ISO 27001 Annex : A.13 Communications Security

 


ISO 27001 Annex : A.13 Communications Security in this article explain A.13.1  Network Security Management, A.13.1.1  Network Controls, A.13.1.2  Security of Network Services, A.13.1.3  Segregation in Networks.

A.13.1  Network Security Management

It’s objective is to ensure the security and supporting information processing facilities of the information in a network.

A.13.1.1  Network Controls

Control- To protect information in systems and applications, networks should be managed and monitored.

Implementation Guidance – The monitoring of network information security and the security of connected networks from unauthorized access should be undertaken. The following things will in particular be taken into account:

  1. Networking equipment management responsibilities and procedures should be established;
  2. Network operational responsibility can, where necessary, be segregated from computer operations;
  3. The confidential and integrity of data transmission via public networks and wireless networks and the protected network and applications should be subject to special controls; specific controls may also be essential to maintain the availability of network services and connected computers;
  4. Appropriate logging and monitoring should be used so that actions that may or are relevant to information security can be recorded and detected;
  5. Close coordination of management activities should be provided to improve the service offered to the company and to ensure effective control of all information processing infrastructures;
  6. Authentication of network systems;
  7. Network connection should be restricted to devices.

Other Information – Further network protection information is available in ISO / IEC 27033.

Related Product : ISO 27001 Lead Auditor Training And Certification ISMS

A.13.1.2  Security of Network Services

Control- Security protocols, quality of service, and management criteria for all network services, whether in-house or outsourced, should be defined and included in-network services agreements.

Implementation Guidance – It is necessary to determine and regularly supervise the capability of the network service provider to safeguard the agreed services and to agree to audit rights.

The required security structures such as security features, service rates, and management criteria for particular facilities should be defined. It will ensure that these steps are enforced by network service providers.

Read More : https://info-savvy.com/iso-27001-annex-a-13-communications-security/

-------------------------------------------------------------------------------------------------------------------------------------

This Blog Article is posted by

Infosavvy, 2nd Floor, Sai Niketan, Chandavalkar Road Opp. Gora Gandhi Hotel, Above Jumbo King, beside Speakwell Institute, Borivali West, Mumbai, Maharashtra 400092
Contact us – www.info-savvy.com

Comments

Post a Comment

Popular posts from this blog

10 Secrets You Will Never Know About Cyber Security And Its Important

ISO 27001 Annex : A.5 Information Security Policies

Impact Of ISO 27001 Lead Auditor