# Network security policy

Source: https://aestech.com.au/policy-templates/#network-security-policy
Markdown URL: https://aestech.com.au/policy-templates/network-security-policy.md

Use for ISO 27001 A.8.20, A.8.21, A.8.22, A.8.23, SOC 2 Security, and PCI DSS requirements 1 and 4.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how company networks and network services are designed, controlled and monitored to protect the confidentiality, integrity and availability of information in transit.

2. Scope
This policy applies to all company networks, cloud networks, virtual private clouds, firewalls, security groups, remote access services and connections to third parties. It applies to all systems connected to company networks.

3. Policy statements
- Network access controls such as firewalls or security groups must restrict traffic to what is required, with default deny on inbound traffic.
- Networks must be segmented to separate environments of different sensitivity, such as production, corporate and any cardholder data environment.
- Inbound and outbound rules must be documented, justified and reviewed at least every [6] months.
- Remote access to internal systems must use encrypted connections and multi-factor authentication.
- Wireless networks must use strong encryption and must separate guest access from internal systems.
- Data transmitted over public or untrusted networks must be encrypted in transit.
- Connections to third parties must be controlled, documented and limited to required services.
- Network changes must follow the change management policy.

4. Roles and responsibilities
- The [Network or Infrastructure Lead] owns network architecture and firewall rule sets.
- IT implements and maintains network controls and remote access.
- The [Security Lead] reviews segmentation, rule sets and remote access.
- System owners request and justify required network access.

5. Procedures
- Maintain network diagrams and a record of firewall or security group rules with justifications.
- Apply default deny and add rules only with documented business need.
- Review rule sets at least every six months and remove unnecessary rules.
- Configure remote access with encryption and multi-factor authentication.
- Validate network segmentation periodically, especially around regulated environments.

6. Evidence and records
Keep network diagrams, firewall and security group rule sets with justifications, rule review records, remote access configuration, segmentation validation results and change records.

7. Review cadence
This policy is reviewed at least annually and rule sets at least every six months.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md