What is ISO 27001 Annex A 8.21 – Security of Network Services?
ISO 27001 Annex A 8.21 focuses on ensuring that the security mechanisms, service levels, and management requirements of network services are identified, implemented, and monitored.
Network services are a critical part of almost every organization’s technology environment.
Examples include:
- Internet connectivity
- Corporate networks
- Wi-Fi
- VPN
- Firewalls
- DNS
- DHCP
- Cloud networking
- Virtual private networks
- Network security services
- SD-WAN
- Network monitoring
- Managed network services
- Connectivity provided by third parties
Simple explanation
A.8.21 means the organization should define and manage the security requirements of its network services instead of treating network connectivity as simply an IT utility.
The organization should understand:
What network service do we use? → What security does it require? → Who provides it? → How is it protected? → How is it monitored?
What does A.8.21 require?
The organization should establish and implement security mechanisms, service levels, and management requirements for network services.
This applies whether the network service is:
- Managed internally
- Provided by a cloud provider
- Provided by an Internet Service Provider
- Managed by a third-party IT provider
- Hosted in a data center
- Delivered through a SaaS/network service provider
Security requirements should be appropriate to the organization’s:
- Business needs
- Information-security risks
- Data sensitivity
- Availability requirements
- Regulatory requirements
- Customer requirements
- Network architecture
Why is A.8.21 important?
A compromised network service can affect the confidentiality, integrity, and availability of business information.
For example:
- An insecure Wi-Fi network could allow unauthorized access.
- A poorly configured firewall could expose systems to the Internet.
- Weak VPN controls could allow unauthorized remote access.
- A DNS compromise could redirect users to malicious destinations.
- Poorly managed cloud networking could expose databases or applications.
- An unreliable network service could affect business availability.
Therefore, network services should have defined security requirements and appropriate monitoring.
What activities are required?
1. Identify network services
Create an inventory of important network services.
For example:
| Network Service | Provider | Purpose | Criticality |
|---|---|---|---|
| Internet | ISP | Internet connectivity | High |
| Firewall | Cloud/On-premise | Network protection | Critical |
| VPN | Security Provider | Remote access | High |
| DNS | DNS Provider | Name resolution | High |
| Wi-Fi | Internal | Office connectivity | Medium |
| Cloud Network | Cloud Provider | Application infrastructure | Critical |
| Network Monitoring | Security Provider | Monitoring | High |
2. Define security requirements
Each important network service should have appropriate security requirements.
Depending on the service, these may include:
- Encryption
- Authentication
- Access control
- Network segmentation
- Firewall protection
- Secure configuration
- Availability
- Redundancy
- Logging
- Monitoring
- Vulnerability management
- Incident response
- Backup/recovery
- Change management
- Service-level requirements
Not every requirement will apply equally to every network service.
3. Establish service levels
Where appropriate, define expected service levels.
For example:
- Availability target
- Incident response time
- Service restoration time
- Support availability
- Maintenance notification
- Security incident notification
- Escalation procedure
- Performance requirements
For critical network services, service-level requirements may be included in an SLA or contract.
4. Manage network service providers
When a network service is provided by a third party, the organization should understand:
- What security controls the provider operates
- What responsibilities belong to the provider
- What responsibilities belong to the organization
- How incidents are reported
- How service availability is managed
- How changes are communicated
- What security evidence is available
For cloud and managed-service environments, this is particularly important.
5. Implement network security controls
Depending on the environment, controls may include:
Firewalls
- Restrict unnecessary traffic
- Control inbound and outbound connections
- Review firewall rules periodically
- Restrict administrative access
VPN
- Strong authentication
- MFA where appropriate
- Encryption
- Restricted access
- User access reviews
- Logging
Wi-Fi
- Strong authentication
- Secure encryption
- Separate guest networks
- Restricted administrative access
- Secure configuration
Network segmentation
Separate environments where appropriate, such as:
- Production
- Development
- Corporate
- Guest
- Management
- Security infrastructure
6. Monitor network services
Network services should be monitored according to their criticality and risk.
Monitoring may include:
- Availability
- Network traffic
- Security events
- Firewall activity
- VPN activity
- Unauthorized connections
- Configuration changes
- Performance
- Service outages
- Suspicious network behavior
Relevant events should be investigated and escalated.
7. Review network configurations
Network configurations should be reviewed periodically and after significant changes.
Examples:
- Firewall rules
- VPN configuration
- Network access rules
- Routing
- Security groups
- Cloud network policies
- DNS configuration
- Wireless configuration
- Network segmentation
Unused or unnecessary rules should be removed where appropriate.
8. Integrate network services with incident management
Network-related incidents should be connected to the organization’s incident-response process.
