Within its networks the organization is to keep groups of users, information services and information systems apart. Purpose: divide the network along security boundaries and control traffic between them according to business need. Guidance: consider managing large networks by splitting them into separate domains, each kept apart from the internet. Domains can be based on trust, criticality and sensitivity (for example public access, desktop and server domains, or low- and high-risk systems), on organizational units such as HR, finance or marketing, or on a mix, such as a server domain serving several units, and can be built with physically separate or logically separate networks. Each domain has a well-defined perimeter; where traffic between domains is allowed it passes through a gateway such as a firewall or filtering router. The criteria for dividing domains and the access permitted through gateways come from assessing each domain's security requirements against the access control policy (5.15), access needs and the value and classification of the information, taking into account the cost and performance impact of the gateway technology. Wireless networks need special handling because their perimeter is poorly defined: consider adjusting radio coverage, and in sensitive environments treat all wireless access as external, keeping it apart from internal networks until it has passed a gateway that applies the network controls (8.20). Guest wireless should be separated from staff wireless where staff use only controlled, policy-compliant devices, and guest WiFi should be at least as restricted as staff WiFi to discourage staff from using it. Other information: networks often extend beyond the organization through partnerships and shared facilities, raising the risk of unauthorized access to systems that need protecting from other network users.
This control maps to 99 controls across 36 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 8.22 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.