ISO 27017:2015
Annex A – Cloud service extended control set – ISO 27017:2015

ISO 27017:2015 CLD.13.1.4: Alignment of security management for virtual and physical networks

Objective ISO/IEC 27002 13.1 applies. Control, in substance: whenever virtual networks are set up, their configuration is to be checked for consistency with the physical network, using the provider's network security policy as the yardstick. Cloud service customer: no additional guidance. Cloud service provider: define and document an information security policy for configuring virtual networks that is consistent with the information security policy for the physical network, and ensure the virtual network configuration matches that policy whatever means are used to create the configuration. Other information: virtual networks are configured on a virtual infrastructure over the physical network, and inconsistent policies can cause outages or defective access control; responsibility for configuring virtual networks can differ between customer and provider depending on the service type.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

C5 (Germany) · 2 controls

  • C5-COS-06 Segregation of data traffic in jointly used network environments
  • C5-PSS-10 Software Defined Networking

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A – Cloud service extended control set – ISO 27017:2015

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.