ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 5. ISO 27001 Annex A - 8 ...
  5. ISO 27001 Annex A 8.21 Security of network services

ISO 27001 Annex A 8.21 Security of network services

What is ISO 27001 Annex A 8.21 – Security of Network Services?

ISO 27001 Annex A 8.21 focuses on ensuring that the security mechanisms, service levels, and management requirements of network services are identified, implemented, and monitored.

Network services are a critical part of almost every organization’s technology environment.

Examples include:

  • Internet connectivity
  • Corporate networks
  • Wi-Fi
  • VPN
  • Firewalls
  • DNS
  • DHCP
  • Cloud networking
  • Virtual private networks
  • Network security services
  • SD-WAN
  • Network monitoring
  • Managed network services
  • Connectivity provided by third parties

Simple explanation

A.8.21 means the organization should define and manage the security requirements of its network services instead of treating network connectivity as simply an IT utility.

The organization should understand:

What network service do we use? → What security does it require? → Who provides it? → How is it protected? → How is it monitored?


What does A.8.21 require?

The organization should establish and implement security mechanisms, service levels, and management requirements for network services.

This applies whether the network service is:

  • Managed internally
  • Provided by a cloud provider
  • Provided by an Internet Service Provider
  • Managed by a third-party IT provider
  • Hosted in a data center
  • Delivered through a SaaS/network service provider

Security requirements should be appropriate to the organization’s:

  • Business needs
  • Information-security risks
  • Data sensitivity
  • Availability requirements
  • Regulatory requirements
  • Customer requirements
  • Network architecture

Why is A.8.21 important?

A compromised network service can affect the confidentiality, integrity, and availability of business information.

For example:

  • An insecure Wi-Fi network could allow unauthorized access.
  • A poorly configured firewall could expose systems to the Internet.
  • Weak VPN controls could allow unauthorized remote access.
  • A DNS compromise could redirect users to malicious destinations.
  • Poorly managed cloud networking could expose databases or applications.
  • An unreliable network service could affect business availability.

Therefore, network services should have defined security requirements and appropriate monitoring.


What activities are required?

1. Identify network services

Create an inventory of important network services.

For example:

Network ServiceProviderPurposeCriticality
InternetISPInternet connectivityHigh
FirewallCloud/On-premiseNetwork protectionCritical
VPNSecurity ProviderRemote accessHigh
DNSDNS ProviderName resolutionHigh
Wi-FiInternalOffice connectivityMedium
Cloud NetworkCloud ProviderApplication infrastructureCritical
Network MonitoringSecurity ProviderMonitoringHigh

2. Define security requirements

Each important network service should have appropriate security requirements.

Depending on the service, these may include:

  • Encryption
  • Authentication
  • Access control
  • Network segmentation
  • Firewall protection
  • Secure configuration
  • Availability
  • Redundancy
  • Logging
  • Monitoring
  • Vulnerability management
  • Incident response
  • Backup/recovery
  • Change management
  • Service-level requirements

Not every requirement will apply equally to every network service.


3. Establish service levels

Where appropriate, define expected service levels.

For example:

  • Availability target
  • Incident response time
  • Service restoration time
  • Support availability
  • Maintenance notification
  • Security incident notification
  • Escalation procedure
  • Performance requirements

For critical network services, service-level requirements may be included in an SLA or contract.


4. Manage network service providers

When a network service is provided by a third party, the organization should understand:

  • What security controls the provider operates
  • What responsibilities belong to the provider
  • What responsibilities belong to the organization
  • How incidents are reported
  • How service availability is managed
  • How changes are communicated
  • What security evidence is available

For cloud and managed-service environments, this is particularly important.


5. Implement network security controls

Depending on the environment, controls may include:

Firewalls

  • Restrict unnecessary traffic
  • Control inbound and outbound connections
  • Review firewall rules periodically
  • Restrict administrative access

VPN

  • Strong authentication
  • MFA where appropriate
  • Encryption
  • Restricted access
  • User access reviews
  • Logging

Wi-Fi

  • Strong authentication
  • Secure encryption
  • Separate guest networks
  • Restricted administrative access
  • Secure configuration

Network segmentation

Separate environments where appropriate, such as:

  • Production
  • Development
  • Corporate
  • Guest
  • Management
  • Security infrastructure

6. Monitor network services

Network services should be monitored according to their criticality and risk.

Monitoring may include:

  • Availability
  • Network traffic
  • Security events
  • Firewall activity
  • VPN activity
  • Unauthorized connections
  • Configuration changes
  • Performance
  • Service outages
  • Suspicious network behavior

Relevant events should be investigated and escalated.


7. Review network configurations

Network configurations should be reviewed periodically and after significant changes.

