SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.8.21Security of network services

Identify the security needs of network services, build them into agreements, and monitor delivery, whether services are provided in-house or by a third party.

Mapping at a glance
A.8.21Security of network servicesISO/IEC 27001:2022

A.8.21 is covered by 1 Sekit CSF control. Open in the full graph

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Cyber Essentials counterparts

In practice

Network services, whether run in-house or bought from a provider, need their security requirements written into the agreement before delivery starts, not discovered afterward. What works: define what a network service must provide, encryption in transit, access restrictions, monitoring, before signing a contract or standing up an internal service, and review the service's firewall rules on a recurring schedule to confirm access still matches what was agreed. The common gap is a network service from years ago whose original security requirements were never documented, so nobody can check whether the service still meets them.

Common gaps

Several long-standing network services predate any formal security requirement documentation, so there is nothing to check current delivery against.
The firewall rules supporting a specific network service have never been reviewed separately from the general rule base, so scope creep goes unnoticed.
A third-party network service provider was never asked to document how they secure the service, and no monitoring of their delivery was set up.

Questions your auditor will ask

How are security requirements for a network service defined before it goes live?
Requirements such as encryption, access restriction and monitoring are agreed and documented before the service is signed off, whether it is run internally or by a provider.
How do you verify a network service still delivers what was agreed?
The firewall rules and access supporting the service are reviewed on a recurring schedule, checking delivery against the documented requirement.
What happens when a network service is provided by a third party?
The same security requirements apply, and the arrangement is reviewed periodically to confirm the provider is still meeting what was agreed in the service arrangement.

Where regulation demands it

NIS2 art. 6.7 covers network security requirements that a service, in-house or outsourced, must meet. ENS op.pl.2 expects network services to fit into a documented security architecture.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.8.21?”
Also via MCP, free with account