Skip to main content

Proof of competence

ISO/IEC 27001:2022 Annex A · Control 8.21

Security of Network Services: A Practical Implementation Guide

Define and verify security requirements for every network service, whether internal or externally supplied.

This control concerns identifying security mechanisms, service levels and management requirements for network services.

Practical interpretation: Connectivity must have an owner, purpose, security properties and measurable obligations. Provider branding or uptime alone does not establish secure service.

What should the control achieve?

  • Network services and owners are inventoried.
  • Security requirements reflect information and criticality.
  • Provider and customer responsibilities are agreed.
  • Performance and security are monitored.

Step-by-step implementation

1

Inventory services

Include internet, WAN, DNS, remote access, wireless, cloud connectivity and managed security.

2

Classify criticality

Assess data, users, availability, trust and dependency.

3

Define requirements

Specify authentication, encryption, segregation, logging, resilience and support.

4

Agree responsibilities

Document provider, customer and subprovider duties and incident contacts.

5

Approve and configure

Validate service design and customer-controlled settings.

6

Monitor and review

Track SLA, security events, changes, assurance and continued need.

What this could look like in practice

A managed SD-WAN service has defined encryption, administrative MFA, logging export, availability, incident notification and change approval. The Network Owner reviews reports and provider changes quarterly.

ActivityPractical implementationEvidence
Service designRequirements map to data and criticality.Service specification
ContractSecurity and incident duties are explicit.Agreement
OperationLogs and SLA data are reviewed.Service report
ChangeProvider architecture change triggers assessment.Change review

Implementation evidence

  • Network service register
  • Security requirements
  • Service agreements
  • Responsibility matrix
  • Configuration reviews
  • SLA reports
  • Incident records
  • Supplier changes

Useful metrics

  • Services with defined security requirements
  • SLA breaches
  • Unreviewed provider changes
  • Network services without owners

Common mistakes

  • Treating carrier services as trusted by default.
  • No security requirements beyond availability.
  • Ignoring DNS and wireless services.
  • Unclear incident responsibilities.
  • Failing to review customer configuration.

Questions an auditor may ask

  • Which network services are critical?
  • What security properties are required?
  • How are providers monitored?
  • Show a service change assessment.
Implementation test: Select one external network service and trace requirement, agreement, configuration, monitoring, incident and exit arrangements.

Continue through Annex A

Explore the growing library of practical guides for all 93 Annex A controls.

Open the ISO 27001 Annex A Control Library

This independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.