← ISO 27001 · A.8 — Technological

A.8.21 — Security of network services

medium network-security

Requirement

Security mechanisms, service levels and service requirements of network services shall be identified, implemented and monitored.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
networknetwork service
Required element 2 — any one of
securityencryptsegmentfirewallmonitoredsegmentation
Supporting terms — specificity signals
tlsvpnsladdospeeringprivate link

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
PCI DSS 4.0.1 1.4 Controls between trusted and untrusted networks network-security
SOC 2 CC6.6 Boundary protection network-security
PCI DSS 4.0.1 1.2 Network security control configuration and review network-security
PCI DSS 4.0.1 1.3 Restrict network access to and from the cardholder data environment network-security
PCI DSS 4.0.1 6.4.1-6.4.2 Public-facing web applications are protected against attacks network-security
NIST CSF 2.0 PR.DS-02 Confidentiality, integrity and availability of data in transit network-security
NIST CSF 2.0 PR.IR-01 Networks and environments are protected from unauthorised logical access network-security
NIST CSF 2.0 DE.CM-01 Networks and network services are monitored network-security