ISO/IEC 27001:2022 Annex A · Control 8.20
Network Security: A Practical Implementation Guide
Design, configure and monitor networks to protect information and connected services.
This control concerns securing and managing networks and network devices to protect information in systems and applications.
What should the control achieve?
- Network architecture and trust boundaries are documented.
- Devices follow secure baselines.
- Traffic is restricted and monitored.
- Changes and incidents are controlled.
Step-by-step implementation
Map architecture
Document zones, routes, external links, cloud networks, remote access and critical flows.
Define trust boundaries
Apply default-deny principles and controlled ingress, egress and management.
Harden infrastructure
Secure protocols, administration, configuration, updates and backups.
Protect communications
Use encryption and authenticated tunnels according to risk.
Monitor traffic and devices
Collect flow, firewall, DNS and device logs and detect anomalies.
Test and review
Assess rules, exposure, resilience and unauthorized paths.
What this could look like in practice
A hybrid network separates user, production, management and guest zones. Administrative access uses a hardened jump path, firewall rules map to approved applications and quarterly reviews remove unused rules.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Architecture | Zones and data flows are documented. | Network diagram |
| Rule change | Owner and Network Security approve justified flow. | Change ticket |
| Administration | MFA and management network protect devices. | Admin log |
| Monitoring | Anomalous egress creates investigation. | Alert case |
Implementation evidence
- Network security standard
- Current diagrams
- Device inventory
- Configuration baselines
- Firewall rules
- Change records
- Network logs
- Rule reviews
Useful metrics
- Unreviewed firewall rules
- Internet-exposed services
- Network devices below baseline
- Unauthorized paths found
Common mistakes
- Flat networks.
- Any-to-any rules.
- Managing devices through insecure protocols.
- Outdated diagrams.
- Ignoring cloud and third-party connectivity.
Questions an auditor may ask
- Where are trust boundaries?
- How are network rules approved?
- Show secure device administration.
- How is unexpected traffic detected?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.