ISO 27701:2019
PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

ISO 27701:2019 6.10.1: Network security management

Network controls, security in network services and segregation in networks apply as the base guidance requires, read as protecting the personal data that crosses those networks.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 78 controls across 24 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 9 controls

  • 1.1.1 1.1.1 Requirement 1 policies and procedures governed
  • 1.2.1 1.2.1 Ruleset configuration standards for NSCs
  • 1.2.3 1.2.3 Accurate network diagram of CDE connections
  • 1.2.5 1.2.5 Allowed services, protocols and ports justified
  • 1.2.7 1.2.7 Six-monthly review of NSC configurations
  • 1.3.1 1.3.1 Inbound CDE traffic restricted
  • 1.4.1 1.4.1 NSCs between trusted and untrusted networks
  • 1.4.2 1.4.2 Restricting traffic entering trusted networks from outside
  • 1.4.4 1.4.4 Cardholder data stores not reachable from untrusted networks

CIS Controls v8 · 8 controls

  • CIS-12.2 Establish and Maintain a Secure Network Architecture
  • CIS-12.3 Securely Manage Network Infrastructure
  • CIS-12.6 Use of Secure Network Management and Communication Protocols
  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-13.4 Perform Traffic Filtering Between Network Segments
  • CIS-13.9 Deploy Port-Level Access Control
  • CIS-4.4 Implement and Manage a Firewall on Servers
  • CIS-4.6 Securely Manage Enterprise Assets and Software

NIST SP 800-53 Rev 5 · 8 controls

CMMC 2.0 · 6 controls

HIPAA Security Rule · 5 controls

NIST SP 800-66 Rev 2 · 5 controls

  • ASBv3-NS-8 Detect and disable insecure services and protocols
  • NS-1 Establish network segmentation boundaries
  • NS-2 Secure cloud services with network controls
  • NS-3 Deploy firewall at the edge of enterprise network

FedRAMP High · 4 controls

  • AC-4 Information Flow Enforcement
  • SC-7 Boundary Protection
  • SC-7(3) Access Points
  • SC-8 Transmission Confidentiality and Integrity

FedRAMP Moderate · 4 controls

  • AC-4 Information Flow Enforcement
  • SC-7 Boundary Protection
  • SC-7(3) Access Points
  • SC-8 Transmission Confidentiality and Integrity

C5 (Germany) · 3 controls

  • C5-COS-02 Security requirements for connections in the Cloud Service Provider's network
  • C5-COS-03 Monitoring of connections in the Cloud Service Provider's network
  • C5-COS-06 Segregation of data traffic in jointly used network environments

ISO 27001:2022 · 3 controls

  • 8.20 Networks security
  • 8.21 Security of network services
  • 8.22 Segregation of networks

ISO 27002:2022 · 2 controls

  • 8.20 Networks security
  • 8.21 Security of network services
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage

NIST SP 800-171 Rev 3 · 2 controls

  • 03.13.01 Boundary Protection
  • 03.13.06 Network Communications - Deny by Default - Allow by Exception
  • AUCDR-IS-2 Secure the network and systems within the data environment

ISO 27017:2015 · 1 control

  • 13.1 Network security management

ISO 27018:2019 · 1 control

  • 13.1 Network security management

ISO/IEC 27043:2015 · 1 control

  • ISO27043-27 Network security management

ISO/SAE 21434 · 1 control

  • ISO21434-27 Network security management

SOC 2 · 1 control

  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 6.10.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 78 it maps to, and the evidence behind each claim, over MCP and REST.