Examples:

  • Firewall rules
  • VPN configuration
  • Network access rules
  • Routing
  • Security groups
  • Cloud network policies
  • DNS configuration
  • Wireless configuration
  • Network segmentation

Unused or unnecessary rules should be removed where appropriate.


8. Integrate network services with incident management

Network-related incidents should be connected to the organization’s incident-response process.

Examples:

Firewall detects suspicious traffic

→ Security team investigates

→ Incident classified

→ Affected systems identified

→ Access blocked/contained

→ Evidence preserved

→ Incident escalated if necessary

→ Root cause investigated

→ Corrective action implemented

→ Incident closed


Example – SaaS Startup Using Cloud Infrastructure

Consider a SaaS startup that uses:

  • AWS
  • Cloudflare
  • Corporate Wi-Fi
  • VPN
  • GitHub
  • Remote employees

The organization identifies its critical network services.

Cloud network

Security requirements include:

  • Restricted inbound access
  • Security groups
  • Network segmentation
  • Restricted administrative access
  • Logging
  • Monitoring

VPN

Requirements include:

  • Strong authentication
  • MFA
  • Authorized users only
  • Logging
  • Periodic access review

Cloudflare

Requirements may include:

  • DNS security
  • Web traffic protection
  • Access controls
  • Monitoring
  • Availability
  • Change management

Corporate Wi-Fi

Requirements include:

  • Secure authentication
  • Strong encryption
  • Separate guest network
  • Restricted administration

The company documents these requirements and periodically reviews whether the controls remain appropriate.

That provides a practical implementation of A.8.21.


What events should trigger action or review?

Network-service security requirements should be reviewed when significant changes occur.

Examples include:

TriggerPossible Action
New network providerPerform security assessment
New cloud environmentReview network architecture
Firewall replacementReview configuration
Major firewall-rule changeSecurity review
New remote-access solutionAssess authentication and access controls
Network outageInvestigate availability
Security incidentReview network controls
Critical vulnerabilityAssess affected services
New customer requirementReview network security
Regulatory requirementUpdate controls
Major infrastructure migrationReassess network architecture
Change in network providerReview contract/SLA/security requirements

Startup-Focused Quick Summary

Does a startup need complex network infrastructure?

No.

A startup using cloud services can still implement A.8.21 effectively.

The key question is:

Are the organization’s important network services protected according to their security and business requirements?

A small SaaS startup may only have:

  • Cloud networking
  • Internet
  • DNS/CDN
  • VPN or zero-trust access
  • Office Wi-Fi
  • Firewall/WAF

That can still be sufficient for implementing the control.

Minimum startup implementation

A startup can begin with:

  1. Create a network-service inventory.
  2. Identify critical network services.
  3. Define security requirements.
  4. Document providers and responsibilities.
  5. Configure appropriate security controls.
  6. Enable logging and monitoring.
  7. Review critical configurations periodically.
  8. Maintain provider SLAs/contracts where appropriate.
  9. Connect network incidents to incident management.
  10. Keep evidence of reviews and changes.

Simple rule

Don’t manage network services only for connectivity. Manage them for security, availability and controlled access.


Example Network Services Security Register

ServiceSecurity RequirementOwnerProviderMonitoringReview Frequency
InternetAvailability, secure gatewayITISPAvailability monitoringAnnual
FirewallAccess control, loggingSecurityInternal/ProviderSecurity monitoringQuarterly
VPNMFA, encryption, loggingIT/SecurityProviderAccess logsQuarterly
DNSSecure administration, availabilityITProviderDNS monitoringAnnual
Cloud NetworkSegmentation, restricted accessCloud TeamCloud ProviderCloud monitoringQuarterly
Wi-FiSecure authentication, encryptionITInternalNetwork monitoringQuarterly

The frequency should be determined based on risk and business requirements rather than applying the same frequency to every service.


Network Security Requirements Checklist

For each critical network service, consider:

Access Control

  • Who can administer the service?
  • Is privileged access restricted?
  • Is MFA implemented where appropriate?
  • Are unused accounts removed?

Encryption

  • Is sensitive communication encrypted?
  • Are secure protocols being used?
  • Are insecure protocols disabled where appropriate?

Availability

  • Is the service business-critical?
  • Is redundancy required?
  • Are backup connectivity arrangements required?

Monitoring

  • Are relevant logs generated?
  • Are security events monitored?
  • Are alerts configured?

Configuration

  • Are secure configurations implemented?
  • Are unnecessary ports/services disabled?
  • Are firewall rules reviewed?

Provider Management

  • Is the provider identified?
  • Are security responsibilities documented?
  • Is an SLA or contract in place where appropriate?
  • Are security incidents reported to the organization?

