ISO 27001 Networks Security
ISO 27001 Annex A 8.20 Network Security is an ISO 27001 control that requires us to secure our networks and document that we are doing so.
Table of contents
- ISO 27001 Networks Security
- Key Takeaways
- Purpose
- Definition
- Explanation
- Requirement
- Audit Focus
- FREE Training Video
- Guidance
- Documentation
- Roles and Responsibilities
- Logging and Monitoring
- Technical Considerations
- Virtual Networks
- Network Security Policy Template
- How to implement it
- What will an auditor check?
- ISO 27001 Templates
- Applicability across different business models
- Network Security Policy Example
- FAQ
- Related ISO 27001 Controls
- Further Reading
- About the author
Key Takeaways
ISO 27001 Annex A 8.20 requires organizations to secure, manage, and control their networks and network devices. Its primary purpose is to protect the information within applications and systems from being compromised via the network. This involves a combination of up-to-date documentation, strict access controls, and technical hardening of network infrastructure.
Purpose
ISO 27001 Annex A 8.20 is a preventive control and a detective control to protect information in networks and its supporting information processing facilities from compromise via the network..
Definition
The ISO 27001 standard defines ISO 27001 Annex A 8.20 as:
Networks and network devices should be secured, managed and controlled to protect information in systems and applications.
ISO27001:2022 Annex A 8.20 Network Security
Explanation
ISO 27001 Annex A 8.20 is a security control that mandates the implementation of network security measures to protect information systems. It requires organizations to secure, manage, and control networks and devices by establishing network boundaries, managing traffic, and ensuring only authorized access, thereby safeguarding data confidentiality and integrity against unauthorised access or interception.
Requirement
- Up-to-Date Documentation: You must maintain current network diagrams and device configuration files. These aren’t just technical aids; they are essential audit artifacts that must be version-controlled and classified (usually as “Confidential”).
- Network Hardening: Default settings are a security risk. You must remove default passwords, disable unnecessary services/protocols, and ensure all network devices (routers, switches, firewalls) are patched and securely configured.
- Segregated Management: Administrative access to network devices should be separated from standard user traffic. This prevents an attacker on the general network from easily targeting the “keys to the kingdom.”
- Monitoring & Logging: You must implement logging for all security-relevant network events. This allows you to not only detect active threats but also provide a “forensic trail” if a compromise occurs.
Audit Focus
- Visibility: “Show me your network diagram. Is it accurate to what is actually plugged in today?”
- Configuration Control: “Show me the logs for the last time a firewall rule was changed. Who authorized it?”
- Authentication: “How do you manage administrative access to your switches? Are you still using the factory default ‘admin’ password?”
FREE Training Video
In this free training video you will learn How to implement ISO 27001 Network Security (Annex A 8.20) and Pass Your Audit
Guidance
This control is looking for us to have control over our networks. We are going to ensure the information security in networks and protect connected services from un authorised access. The are a few things to consider so lets go through them.
Documentation
Documentation plays a large part in the standard and that is equally true of networks. This is usually an area where organisations struggle. Keeping up to date network documentation. But it is key to this control and passing the audit.
The documentation that is expected includes network diagrams and configuration files of devices. This documentation is also expected to have the document hygiene that includes document classification and version control. Again, this can often be overlooked.
Included in the documentation would be the classification level of the data that is carried over the network. As a rule, to simplify it, all organisation networks would be classed as confidential and public access / guest networks would be classified as public.
Roles and Responsibilities
Network management is a specialist activity that requires trained and experienced professionals. As a result you would document the roles and responsibilities including recording who is performing the role. Around this would be the usual access management processes of requesting, authorising and providing access as well as the segregation of duties to remove conflicts.
Logging and Monitoring
As part of the network implementation you will include appropriate logging and monitoring for actions that are relevant to information security.
Technical Considerations
Under advisement of your technical teams you will consider technical elements such as encryption of data in transit, restrictions and filtering of connections to the network and the use of firewalls, hardening of network devices, removal of default passwords and services, disabling vulnerable network protocols, authenticating systems on the network, segregating admin channels from other network channels.
Virtual Networks
Virtual networks can add an additional layer of security and appropriate security controls should be applied. There is a standard that covers Virtual Networks and it is ISO/IEC TS 23167.
Network Security Policy Template
The network security policy sets out the approach to network security.

