ISO 27001 Networks Security Explained – Annex A 8.20

Stuart Barker -271

ISO 27001 Annex A 8.20 Network security involves managing network devices and services through documented configurations. Use SharePoint to store these standards. This ensures information availability and integrity. It requires integrating security controls into existing organisational workflows rather than relying on external dashboards. Manual oversight remains vital for compliance.

Key Takeaways

  • Document Network Configurations: Establish and maintain baseline security standards for all routers, switches, firewalls, and wireless infrastructure in a central repository.
  • Enforce Access Restrictions: Limit network management interfaces and administrative access strictly to authorized network engineers and security leads.
  • Segregate Network Traffic: Divide network architecture into separate, isolated subnets or virtual local networks (VLANs) based on system risk levels and sensitive data flows.
  • Control External Connections: Route all incoming and outgoing internet traffic through monitored security gateways and firewalls using strict, pre-approved rules.
  • Integrate Change Approval: Require formal authorization tickets for every network configuration update, port opening, or firewall rule modification prior to execution.
  • Monitor Network Activity: Maintain continuous logging of network gateway activity, administrative access sessions, and security events to detect unauthorized intrusion attempts.
  • Audit Rules and Routes Regularly: Conduct periodic manual reviews of firewall rules, routing tables, and device configurations to remove obsolete rules and maintain network integrity.
  • Secure Transmission Channels: Enforce strong encryption protocols for data moving across internal networks, remote connections, and wireless environments.

How to Implement ISO 27001 Annex A 8.20

  • Document Configuration Baselines: Define and store secure baseline configuration standards for all firewalls, routers, and switches in a central SharePoint repository.
  • Maintain Approved Architecture Diagrams: Store up-to-date network topology diagrams and segmentation schemes in Confluence to map data flows and security perimeters.
  • Build Change Request Workflows: Route all firewall rule changes, port requests, and network updates through formal Jira change tickets.
  • Enforce Pre-Change Sign-offs: Require explicit management and security team approval in the work ticket before implementing any network configuration adjustment.
  • Audit Network Rules Quarterly: Schedule recurring manual reviews of active firewall rulesets and routing tables to eliminate obsolete or overly permissive rules.
  • Document Audit Findings internally: Record audit outcomes, remediation actions, and review sign-offs within version-controlled internal document repositories.
  • Segregate Network Zones: Implement virtual local networks (VLANs) and access control lists to separate critical server environments, corporate users, and guest access.
  • Centralize Network Access Logging: Configure network devices to send administrative session logs and gateway traffic events to a central, secure log collection point.

How to Audit ISO 27001 Annex A 8.20

  • Inspect Configuration Baselines: Review documented baseline configuration standards for firewalls, routers, and switches stored in the central SharePoint repository.
  • Verify Architecture Diagrams: Examine network topology diagrams and segmentation schemes in Confluence to confirm live network boundaries match documented layouts.
  • Sample Change Request Tickets: Audit a sample of recent Jira tickets for firewall rule updates, port requests, and network adjustments to confirm change workflows were followed.
  • Check Pre-Change Sign-offs: Verify that sampled network change tickets contain explicit approvals from management and security leads prior to implementation.
  • Examine Quarterly Rule Reviews: Inspect records and meeting notes from quarterly firewall ruleset reviews to confirm obsolete or overly permissive rules were identified and purged.
  • Review Audit Remediation Logs: Check internal document repositories for recorded audit findings, fix actions, and sign-offs resulting from network security checks.
  • Audit Network Segmentation: Inspect VLAN setups and Access Control Lists (ACLs) to verify effective isolation between critical servers, corporate users, and guest networks.
  • Verify Centralized Log Feeds: Confirm network firewalls, routers, and gateways actively forward administrative session logs and traffic events to the central log repository.
  • Inspect Remote Management Access Controls: Verify that network device administrative interfaces are restricted strictly to secure, encrypted management subnets and jump hosts.
  • Audit Wireless Network Security: Test enterprise wireless configurations to ensure strong authentication mechanisms and isolated guest access controls are actively enforced.

Audit Evidence Checklist

  • Network Security Management Policy: Show a version-controlled document in SharePoint defining baseline security rules, network boundaries, and management responsibilities.
  • Network Topology Diagrams: Provide current network architecture maps stored in Confluence showing VLANs, subnet ranges, and security perimeters.
  • Firewall Change Tickets: Present approved Jira tickets for recent network changes showing mandatory risk checks, management sign-offs, and implementation logs.
  • Quarterly Rule Review Records: Supply documented reports and meeting notes proving active firewall rulesets and access control lists are reviewed and purged every three months.
  • Network Segmentation Proof: Provide technical configuration exports or screenshots showing active VLAN separation between critical servers, corporate staff, and guest traffic.
  • Device Configuration Screenshots: Supply configuration files or audit screenshots from core firewalls, routers, and switches matching approved baseline standards.
  • Centralized Network Log Proof: Provide sample log stream exports demonstrating network gateways actively forward traffic events and admin access logs to a central log server.
  • Remote Management Interface Access Rules: Present device access control lists (ACLs) proving administrative logins are restricted to encrypted, authorized management jump hosts.

