COBIT 2019
Deliver, Service and Support – COBIT 2019

COBIT 2019 DSS05.02: DSS05.02 Manage network and connectivity security

Information is protected, whatever the means of connection, through security measures and the management procedures that go with them: only authorised devices, set up to require a password, may reach corporate information and the network; network filtering such as firewalls and intrusion detection enforces policy on traffic coming in and going out; approved security protocols are applied to connections; network equipment is configured securely; information is encrypted in transit according to its classification; a connectivity security policy is based on risk assessment and business requirements; trusted mechanisms support sending and receiving securely; and periodic penetration testing and system security testing establish whether network and system protection is adequate.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 3 controls

  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.22 Segregation of networks

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Deliver, Service and Support – COBIT 2019

Query this from an agent

The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.