Posts

Showing posts with the label Annex A.9 Access Control

ISO 27001 Annex : A.9.1.2 Access to Networks and Network Services

Image
Control-  ISO 27001 Annex : A.9.1.2 Access to Networks and Network Services Only network and network facilities which have expressly been approved for use will be made available to users. Implementation Guidance-  A policy on the use of networks and network policy should be developed. Following points should be covered in this policy: networks and network infrastructure to which access is permitted; Authorization procedures for determining who is permitted to access which networks and Networking services; Management  processes and policies for securing access to network interfaces and network services; the medium for networking and network services (for example, using VPN or wireless network); Access to various network services requires user authentication; Network service usage  monitoring . The network services policy should comply with the access control policy of the organization. Related Product :  ISO 27001 Lead Auditor Training And...