Examples:
Firewall detects suspicious traffic
→ Security team investigates
→ Incident classified
→ Affected systems identified
→ Access blocked/contained
→ Evidence preserved
→ Incident escalated if necessary
→ Root cause investigated
→ Corrective action implemented
→ Incident closed
Example – SaaS Startup Using Cloud Infrastructure
Consider a SaaS startup that uses:
- AWS
- Cloudflare
- Corporate Wi-Fi
- VPN
- GitHub
- Remote employees
The organization identifies its critical network services.
Cloud network
Security requirements include:
- Restricted inbound access
- Security groups
- Network segmentation
- Restricted administrative access
- Logging
- Monitoring
VPN
Requirements include:
- Strong authentication
- MFA
- Authorized users only
- Logging
- Periodic access review
Cloudflare
Requirements may include:
- DNS security
- Web traffic protection
- Access controls
- Monitoring
- Availability
- Change management
Corporate Wi-Fi
Requirements include:
- Secure authentication
- Strong encryption
- Separate guest network
- Restricted administration
The company documents these requirements and periodically reviews whether the controls remain appropriate.
That provides a practical implementation of A.8.21.
What events should trigger action or review?
Network-service security requirements should be reviewed when significant changes occur.
Examples include:
| Trigger | Possible Action |
|---|---|
| New network provider | Perform security assessment |
| New cloud environment | Review network architecture |
| Firewall replacement | Review configuration |
| Major firewall-rule change | Security review |
| New remote-access solution | Assess authentication and access controls |
| Network outage | Investigate availability |
| Security incident | Review network controls |
| Critical vulnerability | Assess affected services |
| New customer requirement | Review network security |
| Regulatory requirement | Update controls |
| Major infrastructure migration | Reassess network architecture |
| Change in network provider | Review contract/SLA/security requirements |
Startup-Focused Quick Summary
Does a startup need complex network infrastructure?
No.
A startup using cloud services can still implement A.8.21 effectively.
The key question is:
Are the organization’s important network services protected according to their security and business requirements?
A small SaaS startup may only have:
- Cloud networking
- Internet
- DNS/CDN
- VPN or zero-trust access
- Office Wi-Fi
- Firewall/WAF
That can still be sufficient for implementing the control.
Minimum startup implementation
A startup can begin with:
- Create a network-service inventory.
- Identify critical network services.
- Define security requirements.
- Document providers and responsibilities.
- Configure appropriate security controls.
- Enable logging and monitoring.
- Review critical configurations periodically.
- Maintain provider SLAs/contracts where appropriate.
- Connect network incidents to incident management.
- Keep evidence of reviews and changes.
Simple rule
Don’t manage network services only for connectivity. Manage them for security, availability and controlled access.
Example Network Services Security Register
| Service | Security Requirement | Owner | Provider | Monitoring | Review Frequency |
|---|---|---|---|---|---|
| Internet | Availability, secure gateway | IT | ISP | Availability monitoring | Annual |
| Firewall | Access control, logging | Security | Internal/Provider | Security monitoring | Quarterly |
| VPN | MFA, encryption, logging | IT/Security | Provider | Access logs | Quarterly |
| DNS | Secure administration, availability | IT | Provider | DNS monitoring | Annual |
| Cloud Network | Segmentation, restricted access | Cloud Team | Cloud Provider | Cloud monitoring | Quarterly |
| Wi-Fi | Secure authentication, encryption | IT | Internal | Network monitoring | Quarterly |
The frequency should be determined based on risk and business requirements rather than applying the same frequency to every service.
Network Security Requirements Checklist
For each critical network service, consider:
Access Control
- Who can administer the service?
- Is privileged access restricted?
- Is MFA implemented where appropriate?
- Are unused accounts removed?
Encryption
- Is sensitive communication encrypted?
- Are secure protocols being used?
- Are insecure protocols disabled where appropriate?
Availability
- Is the service business-critical?
- Is redundancy required?
- Are backup connectivity arrangements required?
Monitoring
- Are relevant logs generated?
- Are security events monitored?
- Are alerts configured?
Configuration
- Are secure configurations implemented?
- Are unnecessary ports/services disabled?
- Are firewall rules reviewed?
Provider Management
- Is the provider identified?
- Are security responsibilities documented?
- Is an SLA or contract in place where appropriate?
- Are security incidents reported to the organization?
