ISO27001:2022 – A8.20

Network controls

Want to fast track your ISO 27001 journey? 

Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon).

Introduction to ISO 27001 – A8.20

If ISO27001 is concerned with protecting your most important assets, then it makes sense that it is also interested in how you secure (and manage) the networks that connect them.

This ISO27001 control is specifically focused on securing networks and network devices,  to ensure they are not compromised, leading to data breaches. 

What does the standard require?

The standard states that “Networks and network devices shall be secured, managed and controlled to protect information in systems and applications..” (A8.20 – Network Controls)

 Note that there are three elements to consider in this control. Namely, how networks and network devices are; 

  • Secured – How do you protect your networks (e.g Intrusion Detection Systems IDS)
  • Managed – How are these managed (e.g. ongoing processes, such as Configuration management)
  • Controlled – How are you controlling them (e.g. policies and patch management)

 Subtle, but different requirements requiring different approaches, based upon the risks you face. 

Why is this required?

The power of the internet and the ability for us to communicate is largely down to one thing; Networks.  Without networks we would have a bunch of stand-alone devices that don’t talk to each other.

But as networks communicate, we need to ensure that we can trust the information that is being sent and received across our own networks, and those we connect to.  Without this trust, there is no integrity or assurance of confidentiality.

Man-in-the-Middle (MitM) attacks occur when someone can sit between the sender and receiver of information and change the information for their own benefit.  Failure to control networks could lead to data breaches and cyber-attacks, which could cause damage to you, your business, and data subjects.

Without network controls, you might also be vulnerable to denial of service (DoS) attacks, where attackers bombard your network with traffic, intending to overwhelm it and taking down your systems.  Again, this can lead to business disruption and might be the prelude to a more orchestrated cyber attack. 

What the auditor is looking for

For this ISO27001 control, the auditor will expect to see a variety of security measures that might include; 

What do you need to do?

Speak to your IT team to understand what your network looks like. If possible, ask for a network diagram (aka the network topology).  A picture paints a thousand words and will help you see what your network is, and identify any risks. 

Ask them to talk through how the network is secured from internal and external threats, using firewalls. Ask them to explain what types of firewalls are in place, and how they are managed. For example, do you use software firewalls or hardware firewalls? Do you use internal firewalls, distributed firewalls or even Next-Generation Firewalls NGFW)?   No matter what you us, you should ensure you have processes in place to ensure these are being managed effectively, for example having a configuration management process, and an approach to patch management. 

Identify what monitoring techniques are in place, such as the use of a Network Operations Centre (NOC)  or Security Operation Centre (SOC). Has your business implemented some form of Security Incident and Event Monitoring (SIEM) technology to monitor events that take place on your network, and alert someone in the event of abnormal (network) behaviour? 

Don’t forget to consider network controls for remote workers too, which might include the use of Virtual Private Network (VPN) software, which will ensure the security of users using networks outside of your control.  

Identify any threats or vulnerabilities in your network controls and add these to your risk register, and treat them appropriately by speaking to the Management Review Team (MRT). 

Difficulty rating

We rate this a 2.5 out of 5 difficulty rating. This control requires further consultation with your IT function, to understand how your networks are configured, secured, managed and controlled.  Although you won’t need to become a network architect, you need to be able to speak the language of your IT team. Knowing the difference between a firewall and a router will be a great start. 

Q&A

Do I need a policy?

No, you don’t need a topic-specific policy, but you might look to include reference to the installation of software in your acceptable use policy.

More questions?

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book… “The Real Easy Guide to ISO27001” which is available on Amazon.

Fastback your journey to ISO27001 and buy our Policies to get started TODAY!

Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!

ISO 27001 – A8.20 – Network controls