A8.20 Networks security
4 min read
Network security is essential for safeguarding the integrity, confidentiality, and availability of data in transit. Whether internal or external, networks are prime targets for attackers seeking unauthorized access, data interception, or service disruption. ISO 27001 A8.20 Networks security mandates that organizations implement measures to protect both wired and wireless networks from security threats, unauthorized access, and data leakage.
Network security includes access controls, segmentation, encryption, monitoring, and secure configuration of networking equipment such as routers, switches, firewalls, and wireless access points.
Implementation Guide #
Step 1: Define Network Security Policy
- Develop a formal network security policy that outlines protection measures for internal and external networks.
- Include rules for segmentation, monitoring, access, encryption, and acceptable use.
→ Tool Recommendation: Confluence or SharePoint for policy documentation
Step 2: Segment Networks Based on Security Requirements
- Use network segmentation (e.g., VLANs, subnets, DMZs) to isolate sensitive systems and limit lateral movement.
- Separate production, development, guest, and IoT networks.
→ Tool Recommendation: Cisco Meraki, Fortinet, pfSense, Ubiquiti UniFi
Step 3: Control Network Access
- Implement strong access controls to limit who and what can connect to the network.
- Use Network Access Control (NAC) to enforce device compliance before granting access.
→ Tool Recommendation: Cisco ISE, Aruba ClearPass, Forescout
Step 4: Use Firewalls and Intrusion Detection/Prevention Systems (IDS/IPS)
- Deploy perimeter and internal firewalls to filter traffic and detect intrusions.
- Monitor for suspicious activities and enforce security policies.
→ Tool Recommendation: Palo Alto Networks, Suricata, Snort, FortiGate, Check Point
Step 5: Encrypt Sensitive Network Traffic
- Use protocols like TLS/SSL, IPsec, or VPNs to protect data in transit.
- Enforce secure configurations on routers and switches.
→ Tool Recommendation: OpenVPN, WireGuard, Cisco AnyConnect, Zscaler
Step 6: Monitor Network Activity and Traffic
- Collect logs and monitor traffic patterns to detect anomalies and potential breaches.
- Correlate logs with SIEM tools for enhanced visibility.
→ Tool Recommendation: Wireshark, Nagios, SolarWinds Network Performance Monitor, Splunk, ELK Stack
Step 7: Secure Wireless Networks
- Use strong authentication (e.g., WPA3-Enterprise) and encryption.
- Disable unused wireless SSIDs and limit signal range.
→ Tool Recommendation: Ruckus Wireless, Aruba, Cisco Meraki
Step 8: Patch and Harden Network Devices
- Regularly update firmware of routers, switches, and firewalls.
- Disable unused ports and services, change default credentials, and apply security configurations.
→ Tool Recommendation: Qualys, Nessus, Rapid7 Nexpose
Templates #
- Network Security Policy
- Network Segmentation Plan
- Network Access Control List (ACL) Template
- Firewall Rule Review Checklist
- Network Monitoring and Incident Response Procedures
Example #
A medium-sized enterprise experienced frequent malware outbreaks due to poor network segmentation and lack of monitoring. After adopting Cisco ISE for NAC and FortiGate firewalls, they segmented their environment into production, user, and guest networks. They also implemented Splunk for real-time monitoring and alerts. This dramatically reduced infection rates and improved incident response times.
How to Comply #
To comply with ISO 27001 A.8.20, organizations should:
- Define and enforce a network security policy.
- Segment and control access to internal and external networks.
- Encrypt data in transit where required.
- Use firewalls, IDS/IPS, and NAC systems.
- Regularly monitor, audit, and update network infrastructure.
How to Pass an Audit #
Key Documents to Prepare:
- Network Security and Access Policy
- Network Architecture and Segmentation Diagram
- Firewall and IDS/IPS Configuration Files
- Patch and Firmware Update Records
- Network Monitoring and Incident Logs
What the Auditor Will Check:
- Are there defined and enforced controls over network access?
- Is sensitive traffic encrypted and securely routed?
- Are there mechanisms in place to detect and respond to network threats?
- Are network devices updated and hardened regularly?
Top 3 Mistakes People Make #
- Failing to segment networks, allowing lateral movement for attackers.
- Using outdated or default configurations on network equipment.
- Not monitoring or logging network activity effectively.
ISO 27001 Network Security FAQ #
Q1: Do we need firewalls for internal networks, or just the perimeter?
Internal segmentation firewalls are important for protecting sensitive systems even within your LAN, especially in flat networks.
Q2: How do we secure remote access to the internal network?
Use secure VPNs with MFA and monitor sessions. Solutions like Cisco AnyConnect, OpenVPN, or Zscaler can help.
Q3: Is it necessary to monitor encrypted traffic?
Yes, encrypted traffic should be monitored using SSL decryption where lawful and feasible, especially for threat detection and data exfiltration monitoring.
ISO 27001 Controls and Attribute Values #
| Control | Attribute Value |
| A.8.20 Networks Security | Preventive, Detective, Technical |
| Purpose | Ensure secure and reliable data transmission across networks and prevent unauthorized access or threats. |
| Applicability | All physical and wireless networks across the organization. |
| ISO 27001 Domains | Communications Security, Operations Security, Access Control |
Implementing strong network security helps organizations safeguard communication channels, prevent breaches, and maintain business continuity in the face of evolving cyber threats.