How to implement it
Establishing robust network security is a cornerstone of ISO 27001 compliance, designed to protect the confidentiality, integrity, and availability of data as it moves across your infrastructure. By following these technical implementation steps, your organisation can effectively harden network boundaries and mitigate the risk of unauthorised access or lateral movement.
1. Formalise Network Security Policies and ROE
- Draft a formal Network Security Policy that defines the baseline configurations, permitted protocols, and prohibited services across the estate.
- Establish a Rules of Engagement (ROE) document for network administrators and third-party managed service providers (MSPs) to ensure clear accountability.
- Result: A documented governance framework that serves as the legal and technical foundation for all network security controls.
2. Provision Network Segmentation and VLAN Isolation
- Utilise Virtual Local Area Networks (VLANs) and subnets to logically separate distinct business functions, such as Finance, HR, and guest traffic.
- Implement micro-segmentation for critical server environments to prevent lateral movement in the event of a single-host compromise.
- Result: A reduced blast radius that ensures a security breach in one segment cannot easily migrate to sensitive data zones.
3. Enforce Perimeter Defences and TLS Inspection
- Deploy Next-Generation Firewalls (NGFW) and Intrusion Prevention Systems (IPS) at all network entry and exit points to monitor for malicious patterns.
- Enable TLS inspection on web gateways to scan encrypted traffic for hidden malware payloads and data exfiltration attempts.
- Result: Real-time blocking of known threats and visibility into previously “blind” encrypted communication channels.
4. Restrict Administrative Access via IAM and MFA
- Configure granular Identity and Access Management (IAM) roles for network infrastructure, ensuring only authorised personnel can modify device configurations.
- Mandate Multi-Factor Authentication (MFA) for all administrative logins, particularly for remote access via VPN or cloud-based management consoles.
- Result: Elimination of risks associated with credential theft and unauthorised infrastructure tampering.
5. Execute Continuous Vulnerability Scanning and Hashing
- Schedule automated network vulnerability scans to identify open ports, insecure protocols (e.g. Telnet, FTP), and unpatched firmware.
- Use cryptographic hashing to verify the integrity of router and switch configuration files, ensuring no unauthorised changes have occurred.
- Result: Proactive identification of technical weaknesses and the ability to detect configuration drift in real time.
6. Implement Centralised Logging and SIEM Integration
- Configure all network devices to export Syslog and NetFlow data to a centralised Security Information and Event Management (SIEM) platform.
- Establish automated alerts for high-risk events, such as brute-force attempts on network gateways or unauthorised internal connection requests.
- Result: Comprehensive situational awareness and a verifiable audit trail for ISO 27001 compliance reviews and forensic investigations.
Hello. I am Stuart Barker.
CEO here at High Table: The Compliance Agency
If you want help by the hour, internal audit or consulting support …

What will an auditor check?
The audit is going to check a number of areas. Lets go through the main ones
1. That you have documentation
What this means is that you need to show that you have documented your network. Can you show network diagrams, a list of devices and their configurations, logs of configuration changes, roles and responsibilities?
2. That you have have implemented Network Security appropriately
They will look at systems to seek evidence of network security. They will question you on the process and seek evidence that you have followed it. They want to see evidence of network security and the process in operation.
3. That you have conducted internal audits
The audit will want to see that you have tested the controls and evidenced that they are operating. This is usually in the form of the required internal audits. They will check the records and outputs of those internal audits.
ISO 27001 Templates

Applicability across different business models
| Business Type | Applicability | Examples of Control Implementation |
|---|---|---|
| Small Businesses | Focuses on securing physical office hardware and basic internet connectivity. Ensuring that standard routers and Wi-Fi access points are hardened against common attacks. |
|
| Tech Startups | Critical for cloud-native infrastructures. Focuses on logical network control, managing Virtual Private Clouds (VPCs), and securing remote access for distributed teams. |
|
| AI Companies | Vital for protecting massive datasets and high-value model IP. Focuses on high-speed data transfer security and isolating sensitive training environments. |
|
Network Security Policy Example
An example of the ISO 27001 Network Security Policy.

FAQ
Responsibility usually lies with the IT or Network Security team, specifically those with specialist training. However, the standard requires clear segregation of duties to prevent conflicts of interest.
Network Administrators: Responsible for day-to-day configuration and maintenance.
Security Officers: Responsible for monitoring logs and auditing configurations.
Authorisation: A separate role should authorize significant changes (e.g., opening a firewall port) before implementation.
Yes, network segmentation is a critical component of securing networks under Annex A 8.20. While often detailed further in Annex A 8.22 (Segregation of Networks), control 8.20 requires you to manage and control the flow of information to prevent unauthorized access.
Guest Networks: Must be completely isolated from corporate production networks.
Admin Segregation: Management interfaces should not be accessible from the general user network.
Traffic Filtering: Use VLANs and firewalls to restrict traffic between different business units or security zones.
Auditors primarily verify compliance by examining your network documentation, configuration logs, and access control records. They will look for proof that your documented policies match the actual configuration of your live environment.
Network Diagrams: Must be current, dated, and accurately reflect physical and logical topologies.
Configuration Logs: Evidence of who changed firewall rules or device settings and when.
Access Reviews: Records showing regular reviews of who has administrative access to network gear.
Asset Inventory: A complete list of network devices (switches, routers, WAPs) and their owners.
Yes, encryption is a standard technical measure required to protect information in transit across networks. You must ensure that data moving between systems or over public networks is protected against interception.
Protocols: Use secure protocols like TLS/SSL for web traffic and IPsec for VPNs.
Management: Ensure management interfaces (e.g., SSH, HTTPS) are encrypted to protect admin credentials.
Policy: Define encryption standards in your Network Security Policy.
Related ISO 27001 Controls
Further Reading
- ISO 27001 Physical and Virtual Asset Register Template
- ISO 27001 Documented Information Beginner’s Guide
About the author






