A.3 Network Security Standards

Version: April 2025
Aligned with: ISO/IEC 27001:2022 (Annex A: A.8.20, A.8.21, A.8.22)
Applies to: All network infrastructure, administrators, and connected systems

Purpose
To establish network security requirements that protect organizational infrastructure from unauthorized access and threats.

1. Network Segmentation
(Aligned with A.8.22 – Segregation of networks)

  • DMZ implementation for public-facing services
  • VLAN segmentation for different security zones
  • Network access control (NAC) for device authentication
  • Intrusion detection and prevention systems (IDS/IPS)

2. Firewall Configuration
(Aligned with A.8.20 – Networks security)

  • Default deny policy for all traffic
  • Regular review and cleanup of firewall rules
  • Logging and monitoring of all firewall activities
  • Change management process for firewall modifications
Direct URL: