SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.8.20Networks security

Secure and manage your networks to protect the information that travels across them, including segmentation and appropriate controls between zones.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0084Remote access · TechnicalsupportsRestricting remote connections to encrypted VPN or zero-trust access on enrolled devices, with no internal service directly reachable, implements the boundary control A.8.20 requires.RCF-0099Encryption in transit · TechnicalsupportsEnforcing encrypted protocols everywhere and disabling legacy unencrypted options protects information as it travels across the network, a core objective of A.8.20.RCF-0170Network segmentation · ProcesssupportsReviewing zone boundaries and the rules permitting traffic between them on a schedule keeps A.8.20's network segmentation accurate rather than a stale diagram.RCF-0171Network segmentation · TechnicalsupportsEnforcing zone boundaries with VLANs and firewall rules blocking traffic unless explicitly allowed is the segmentation slice of A.8.20, which also covers encrypted transit, remote access and wireless protection.RCF-0172Firewall management · PolicyenablesAn approved firewall standard defining default-deny and who may approve rule changes is the policy basis A.8.20's network controls depend on.RCF-0173Firewall management · ProcesssupportsReviewing the firewall rule set and removing unjustified or overly broad rules keeps A.8.20's network protection from eroding over time.RCF-0174Firewall management · TechnicalsupportsAn edge firewall denying inbound traffic by default with logged, alerted changes is one perimeter mechanism inside A.8.20, which also requires securing and managing controls between internal zones.RCF-0175Secure DNS · PolicyenablesStating which DNS resolvers devices must use and requiring domain protection against tampering is the policy basis for A.8.20's secure-DNS component.RCF-0176Secure DNS · ProcesssupportsChecking public DNS records and resolver reports on a recurring basis catches tampering or bypass, keeping A.8.20's DNS protection effective.RCF-0177Secure DNS · TechnicalsupportsFiltering DNS resolution and locking public DNS records with registrar protections is a specific technical layer of the network protection A.8.20 requires.RCF-0183TLS termination/hardening · TechnicalsupportsRequiring TLS 1.2 or later with modern ciphers on every service enforces the encrypted-transit expectation that is part of A.8.20's network protection.RCF-0186Zero Trust network access · TechnicalsupportsContinuous verification of identity, MFA and device health at every sign-in extends A.8.20's network access control beyond a fixed perimeter.RCF-0190Wireless security · PolicyenablesDefining written security requirements for every wireless network, including encryption and guest separation, is the policy basis A.8.20's wireless protection depends on.RCF-0191Wireless security · ProcesssupportsConfirming wireless configuration against the standard and looking for rogue access points on a recurring basis keeps A.8.20's wireless security enforced in practice.RCF-0192Wireless security · TechnicalsupportsWPA2 or WPA3 encryption, an isolated guest network and unreachable management interfaces cover wireless only, one piece of the wider network protection and segmentation A.8.20 requires.RCF-0421Network segmentation (ICS) · PolicyenablesMandating that production control systems live on their own network, separate from office IT, is the policy foundation for A.8.20's segmentation in industrial environments.RCF-0422Network segmentation (ICS) · ProcesssupportsContinuously controlling the IT/OT boundary, reviewing cross-boundary rules and removing unneeded connections, keeps A.8.20's segmentation intact in production environments.RCF-0423Network segmentation (ICS) · TechnicalsupportsA firewall between IT and OT zones permitting only necessary flows, plus one-way data paths, is the technical segmentation A.8.20 requires for industrial networks.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Network architecture diagram
The drawing or schematic showing how the company's systems connect: networks, firewalls, segments, and links to the internet and the cloud.
Wireless network configuration
How the company's Wi-Fi is secured: encryption, a separate guest network, and control of access points.
VPN and remote access configuration
How employees connect securely to company systems when working outside the office: VPN, remote-access rules and allowed devices.
From the Sekit evidence catalog

In practice

Network security for an SME comes down to three concrete things auditors check: can someone reach an internal service directly from the internet, is the guest Wi-Fi separated from the corporate network, and does the firewall default-deny inbound traffic. What works: segment the network into zones with a firewall enforcing default-deny between them, require VPN or zero-trust access for anyone connecting remotely, and lock wireless down to WPA2 or WPA3 with an isolated guest network. The network architecture diagram is the artifact auditors want to see, because it shows whether the segmentation described in policy matches what is wired.

Common gaps

The network diagram shows planned segmentation between office and server zones, but the firewall rules that should enforce that boundary were never fully implemented.
Guest Wi-Fi shares a subnet with a handful of legacy office devices because the isolation configuration was only partially completed during the last upgrade.
Firewall rules have accumulated for years and nobody has reviewed them recently, so several overly broad allow rules remain that nobody can justify.

Questions your auditor will ask

Can an internal service be reached directly from the internet without going through a controlled path?
No, remote access is only permitted over an encrypted VPN or zero-trust service restricted to enrolled company devices, shown on the network architecture diagram.
How is guest Wi-Fi separated from the network handling company data?
Guest and corporate wireless run on isolated networks with no path between them, configured with WPA2 or WPA3 encryption and separate access controls.
When was the firewall rule set last reviewed, and how are unused rules removed?
Rules are reviewed on a recurring schedule, each allow rule is justified against a business need, and unused or overly broad rules are removed.
How is the boundary between production control systems and office IT enforced?
A dedicated firewall permits only the specific flows production needs between zones, with the boundary reviewed and verified after any change.

Where regulation demands it

NIS2 art. 6.8 requires network segmentation as a distinct control from general network security. ENS mp.com.4 expects information flows to be separated across the network by sensitivity.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.8.20?”
Also via MCP, free with account