ISO/IEC 27001:2022 Annex A · Control 8.21
Security of Network Services: A Practical Implementation Guide
Define and verify security requirements for every network service, whether internal or externally supplied.
This control concerns identifying security mechanisms, service levels and management requirements for network services.
What should the control achieve?
- Network services and owners are inventoried.
- Security requirements reflect information and criticality.
- Provider and customer responsibilities are agreed.
- Performance and security are monitored.
Step-by-step implementation
Inventory services
Include internet, WAN, DNS, remote access, wireless, cloud connectivity and managed security.
Classify criticality
Assess data, users, availability, trust and dependency.
Define requirements
Specify authentication, encryption, segregation, logging, resilience and support.
Agree responsibilities
Document provider, customer and subprovider duties and incident contacts.
Approve and configure
Validate service design and customer-controlled settings.
Monitor and review
Track SLA, security events, changes, assurance and continued need.
What this could look like in practice
A managed SD-WAN service has defined encryption, administrative MFA, logging export, availability, incident notification and change approval. The Network Owner reviews reports and provider changes quarterly.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Service design | Requirements map to data and criticality. | Service specification |
| Contract | Security and incident duties are explicit. | Agreement |
| Operation | Logs and SLA data are reviewed. | Service report |
| Change | Provider architecture change triggers assessment. | Change review |
Implementation evidence
- Network service register
- Security requirements
- Service agreements
- Responsibility matrix
- Configuration reviews
- SLA reports
- Incident records
- Supplier changes
Useful metrics
- Services with defined security requirements
- SLA breaches
- Unreviewed provider changes
- Network services without owners
Common mistakes
- Treating carrier services as trusted by default.
- No security requirements beyond availability.
- Ignoring DNS and wireless services.
- Unclear incident responsibilities.
- Failing to review customer configuration.
Questions an auditor may ask
- Which network services are critical?
- What security properties are required?
- How are providers monitored?
- Show a service change assessment.
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.