, you should also be clear on how service levels are communicated to your business. For example, network services are a good metric to discuss at your Management Review Team (MRT) meetings. Network outages and issues will also be discussed, and where necessary changes made (including implementing additional redundancy controls).
Difficulty rating
We rate this a 1.5 out of 5 difficulty rating. This control should almost be addressed by ensuring you have factored in network services within your approach to supplier management. Of course it requires some level of technical understanding, but this is something your IT team should be able to explain to you. Keep in mind that this is about the security of network services. Therefore it is how these services are delivered and the service provider that is of primary focus.
Q&A
Do I need a policy?
No, you don’t need a topic-specific policy, but you should consider this as part of your overall approach to supplier management.
What if the Network services are provided by the landlord. Are they in scope?
You should still consider your network services in scope, as the service will be outlined in your service agreement with your landlord. Although you might not have much sway on who you use, you should still look to establish what service levels have been agreed, and understand what resilience and redundancy is in place.
More questions?
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book “The Real Easy Guide to ISO27001” which is available on Amazon.
Fastback your journey to ISO27001 and buy our Policies to get started TODAY!
Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!
