The ultimate audit guide to ISO 27001 Annex A 8.20 Network Security
Table of contents
- 1. Network Security Policy Formalisation Verified
- 2. Network Segmentation and Segregation Confirmed
- 3. Restricted Use of Insecure Protocols Validated
- 4. Network Device Hardening Consistency Verified
- 5. Encryption for Data in Transit Confirmed
- 6. Intrusion Detection and Prevention (IDS/IPS) Presence Validated
- 7. Remote Access Security Enforcement Confirmed
- 8. Firewall Rule Base Integrity Verified
- 9. Network Management Tool Access Restricted
- 10. Wireless Network Security Validated
1. Network Security Policy Formalisation Verified
Verification Criteria: A documented policy exists defining the security requirements for network management, including baseline configurations and restricted protocols.
Required Evidence: Approved Network Security Policy or Infrastructure Hardening Standard with explicit version control.
Pass/Fail Test: If the organisation cannot produce a formal policy specifying the mandatory security controls for network equipment, mark as Non-Compliant.
2. Network Segmentation and Segregation Confirmed
Verification Criteria: Technical controls (VLANs, Subnets, or Micro-segmentation) separate the network into logical zones based on sensitivity and function (e.g., DMZ, Corporate, Guest).
Required Evidence: Current network topology diagram and firewall configuration logs showing active traffic isolation between zones.
Pass/Fail Test: If the Guest Wi-Fi or a low-security zone has direct, unfirewalled routing to the production database environment, mark as Non-Compliant.
3. Restricted Use of Insecure Protocols Validated
Verification Criteria: Legacy or insecure protocols (e.g., Telnet, FTP, HTTP, SMBv1) are disabled across all network devices in favour of secure alternatives (SSH, SFTP, HTTPS).
Required Evidence: Port scan results (Nmap) or device configuration exports showing specific port closures.
Pass/Fail Test: If any network management interface is accessible via unencrypted Telnet or HTTP, mark as Non-Compliant.
DO IT YOURSELF
ISO 27001
All the templates, tools, support and knowledge you need to do it yourself.
4. Network Device Hardening Consistency Verified
Verification Criteria: Routers, switches, and firewalls are hardened according to an established baseline, including the removal of default credentials and unused services.
Required Evidence: Hardening checklist sign-offs or configuration comparison reports against CIS Benchmarks.
Pass/Fail Test: If a sampled network switch is found running with factory-default administrative credentials, mark as Non-Compliant.
5. Encryption for Data in Transit Confirmed
Verification Criteria: Technical controls enforce the encryption of data traversing public or untrusted networks using modern protocols (TLS 1.2+ or IPsec VPNs).
Required Evidence: SSL/TLS certificate reports and VPN configuration settings for remote access and site-to-site tunnels.
Pass/Fail Test: If sensitive data is transmitted over the internet via plain-text protocols without a VPN or TLS wrapping, mark as Non-Compliant.
6. Intrusion Detection and Prevention (IDS/IPS) Presence Validated
Verification Criteria: Active monitoring and prevention systems are deployed at network boundaries to detect and block malicious traffic patterns.
Required Evidence: IDS/IPS dashboard screenshots and recent alert logs showing blocked attack signatures.
Pass/Fail Test: If the network perimeter lacks automated detection for common exploit patterns (e.g., SQL injection or brute force), mark as Non-Compliant.
7. Remote Access Security Enforcement Confirmed
Verification Criteria: All remote network access is authenticated via Multi-Factor Authentication (MFA) and restricted to managed or authorised endpoints.
Required Evidence: VPN configuration logs and MFA provider reports showing 100% enforcement for remote users.
Pass/Fail Test: If a user can establish a remote network connection (VPN) using only a single-factor password, mark as Non-Compliant.
8. Firewall Rule Base Integrity Verified
Verification Criteria: Firewall rules follow the “Deny All” principle, with only specifically authorised traffic permitted via the rule base.
Required Evidence: Firewall rule base export showing a “Cleanup” rule (Deny Any/Any) at the bottom of the list.
Pass/Fail Test: If the firewall contains “Any/Any” permit rules or has not undergone a formal rule review in the last 12 months, mark as Non-Compliant.
9. Network Management Tool Access Restricted
Verification Criteria: Access to network management consoles and monitoring tools is restricted to authorised IT personnel using dedicated administrative accounts.
Required Evidence: Access Control Lists (ACLs) for management subnets and RBAC logs from the network management platform.
Pass/Fail Test: If the network management interface (e.g., GUI/SSH) is accessible from the general staff VLAN or Guest network, mark as Non-Compliant.
10. Wireless Network Security Validated
Verification Criteria: Corporate wireless networks use robust authentication (e.g., WPA3 or WPA2-Enterprise with 802.1X) to prevent unauthorised association.
Required Evidence: Wireless Controller (WLC) configuration showing the authentication method and active client certificates.
Pass/Fail Test: If the corporate Wi-Fi relies on a shared Pre-Shared Key (PSK) rather than individual user/device certificates, mark as Non-Compliant.
