For each network service, the organization is to identify, put in place and monitor the security mechanisms, the service levels and the requirements that apply. Purpose: make using network services safe. Guidance: identify and implement the security measures a given service needs, including security features, service levels and requirements, whether it is provided internally or externally, and make sure providers implement them. Determine and regularly monitor each provider's ability to manage the agreed services securely, agree a right to audit, and consider third-party attestations from providers showing they maintain appropriate security. Rules for using networks and network services should cover which networks and services may be accessed; authentication requirements for each service; authorization procedures deciding who may reach which networks and services; management, technical controls and procedures protecting access to network connections and services; the means of access, such as VPN or wireless; the user's time, location and other attributes at access; and monitoring of service use. Security features to consider include the technologies securing the service, such as authentication, encryption and connection controls; the technical parameters needed for a secure connection under the security and connection rules; caching, for example in content delivery networks, with parameters that let users choose caching according to performance, availability and confidentiality needs; and usage procedures that limit who may reach particular services or applications when needed. Network services range from simple unmanaged bandwidth to connections, private network services and managed security services such as firewalls and intrusion detection; ISO/IEC 29146 gives an access management framework.
This control maps to 87 controls across 26 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 8.21 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.