A.8.21 Audit Evidence
An auditor may request evidence such as:
Network documentation
- Network architecture diagram
- Network-service inventory
- Network security requirements
- Firewall architecture
- Network segmentation design
- VPN architecture
Configuration evidence
- Firewall configuration
- Firewall rule review
- VPN configuration
- Security group configuration
- Network access-control configuration
- Wi-Fi security configuration
- Cloud network configuration
Monitoring evidence
- Firewall logs
- VPN logs
- Network monitoring reports
- Security alerts
- Availability monitoring
- Incident tickets
Provider evidence
- Network service contracts
- SLA
- Security requirements
- Provider security documentation
- Security assessment
- Relevant assurance reports
Review evidence
- Firewall-rule review
- Network configuration review
- Access review
- Change records
- Vulnerability assessment
- Network security testing
A.8.21 Audit Checklist
| Audit Question | Evidence |
|---|---|
| Have important network services been identified? | Network Service Inventory |
| Are security requirements defined? | Security Requirements |
| Are critical services identified? | Risk Assessment |
| Are network service providers documented? | Supplier Register |
| Are responsibilities defined? | RACI / Contracts |
| Are appropriate security controls implemented? | Configurations |
| Is network traffic/security activity monitored? | Logs/Monitoring |
| Are firewall rules periodically reviewed? | Review Records |
| Is remote access protected? | VPN/MFA Evidence |
| Is network segmentation implemented where required? | Network Diagram/Configuration |
| Are network changes controlled? | Change Records |
| Are incidents involving network services managed? | Incident Records |
| Are provider security requirements reviewed? | Supplier Assessment |
| Is service availability monitored? | Monitoring/SLA Reports |
Common Mistakes
1. Treating the ISP as the only network service
Network services include much more than Internet connectivity.
Cloud networking, VPN, DNS, firewalls, WAFs, Wi-Fi and managed network services may also be relevant.
2. No documented security requirements
Organizations may have technically secure infrastructure but cannot demonstrate what security requirements were established.
3. No ownership
It should be clear who manages each critical network service.
4. Excessive firewall permissions
Overly permissive firewall rules can create unnecessary exposure.
5. No firewall-rule review
Firewall configurations can become increasingly complex over time.
Unused or unnecessary rules should be identified and removed where appropriate.
6. Poor remote-access security
Remote access should be appropriately protected through authentication, authorization, encryption and monitoring.
7. Ignoring third-party providers
When a provider manages a network service, security responsibilities should be understood rather than assumed.
8. No monitoring
Having a firewall or VPN does not automatically mean the service is being effectively monitored.
Practical Implementation Model
A practical A.8.21 implementation model is:
Identify Network Services
↓
Classify Criticality
↓
Define Security Requirements
↓
Define Service Levels
↓
Assign Ownership
↓
Implement Security Controls
↓
Monitor
↓
Review Configurations
↓
Manage Changes
↓
Assess Incidents
↓
Improve
Policy vs. Requirement vs. Evidence
| Element | Example |
|---|---|
| Policy | Network services must be appropriately secured and managed. |
| Security Requirement | VPN must use strong authentication and encryption. |
| Implementation | MFA and encrypted VPN connections are configured. |
| Evidence | VPN configuration, logs, access review and security testing. |
This distinction is important during an ISO 27001 audit.
A policy saying “network services shall be secure” is not enough.
The organization should be able to demonstrate defined requirements, implementation and ongoing management.
Useful Resources
Recommended documents
- Draft Network Services Security Standard – [Insert Draft Document Link]
- Network Security Policy – [Insert Draft Document Link]
- Network Service Inventory Template – [Insert Draft Document Link]
- Firewall Rule Review Checklist – [Insert Draft Document Link]
- Network Architecture Diagram Template – [Insert Draft Document Link]
- VPN Security Standard – [Insert Draft Document Link]
- Cloud Network Security Checklist – [Insert Draft Document Link]
- Network Change Management Procedure – [Insert Draft Document Link]
Related ISO 27001 controls
A.8.21 works closely with:
- A.5.19 – Information security in supplier relationships
- A.5.20 – Addressing information security within supplier agreements
- A.5.22 – Monitoring, review and change management of supplier services
- A.5.23 – Information security for use of cloud services
- A.8.2 – Privileged access rights
- A.8.5 – Secure authentication
- A.8.9 – Configuration management
- A.8.13 – Information backup
- A.8.15 – Logging
- A.8.16 – Monitoring activities
- A.8.20 – Network security
- A.8.22 – Segregation of networks
Final Takeaway
ISO 27001 Annex A 8.21 is about ensuring that network services have appropriate security requirements, service levels and management arrangements.
A practical organization should be able to answer:
What network services do we depend on?
Which are critical?
What security requirements apply?
Who manages them?
How are they monitored?
How do we know they remain secure?
For a startup, this does not require a complex enterprise network.
A cloud-native startup can implement the control around its cloud network, firewall/WAF, DNS, VPN/remote access, Wi-Fi and network-service providers.
A.8.21 = Identify → Define Requirements → Secure → Monitor → Review → Improve.
