View Categories

A8.21 Security of network services

4 min read

Network services—including internet access, email, DNS, remote access, and cloud connectivity—are vital for business operations but are also attractive targets for cyber threats. These services must be securely designed, configured, and managed to ensure the confidentiality, integrity, and availability of transmitted data.

ISO 27001 A8.21 Security of network services emphasizes the need to ensure that the security features of network services are clearly defined, agreed upon, implemented, and monitored—whether those services are managed internally or outsourced to third-party providers.

Implementation Guide #

Step 1: Define Security Requirements for Network Services

  • Document the types of network services in use (e.g., DNS, VPN, email gateways, web filtering).
  • Identify security requirements (e.g., encryption, authentication, availability, monitoring) for each service.
    → Tool Recommendation: Use Microsoft Visio, Lucidchart, or io for network service architecture diagrams.

Step 2: Formalize Agreements with Third-Party Providers

  • For outsourced services (e.g., cloud hosting, managed DNS), ensure SLAs and contracts include specific security clauses.
  • Include rights to audit, data protection obligations, and incident response terms.
    → Tool Recommendation: Use DocuSign or ContractWorks for tracking and managing SLAs.

Step 3: Secure Core Network Services

  • DNS: Use secure and redundant DNS services (e.g., DNSSEC, Cloudflare DNS, Quad9).
  • Email: Implement email security gateways with spam/phishing protection (e.g., Proofpoint, Mimecast, Microsoft Defender for Office 365).
  • VPN: Use secure VPN protocols (e.g., IPsec, SSL) and enforce MFA.
  • Remote Access: Restrict access to trusted devices and monitor all connections.
    → Tool Recommendation: Cisco AnyConnect, OpenVPN, Zscaler, Cloudflare Zero Trust

Step 4: Monitor and Audit Network Services

  • Continuously monitor service usage, performance, and anomalies.
  • Set up alerts for unusual behaviors or access patterns.
    → Tool Recommendation: Nagios, SolarWinds NPM, Splunk, Wazuh, Datadog

Step 5: Maintain a Network Services Inventory

  • Maintain a centralized list of all network services, their owners, service providers, and associated security controls.
  • Document how each service is protected and monitored.
    → Tool Recommendation: CMDB tools like ServiceNow, Device42, or ManageEngine AssetExplorer

Step 6: Test and Review Security Regularly

  • Perform periodic penetration tests and vulnerability scans on network services.
  • Review and update configurations based on new threats or changes in usage.
    → Tool Recommendation: Nessus, Qualys, Burp Suite, OWASP ZAP

Templates #

  • Network Services Inventory Template
  • Security Requirements for Network Services Checklist
  • Third-Party Security Agreement Template
  • VPN Access Policy
  • Email Security Configuration Guide

Example #

A financial services firm outsourced its email and DNS to third-party providers without defining specific security requirements. After a phishing attack led to a data leak, they revised contracts to include anti-spoofing protections, implemented DMARC/DKIM/SPF, and added Proofpoint as a secure email gateway. They also began using Nagios and Splunk to monitor these services in real time, reducing the risk of recurrence.

How to Comply #

To comply with ISO 27001 A.8.21, organizations should:

  • Define and document the security requirements of all network services.
  • Ensure contracts and SLAs for third-party services include security measures.
  • Regularly test, monitor, and audit all critical network services.
  • Maintain an up-to-date inventory of services and ensure responsible ownership.

How to Pass an Audit #

Key Documents to Prepare:

  • Network Services Inventory
  • SLA and Security Agreement Documents
  • Security Configuration Files
  • Monitoring and Alert Logs
  • Penetration Test and Vulnerability Scan Reports

What the Auditor Will Check:

  • Are network services documented with clearly defined security requirements?
  • Are third-party agreements aligned with your organization’s security policy?
  • Are network services monitored and regularly reviewed?
  • Is there evidence of security testing and incident response planning?

Top 3 Mistakes People Make #

  • Relying on third-party providers without validating their security controls.
  • Failing to monitor critical network services in real time.
  • Not defining security responsibilities for internally managed services.

ISO 27001 Network Services FAQ #

Q1: Do we need to assess the security of services provided by major vendors like Microsoft or Google?
Yes. Even trusted providers should have their configurations reviewed and monitored, and your responsibilities under shared security models must be understood.

Q2: How often should we test network services for vulnerabilities?
At least annually, or after major changes to services or infrastructure. High-risk services should be tested more frequently.

Q3: Can we use open-source tools to secure our network services?
Absolutely. Tools like Suricata, OpenVPN, Snort, and Wazuh offer powerful capabilities when correctly configured and maintained.

ISO 27001 Controls and Attribute Values #

Control Attribute Value
A.8.21 Security of Network Services Preventive, Contractual, Operational
Purpose Ensure that the security of internal and external network services is maintained and aligned with business requirements.
Applicability All managed or outsourced network services.
ISO 27001 Domains Communications Security, Supplier Relationships, Operations Security

By ensuring robust security for all network services, organizations can reduce risks of data leakage, downtime, and non-compliance, while enabling secure and reliable connectivity for business operations.

Leave a Reply

Your email address will not be published. Required fields are marked *

Log in

You dont have an account yet? Register Now