What to Teach Employees

  • Understand Network Controls: Teach employees how network security controls, firewalls, and segmentation protect company data from external threats.
  • Use Approved Access Paths: Show workers how to access company network resources using authorized remote connections and official VPN tools.
  • Respect Network Segregation: Explain why guest Wi-Fi networks are kept strictly separated from internal corporate systems and databases.
  • Follow Change Approval Workflows: Train network engineers and technical staff to route all firewall rule changes and port requests through formal ticket approvals.
  • Avoid Unsanctioned Network Tools: Remind employees never to connect unauthorized routers, wireless access points, or network switches to the corporate network.
  • Maintain Baseline Settings: Teach system admins why applying approved baseline configuration standards prevents network vulnerabilities.
  • Report Network Anomalies Promptly: Train staff to notify the IT security team immediately if they notice unusual network lag, blocked sites, or unexpected connection alerts.
  • Participate in Periodic Rule Audits: Ensure technical leads review active firewall rules and routing tables every quarter to remove outdated entries.
  • Protect Administrative Session Credentials: Remind network administrators to manage infrastructure using encrypted protocols only, avoiding plaintext management tools over unsecured networks.

Common Implementation Challenges

  • Automated Complacency: Caused by relying on software status checks without keeping manual test logs. Fix this by recording routine failover test results in work tracking tools like Jira and Confluence.
  • Single Point of Failure: Caused by systems lacking duplicate power units or extra network cables. Fix this by updating network topology charts in Confluence to spot and fix hidden security gaps.
  • Stale Documentation: Caused by keeping old redundancy plans that do not match live hardware setups. Fix this by reviewing and updating system documents and network baselines in SharePoint each month.
  • Untested Failover Plans: Caused by setting up backup servers but never testing if they take over during a crash. Fix this by running quarterly switchover tests and recording the results in your internal wiki.
  • Unmatched Backup Capacity: Caused by using smaller, slower spare servers that crash under normal work traffic. Fix this by ensuring backup network systems match the full power and bandwidth capacity of primary setups.
  • Unassigned System Owners: Caused by missing team leads for spare hardware, firewalls, and network units. Fix this by assigning named staff to inspect, update, and maintain all redundant network equipment.
  • Unmanaged Rule Accumulation: Caused by leaving temporary firewall rules open after emergency troubleshooting. Fix this by enforcing mandatory quarterly firewall rule audits to purge stale access permissions.
  • Shadow Network Expansion: Caused by team members deploying unsanctioned switches or access points. Fix this by enforcing strict network baseline controls and regular port security scans.

How to Measure Effectiveness (KPIs)

  • Unapproved Network Change Count: Tracks the number of unauthorized firewall rule or network setting adjustments detected during automated config checks.
  • Quarterly Rule Review Rate: Measures the percentage of active firewall rulesets and access control lists reviewed and cleaned on schedule every three months.
  • Network Intrusion Block Rate: Tracks the percentage of suspicious network traffic and unauthorized access attempts successfully stopped by perimeter controls.
  • Baseline Compliance Rate: Measures the percentage of active firewalls, routers, and switches that perfectly match approved baseline configuration standards.
  • Mean Time to Resolve Network Incidents: Measures the average time required for technical teams to investigate, contain, and fix confirmed network security events.
  • Network Segment Isolation Rate: Tracks how successfully corporate, guest, and production network zones remain fully segregated with zero unauthorized cross-zone traffic.
  • Obsolete Rule Purge Percentage: Tracks the proportion of redundant, temporary, or unused firewall rules identified and deleted following quarterly audits.
  • Network Logging Feed Uptime: Measures the uptime and coverage percentage of network security devices actively streaming audit logs to central logging repositories.

ISO 27001 Annex A 8.20 connects to several other ISO 27001 requirements.

  • ISO 27001 Clause 8.1 governs operational planning for network changes.
  • ISO 27001 Annex A 8.22 focuses on segregation of networks.
  • ISO 27001 Annex A 8.21 manages the security of network services. All these dependencies must link within your central SharePoint library.
ISO 27001 Networks Security Explained – Annex A 8.20 - ISO 27001.com
ISO 27001 Networks Security Explained – Annex A 8.20
ISO 27001 Annex A 8.20