Frameworks / ISO 27001:2022 / 8.20 ISO 27001:2022
Technological controls – ISO 27001:2022
ISO 27001:2022 8.20: Networks security Networks and network devices are to be secured, managed and controlled so that information in systems and applications is protected. Purpose (stated in ISO/IEC 27002:2022): protects information in networks and supporting facilities from compromise via the network. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 8.20.
Maintained by Gerard Blokdyk · Verified against the published standard 18 August 2026 · Control text last updated 25 September 2026 What else in your programme already covers this This control maps to 155 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
1.1.1 1.1.1 Requirement 1 policies and procedures governed 1.2.1 1.2.1 Ruleset configuration standards for NSCs 1.2.3 1.2.3 Accurate network diagram of CDE connections 1.2.4 1.2.4 Accurate data-flow diagram for account data 1.2.5 1.2.5 Allowed services, protocols and ports justified 1.2.6 1.2.6 Security features for insecure services in use 1.2.7 1.2.7 Six-monthly review of NSC configurations 1.3.1 1.3.1 Inbound CDE traffic restricted 1.3.2 1.3.2 Outbound CDE traffic restricted 1.4.1 1.4.1 NSCs between trusted and untrusted networks 1.4.2 1.4.2 Restricting traffic entering trusted networks from outside 1.4.3 1.4.3 Anti-spoofing measures at trusted boundary 1.4.4 1.4.4 Cardholder data stores not reachable from untrusted networks 1.4.5 1.4.5 Internal IP and routing disclosure limited 1.5.1 1.5.1 Security controls on dual-connected devices 11.2.1 11.2.1 Detect authorized and rogue wireless access points 11.4.5 11.4.5 Annual segmentation penetration testing 11.5.1 11.5.1 IDS/IPS monitoring of CDE traffic 11.5.1.1 11.5.1.1 Service providers detect covert malware channels 11.6.1 11.6.1 Payment page tamper detection 2.2.4 2.2.4 Only necessary functionality enabled 2.2.5 2.2.5 Insecure services, protocols or daemons secured 2.2.6 2.2.6 System security parameters configured against misuse 2.3.1 2.3.1 Wireless vendor defaults changed or confirmed secure 3.4.2 3.4.2 Remote access blocks copying or relocating PAN 4.2.1.2 4.2.1.2 Wireless networks use strong cryptography 6.4.2 6.4.2 Automated web attack detection and prevention 6.4.3 6.4.3 Payment page script management CIS-1.2 Address Unauthorized Assets CIS-12.1 Ensure Network Infrastructure is Up-to-Date CIS-12.2 Establish and Maintain a Secure Network Architecture CIS-12.3 Securely Manage Network Infrastructure CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA) CIS-12.6 Use of Secure Network Management and Communication Protocols CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work CIS-13.4 Perform Traffic Filtering Between Network Segments CIS-13.6 Collect Network Traffic Flow Logs CIS-13.8 Deploy a Network Intrusion Prevention Solution CIS-13.9 Deploy Port-Level Access Control CIS-3.10 Encrypt Sensitive Data in Transit CIS-3.12 Segment Data Processing and Storage Based on Sensitivity CIS-4.2 Establish and Maintain a Secure Configuration Process for Network Infrastructure CIS-4.4 Implement and Manage a Firewall on Servers CIS-4.5 Implement and Manage a Firewall on End-User Devices CIS-4.6 Securely Manage Enterprise Assets and Software CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software CIS-4.9 Configure Trusted DNS Servers on Enterprise Assets AC-17 Remote Access AC-17(3) Managed Access Control Points AC-18 Wireless Access CP-8(2) Telecommunications Services | Single Points of Failure (CP-8(2)) MA-4 Nonlocal Maintenance SA-4(9) Acquisition Process | Functions, Ports, Protocols, and Services in Use (SA-4(9)) SA-9(2) Identification of Functions, Ports, Protocols, and Services SC-7 Boundary Protection SC-7(12) Boundary Protection | Host-based Protection (SC-7(12)) SC-7(18) Boundary Protection | Fail Secure (SC-7(18)) SC-7(7) Split Tunneling for Remote Devices SC-7(8) Route Traffic to Authenticated Proxy Servers SC-8 Transmission Confidentiality and Integrity SC-8(1) Cryptographic Protection SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18)) AC-17 Remote Access AC-17(3) Managed Access Control Points AC-18 Wireless Access CP-8(2) Telecommunications Services | Single Points of Failure (CP-8(2)) MA-4 Nonlocal Maintenance SA-4(9) Acquisition Process | Functions, Ports, Protocols, and Services in Use (SA-4(9)) SA-9(2) Identification of Functions, Ports, Protocols, and Services SC-7 Boundary Protection SC-7(12) Boundary Protection | Host-based Protection (SC-7(12)) SC-7(18) Boundary Protection | Fail Secure (SC-7(18)) SC-7(7) Split Tunneling for Remote Devices SC-7(8) Route Traffic to Authenticated Proxy Servers SC-8 Transmission Confidentiality and Integrity SC-8(1) Cryptographic Protection SI-4(18) System Monitoring | Analyze Traffic and Covert Exfiltration (SI-4(18)) ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment ANSSI-HYG-17 Enable and Configure the Local Firewall on Workstations ANSSI-HYG-19 Segment the Network and Partition the Zones ANSSI-HYG-20 Secure Wi-Fi Access Networks and Separate Usage ANSSI-HYG-21 Use Secure Protocols Wherever They Exist ANSSI-HYG-22 Put in Place a Secure Internet Access Gateway ASD37-08 Deny direct internet connectivity (Excellent) ASD37-14 Block spoofed emails (Very Good) ASD37-25 Software firewall - inbound (Very Good) ASD37-26 Software firewall - outbound (Very Good) ASD37-32 Network-based IDS/IPS (Limited) ASBv3-GS-4 Define and implement network security strategy ASBv3-NS-7 Simplify network security configuration ASBv3-NS-8 Detect and disable insecure services and protocols NS-1 Establish network segmentation boundaries NS-3 Deploy firewall at the edge of enterprise network SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.1 CC6.1 Logical access security over protected information assets SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities 8.20 Networks security 8.21 Security of network services 8.22 Segregation of networks 8.23 Web filtering NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events NIST-CSF-ID.AM-03 Representations of the organization's authorized network communication and internal and external network data flows are maintained NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage E8-PATCHOS-ML3 Patch Operating Systems (ML3) AUCDR-IS-2 Secure the network and systems within the data environment DSS05.02 DSS05.02 Manage network and connectivity security 6.10.1 Network security management Art.21.2.j Multi-factor or continuous authentication, secured communications and secured emergency communications 3.5.1e Identification of Systems, Components, and Devices Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Technological controls – ISO 27001:2022 You are reading one control. How much of ISO 27001:2022 have you already done? ISO 27001:2022 8.20 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.
Query this from an agent The graph holds this control, the 155 it maps to, and the evidence behind each claim, over MCP and REST.