ISO27001:2022 – A8.22

Segregation of networks

Want to fast track your ISO 27001 journey? 

Our “ISO 27001:2022 Policy Pack” gives you everything you need to comply with this, and all ISO 27001 requirements. Take a look, and when you buy it, you also receive our “Real Easy Guide To ISO27001” book (available on Amazon).

Introduction to ISO 27001 – A8.22

If ISO27001 is concerned with the segregation of duties, then it is little wonder that it also requires us implement controls that segregate (or segment) networks.  Buy doing so, we can positively manage the risk of unauthorised access to our systems and data. 

What does the standard require?

The standard states that “Groups of information services, users and information systems shall be segregated in the organisations networks.” (A8.22 – Segregation of networks)

 There are three separate aspects to this control, which require us to consider the segregation of networks for; 

  • Information services – E.g. processing of specific products or services
  • Users – E.g. Access controls for developers who can only access test environments
  • Information systems – Access to HR systems for people management teams 

Why is this required?

Imagine having just one enormous building, with no doors, and no control over access from one floor to the next. People can go anywhere they want at any time. This is what having a network would look like, if you didn’t implement some form of segregation of your networks. 

One gigantic building where one ‘bad actor’ could do damage to your entire operation, simply by gaining access through the front (or back) door. 

By thoughtfully segregating your network, you reduce the risks to critical data and infrastructure, by limiting the movement (upwards or sideways) throughout your business.  Without these controls in place, anyone accessing your network could accidentally or deliberately cause a data breach or cyber security incident that affects your clients and your business. 

We worked with a client who had a ‘flat structure’ in terms of networks.  No segregation was implemented, and guests coming into their organisation were given the company WiFi code, giving them the same levels of access as any employee. 

This code had not been changed for over 5 years, meaning any visitor or past employees could still access all their network services.  When they had a virus outbreak across their business, it was eventually traced back to a visitor who had connected to their network. Because there was no segregation of the network, the virus ran through their business like a bush fire. Unimpeded by any internal firewalls or segregation.

What the auditor is looking for

For this ISO27001 control, the auditor will expect to see a variety of security measures that might include; 

What do you need to do?

Speak to your IT team and ask for a network diagram, so that you can see how your network is configured. 

To ensure security, you should be managing your networks by dividing them into separate network domains and separating them from the public network (i.e. internet). ISO27002 suggests these domains could be selected based on levels of trust, criticality and sensitivity (eg public access domain, desktop domain, server domain, low- and high-risk systems), along organisational units (eg. human resources, finance, marketing) or some combination (e.g. server domain connecting to multiple organisational units).

Difficulty rating

We rate this a 1.5 out of 5 difficulty rating. In speaking to your IT team you will understand how the network has been designed and identify threats and vulnerabilities which need to be managed through your risk management framework. As you begin to develop this security control you should look to segment your network in an effective and appropriate way, based on the criticality of the data you are protecting.

Q&A

Do I need a policy?

No, you don’t need a topic-specific policy, but you should be able to evidence that network segregation is in place. This isn’t always possible, for example might be a business that operates only on a remote basis (i.e. from home).  By the very nature of what you do, your networks are dispersed and therefore segregated.  However, think about how you evidence segregation of the information systems that you are connecting into. Are the networks segregated by users or information systems?

More questions?

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you should buy our book “The Real Easy Guide to ISO27001” which is available on Amazon.

Fastback your journey to ISO27001 and buy our Policies to get started TODAY!

Take a look at our “ISO 27001:2022 Policy Pack” and when coupled with our book you’ll have everything you need to succeed in achieving ISO 27001 certification!

ISO 27001 – A8.22 –  Segregation of networks