EvidenceSheet

8.20 Networks security

Requires networks and network devices to be secured, managed and controlled in order to protect the information carried in systems and applications.

5
artefacts
1
held by a system
2
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review

system holds itEvidence a system already holds

  • Records of network monitoring and of the response to unauthorised connections or devices · Endpoint management (MDM / EDR)

periodic reviewEvidence produced at each review

  • Firewall and access control rule sets, with evidence of periodic review and removal of obsolete or overly permissive rules · Identity provider / directory
  • Evidence of authentication and encryption for network device management and for remote administration · Endpoint management (MDM / EDR)

governing documentDocuments that govern the control

  • Network documentation showing the current topology, zones, connections and the security controls at each boundary · Policy repository / GRC workspace
  • Configuration standards for network devices and evidence of compliance, including management plane protection · Policy repository / GRC workspace

First move

Mostly documents and reviews. Pull the 1 system-held artefact from your Endpoint management (MDM / EDR) on a schedule; put the documents under version control with an owner and review date, and log each review as a dated record with a named reviewer.

Common gaps auditors find

Do this for your whole sheet

Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.

Build my evidence sheet

8.19 Installation of software on operational systems · 8.21 Security of network services