A.8.21 Audit Evidence

An auditor may request evidence such as:

Network documentation

  • Network architecture diagram
  • Network-service inventory
  • Network security requirements
  • Firewall architecture
  • Network segmentation design
  • VPN architecture

Configuration evidence

  • Firewall configuration
  • Firewall rule review
  • VPN configuration
  • Security group configuration
  • Network access-control configuration
  • Wi-Fi security configuration
  • Cloud network configuration

Monitoring evidence

  • Firewall logs
  • VPN logs
  • Network monitoring reports
  • Security alerts
  • Availability monitoring
  • Incident tickets

Provider evidence

  • Network service contracts
  • SLA
  • Security requirements
  • Provider security documentation
  • Security assessment
  • Relevant assurance reports

Review evidence

  • Firewall-rule review
  • Network configuration review
  • Access review
  • Change records
  • Vulnerability assessment
  • Network security testing

A.8.21 Audit Checklist

Audit QuestionEvidence
Have important network services been identified?Network Service Inventory
Are security requirements defined?Security Requirements
Are critical services identified?Risk Assessment
Are network service providers documented?Supplier Register
Are responsibilities defined?RACI / Contracts
Are appropriate security controls implemented?Configurations
Is network traffic/security activity monitored?Logs/Monitoring
Are firewall rules periodically reviewed?Review Records
Is remote access protected?VPN/MFA Evidence
Is network segmentation implemented where required?Network Diagram/Configuration
Are network changes controlled?Change Records
Are incidents involving network services managed?Incident Records
Are provider security requirements reviewed?Supplier Assessment
Is service availability monitored?Monitoring/SLA Reports

Common Mistakes

1. Treating the ISP as the only network service

Network services include much more than Internet connectivity.

Cloud networking, VPN, DNS, firewalls, WAFs, Wi-Fi and managed network services may also be relevant.

2. No documented security requirements

Organizations may have technically secure infrastructure but cannot demonstrate what security requirements were established.

3. No ownership

It should be clear who manages each critical network service.

4. Excessive firewall permissions

Overly permissive firewall rules can create unnecessary exposure.

5. No firewall-rule review

Firewall configurations can become increasingly complex over time.

Unused or unnecessary rules should be identified and removed where appropriate.

6. Poor remote-access security

Remote access should be appropriately protected through authentication, authorization, encryption and monitoring.

7. Ignoring third-party providers

When a provider manages a network service, security responsibilities should be understood rather than assumed.

8. No monitoring

Having a firewall or VPN does not automatically mean the service is being effectively monitored.


Practical Implementation Model

A practical A.8.21 implementation model is:

Identify Network Services

↓

Classify Criticality

↓

Define Security Requirements

↓

Define Service Levels

↓

Assign Ownership

↓

Implement Security Controls

↓

Monitor

↓

Review Configurations

↓

Manage Changes

↓

Assess Incidents

↓

Improve


Policy vs. Requirement vs. Evidence

ElementExample
PolicyNetwork services must be appropriately secured and managed.
Security RequirementVPN must use strong authentication and encryption.
ImplementationMFA and encrypted VPN connections are configured.
EvidenceVPN configuration, logs, access review and security testing.

This distinction is important during an ISO 27001 audit.

A policy saying “network services shall be secure” is not enough.

The organization should be able to demonstrate defined requirements, implementation and ongoing management.


Useful Resources

Recommended documents

  • Draft Network Services Security Standard – [Insert Draft Document Link]
  • Network Security Policy – [Insert Draft Document Link]
  • Network Service Inventory Template – [Insert Draft Document Link]
  • Firewall Rule Review Checklist – [Insert Draft Document Link]
  • Network Architecture Diagram Template – [Insert Draft Document Link]
  • VPN Security Standard – [Insert Draft Document Link]
  • Cloud Network Security Checklist – [Insert Draft Document Link]
  • Network Change Management Procedure – [Insert Draft Document Link]

Related ISO 27001 controls

A.8.21 works closely with:

  • A.5.19 – Information security in supplier relationships
  • A.5.20 – Addressing information security within supplier agreements
  • A.5.22 – Monitoring, review and change management of supplier services
  • A.5.23 – Information security for use of cloud services
  • A.8.2 – Privileged access rights
  • A.8.5 – Secure authentication
  • A.8.9 – Configuration management
  • A.8.13 – Information backup
  • A.8.15 – Logging
  • A.8.16 – Monitoring activities
  • A.8.20 – Network security
  • A.8.22 – Segregation of networks

Final Takeaway

ISO 27001 Annex A 8.21 is about ensuring that network services have appropriate security requirements, service levels and management arrangements.

A practical organization should be able to answer:

What network services do we depend on?
Which are critical?
What security requirements apply?
Who manages them?
How are they monitored?
How do we know they remain secure?

For a startup, this does not require a complex enterprise network.

A cloud-native startup can implement the control around its cloud network, firewall/WAF, DNS, VPN/remote access, Wi-Fi and network-service providers.

A.8.21 = Identify → Define Requirements → Secure → Monitor → Review → Improve.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *