ISO 27001 Annex A 8.20 Networks Security Explained

Stuart Barker - High Table - ISO27001 Director

ISO 27001 Networks Security

ISO 27001 Annex A 8.20 Network Security is an ISO 27001 control that requires us to secure our networks and document that we are doing so.

Key Takeaways

ISO 27001 Annex A 8.20 requires organizations to secure, manage, and control their networks and network devices. Its primary purpose is to protect the information within applications and systems from being compromised via the network. This involves a combination of up-to-date documentation, strict access controls, and technical hardening of network infrastructure.

Purpose

ISO 27001 Annex A 8.20 is a preventive control and a detective control to protect information in networks and its supporting information processing facilities from compromise via the network..

Definition

The ISO 27001 standard defines ISO 27001 Annex A 8.20 as:

Networks and network devices should be secured, managed and controlled to protect information in systems and applications.

ISO27001:2022 Annex A 8.20 Network Security

Explanation

ISO 27001 Annex A 8.20 is a security control that mandates the implementation of network security measures to protect information systems. It requires organizations to secure, manage, and control networks and devices by establishing network boundaries, managing traffic, and ensuring only authorized access, thereby safeguarding data confidentiality and integrity against unauthorised access or interception.

Requirement

  • Up-to-Date Documentation: You must maintain current network diagrams and device configuration files. These aren’t just technical aids; they are essential audit artifacts that must be version-controlled and classified (usually as “Confidential”).
  • Network Hardening: Default settings are a security risk. You must remove default passwords, disable unnecessary services/protocols, and ensure all network devices (routers, switches, firewalls) are patched and securely configured.
  • Segregated Management: Administrative access to network devices should be separated from standard user traffic. This prevents an attacker on the general network from easily targeting the “keys to the kingdom.”
  • Monitoring & Logging: You must implement logging for all security-relevant network events. This allows you to not only detect active threats but also provide a “forensic trail” if a compromise occurs.

Audit Focus

  1. Visibility: “Show me your network diagram. Is it accurate to what is actually plugged in today?”
  2. Configuration Control: “Show me the logs for the last time a firewall rule was changed. Who authorized it?”
  3. Authentication: “How do you manage administrative access to your switches? Are you still using the factory default ‘admin’ password?”

FREE Training Video

In this free training video you will learn How to implement ISO 27001 Network Security (Annex A 8.20) and Pass Your Audit

Guidance

This control is looking for us to have control over our networks. We are going to ensure the information security in networks and protect connected services from un authorised access. The are a few things to consider so lets go through them.

Documentation

Documentation plays a large part in the standard and that is equally true of networks. This is usually an area where organisations struggle. Keeping up to date network documentation. But it is key to this control and passing the audit.

The documentation that is expected includes network diagrams and configuration files of devices. This documentation is also expected to have the document hygiene that includes document classification and version control. Again, this can often be overlooked.

Included in the documentation would be the classification level of the data that is carried over the network. As a rule, to simplify it, all organisation networks would be classed as confidential and public access / guest networks would be classified as public.

Roles and Responsibilities

Network management is a specialist activity that requires trained and experienced professionals. As a result you would document the roles and responsibilities including recording who is performing the role. Around this would be the usual access management processes of requesting, authorising and providing access as well as the segregation of duties to remove conflicts.

Logging and Monitoring

As part of the network implementation you will include appropriate logging and monitoring for actions that are relevant to information security.

Technical Considerations

Under advisement of your technical teams you will consider technical elements such as encryption of data in transit, restrictions and filtering of connections to the network and the use of firewalls, hardening of network devices, removal of default passwords and services, disabling vulnerable network protocols, authenticating systems on the network, segregating admin channels from other network channels.

Virtual Networks

Virtual networks can add an additional layer of security and appropriate security controls should be applied. There is a standard that covers Virtual Networks and it is ISO/IEC TS 23167.

Network Security Policy Template

The network security policy sets out the approach to network security.

ISO 27001 Network Security Management Policy Template - ISO 27001 Annex A 8.20 Networks Security Template
ISO 27001 Network Security Policy Template

How to implement it

Establishing robust network security is a cornerstone of ISO 27001 compliance, designed to protect the confidentiality, integrity, and availability of data as it moves across your infrastructure. By following these technical implementation steps, your organisation can effectively harden network boundaries and mitigate the risk of unauthorised access or lateral movement.

1. Formalise Network Security Policies and ROE

  • Draft a formal Network Security Policy that defines the baseline configurations, permitted protocols, and prohibited services across the estate.
  • Establish a Rules of Engagement (ROE) document for network administrators and third-party managed service providers (MSPs) to ensure clear accountability.
  • Result: A documented governance framework that serves as the legal and technical foundation for all network security controls.

2. Provision Network Segmentation and VLAN Isolation

  • Utilise Virtual Local Area Networks (VLANs) and subnets to logically separate distinct business functions, such as Finance, HR, and guest traffic.
  • Implement micro-segmentation for critical server environments to prevent lateral movement in the event of a single-host compromise.
  • Result: A reduced blast radius that ensures a security breach in one segment cannot easily migrate to sensitive data zones.

3. Enforce Perimeter Defences and TLS Inspection

  • Deploy Next-Generation Firewalls (NGFW) and Intrusion Prevention Systems (IPS) at all network entry and exit points to monitor for malicious patterns.
  • Enable TLS inspection on web gateways to scan encrypted traffic for hidden malware payloads and data exfiltration attempts.
  • Result: Real-time blocking of known threats and visibility into previously “blind” encrypted communication channels.

4. Restrict Administrative Access via IAM and MFA

  • Configure granular Identity and Access Management (IAM) roles for network infrastructure, ensuring only authorised personnel can modify device configurations.
  • Mandate Multi-Factor Authentication (MFA) for all administrative logins, particularly for remote access via VPN or cloud-based management consoles.
  • Result: Elimination of risks associated with credential theft and unauthorised infrastructure tampering.

5. Execute Continuous Vulnerability Scanning and Hashing

  • Schedule automated network vulnerability scans to identify open ports, insecure protocols (e.g. Telnet, FTP), and unpatched firmware.
  • Use cryptographic hashing to verify the integrity of router and switch configuration files, ensuring no unauthorised changes have occurred.
  • Result: Proactive identification of technical weaknesses and the ability to detect configuration drift in real time.

6. Implement Centralised Logging and SIEM Integration

  • Configure all network devices to export Syslog and NetFlow data to a centralised Security Information and Event Management (SIEM) platform.
  • Establish automated alerts for high-risk events, such as brute-force attempts on network gateways or unauthorised internal connection requests.
  • Result: Comprehensive situational awareness and a verifiable audit trail for ISO 27001 compliance reviews and forensic investigations.
CEO at High Table: The Compliance Agency

What will an auditor check?

The audit is going to check a number of areas. Lets go through the main ones

1. That you have documentation

What this means is that you need to show that you have documented your network. Can you show network diagrams, a list of devices and their configurations, logs of configuration changes, roles and responsibilities?

2. That you have have implemented Network Security appropriately

They will look at systems to seek evidence of network security. They will question you on the process and seek evidence that you have followed it. They want to see evidence of network security and the process in operation.

3. That you have conducted internal audits

The audit will want to see that you have tested the controls and evidenced that they are operating. This is usually in the form of the required internal audits. They will check the records and outputs of those internal audits.

ISO 27001 Templates

ISO 27001 Templates - ISO 27001 Annex A 8.20 Networks Security Template - Do it Yourself
ISO 27001 Templates

Applicability across different business models

Business TypeApplicabilityExamples of Control Implementation
Small BusinessesFocuses on securing physical office hardware and basic internet connectivity. Ensuring that standard routers and Wi-Fi access points are hardened against common attacks.
  • Changing factory-default ‘admin’ passwords on all office routers and switches.
  • Disabling unnecessary WPS and guest SSID features on office Wi-Fi routers.
  • Maintaining a simple, up-to-date network diagram showing connected office devices.
Tech StartupsCritical for cloud-native infrastructures. Focuses on logical network control, managing Virtual Private Clouds (VPCs), and securing remote access for distributed teams.
  • Implementing strict Security Groups and Network ACLs in AWS/Azure to restrict traffic flow.
  • Enforcing Multi-Factor Authentication (MFA) for all VPN and SSH administrative logins.
  • Configuring centralized logging to an external SIEM to track all network configuration changes.
AI CompaniesVital for protecting massive datasets and high-value model IP. Focuses on high-speed data transfer security and isolating sensitive training environments.
  • Enforcing TLS 1.3 for high-speed data ingestion pipelines to prevent interception.
  • Implementing micro-segmentation for GPU clusters to isolate training workloads from the public web.
  • Disabling vulnerable network protocols (e.g., Telnet, FTP) on all high-performance computing nodes.

Network Security Policy Example

An example of the ISO 27001 Network Security Policy.

ISO 27001 Network Security Policy Page 1 - ISO 27001 Annex A 8.20 Networks Security Template
ISO 27001 Network Security Policy Page 1
ISO 27001 Network Security Policy Page 2 - ISO 27001 Annex A 8.20 Networks Security Template
ISO 27001 Network Security Policy Page 2
ISO 27001 Network Security Policy Page 3 - ISO 27001 Annex A 8.20 Networks Security Template
ISO 27001 Network Security Policy Page 3
ISO 27001 Network Security Policy Page 4 - ISO 27001 Annex A 8.20 Networks Security Template
ISO 27001 Network Security Policy Page 4
ISO 27001 Network Security Policy Page 5 - ISO 27001 Annex A 8.20 Networks Security Template
ISO 27001 Network Security Policy Page 5
ISO 27001 Network Security Policy Page 6 - ISO 27001 Annex A 8.20 Networks Security Template
ISO 27001 Network Security Policy Page 6

FAQ

Who is responsible for ISO 27001 Network Security?

Responsibility usually lies with the IT or Network Security team, specifically those with specialist training. However, the standard requires clear segregation of duties to prevent conflicts of interest.
Network Administrators: Responsible for day-to-day configuration and maintenance.
Security Officers: Responsible for monitoring logs and auditing configurations.
Authorisation: A separate role should authorize significant changes (e.g., opening a firewall port) before implementation.

Does ISO 27001 Annex A 8.20 require network segmentation?

Yes, network segmentation is a critical component of securing networks under Annex A 8.20. While often detailed further in Annex A 8.22 (Segregation of Networks), control 8.20 requires you to manage and control the flow of information to prevent unauthorized access.
Guest Networks: Must be completely isolated from corporate production networks.
Admin Segregation: Management interfaces should not be accessible from the general user network.
Traffic Filtering: Use VLANs and firewalls to restrict traffic between different business units or security zones.

What evidence will an ISO 27001 auditor check for Network Security?

Auditors primarily verify compliance by examining your network documentation, configuration logs, and access control records. They will look for proof that your documented policies match the actual configuration of your live environment.
Network Diagrams: Must be current, dated, and accurately reflect physical and logical topologies.
Configuration Logs: Evidence of who changed firewall rules or device settings and when.
Access Reviews: Records showing regular reviews of who has administrative access to network gear.
Asset Inventory: A complete list of network devices (switches, routers, WAPs) and their owners.

Is encryption required for ISO 27001 Annex A 8.20 compliance?

Yes, encryption is a standard technical measure required to protect information in transit across networks. You must ensure that data moving between systems or over public networks is protected against interception.
Protocols: Use secure protocols like TLS/SSL for web traffic and IPsec for VPNs.
Management: Ensure management interfaces (e.g., SSH, HTTPS) are encrypted to protect admin credentials.
Policy: Define encryption standards in your Network Security Policy.

Further Reading

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

ISO 27001 Annex A 8.20 Network Security
Shopping Basket
Scroll to Top