Identify the security needs of network services, build them into agreements, and monitor delivery, whether services are provided in-house or by a third party.
Mapping at a glance
A.8.21Security of network servicesISO/IEC 27001:2022
Network services, whether run in-house or bought from a provider, need their security requirements written into the agreement before delivery starts, not discovered afterward. What works: define what a network service must provide, encryption in transit, access restrictions, monitoring, before signing a contract or standing up an internal service, and review the service's firewall rules on a recurring schedule to confirm access still matches what was agreed. The common gap is a network service from years ago whose original security requirements were never documented, so nobody can check whether the service still meets them.
Common gaps
Several long-standing network services predate any formal security requirement documentation, so there is nothing to check current delivery against.
The firewall rules supporting a specific network service have never been reviewed separately from the general rule base, so scope creep goes unnoticed.
A third-party network service provider was never asked to document how they secure the service, and no monitoring of their delivery was set up.
Questions your auditor will ask
How are security requirements for a network service defined before it goes live?
Requirements such as encryption, access restriction and monitoring are agreed and documented before the service is signed off, whether it is run internally or by a provider.
How do you verify a network service still delivers what was agreed?
The firewall rules and access supporting the service are reviewed on a recurring schedule, checking delivery against the documented requirement.
What happens when a network service is provided by a third party?
The same security requirements apply, and the arrangement is reviewed periodically to confirm the provider is still meeting what was agreed in the service arrangement.
Where regulation demands it
NIS2 art. 6.7 covers network security requirements that a service, in-house or outsourced, must meet. ENS op.pl.2 expects network services to fit into a documented security architecture.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.