A.8.21A.8 Technological controls

Security of network services

A.5EVIDENCEA.6EVIDENCEA.7EVIDENCEA.8EVIDENCECONTROL MAPA.8.21 Evidence MapPOLICY / CONTROL / EVIDENCE / REVIEW

Purpose

Identify, deliver and monitor the security mechanisms, service levels and requirements of network services.

How to meet this control

In short: Identify the security mechanisms, service levels and service requirements of each network service, implement them (whether the service is provided in-house or by an external provider), and monitor that they continue to be met.

  1. Step 01Document the security features each network service must provide, such as encryption, authentication and DDoS protection, and confirm the provider delivers them
  2. Step 02Capture security requirements and service levels in agreements with carriers and managed network providers, including audit and reporting rights
  3. Step 03Obtain third-party attestations (ISO 27001, SOC 2) from providers as assurance of ongoing controls
  4. Step 04Define authorisation rules for who may access which networks and services and the authentication required
  5. Step 05Apply technology such as VPN, certificate authentication and connection filtering based on user context and access method
  6. Step 06Monitor provider performance and security against the agreed terms

Tip: Document security requirements for each network service used.

What ISO 27002 says to cover

Reference points from the ISO/IEC 27002:2022 guidance for this control. Use them to check the steps above cover everything relevant to you.

  • ›Identify the security features each network service needs and ensure providers implement them
  • ›Regularly check the provider ability to manage agreed services securely, with audit rights
  • ›Consider third-party attestations as evidence that providers maintain security
  • ›Set rules covering which networks and services may be accessed and the authentication needed
  • ›Define authorisation procedures for who may use which networks and services
  • ›Use appropriate technology such as authentication, encryption and connection controls
  • ›Factor in context like the user time, location and access method such as VPN or wireless
  • ›Configure caching to meet performance, availability and confidentiality needs and monitor use

Audit evidence to keep

  • - Network service agreement listing security requirements and service levels
  • - Provider attestation such as ISO 27001 or SOC 2 report
  • - Authorisation rules for network and service access
  • - Configuration of VPN or authentication for network service access
  • - Monitoring records of provider performance against the agreement

Common mistakes

  • - Writing a policy but not operating the process
  • - Keeping evidence in personal folders where auditors cannot trace it
  • - Letting exceptions stay open with no owner or expiry date

Owner, cadence, and proof

Assign one accountable owner for A.8.21. Review this control at least annually, after related incidents, and whenever the underlying process, supplier, system, office, or legal obligation changes. The control is audit-ready when the owner can show the policy or procedure, the latest operating evidence, the latest review, and any open exceptions with due dates.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Back to all technological controls or see the requirements (clauses 4 to 10). To run this control with automation, read how AI manages controls.