Skip to content
compliancebase
ISO 27001A.8 — Security of network services

A.8.21

Security of network services

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Secure network services and ensure security mechanisms, service levels, and management requirements are identified and implemented.

Points of focus

  • Inventory network services
  • Hardening and TLS baselines
  • SLAs/security features with providers
  • Monitor availability and abuse

Implementation notes

Enforce TLS 1.2+. Restrict security groups to least privilege. Use private endpoints for databases. Document CDN/WAF ownership. Review third-party network service settings quarterly. Assign a named owner in the SoA, tie operating evidence to network service inventory, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Sample security group rules and TLS configs; show ownership for DNS/CDN.

Evidence auditors typically request:

  • Network service inventory
  • TLS/configuration baselines
  • Provider security addenda
  • Monitoring/alerting for network services

Common gaps

  • Plaintext admin protocols
  • Open security groups
  • No owner for DNS/CDN config

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.8.21This control
SOC 2CC6.6, CC6.7Related SOC 2 themes (CC6.6, CC6.7) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Includes cloud networking and managed network services.

A.8.20 is broader network security management; A.8.21 focuses on the services themselves.

Risk-based for public apps — common for SaaS APIs.

Even without owned data centers, security of network services still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with network service inventory, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above