1import{j as e}from"./vendor-react-CFfMHXOf.js";import{L as a,a1 as A,i as b}from"./vendor-misc-DuTjEaCc.js";import{S as v}from"./ServicePageLayout-DuspEfTI.js";import{u as s,Q as k}from"./index-XZRKEe8O.js";import"./vendor-radix-DHqUeYEQ.js";const N="24 August 2026",j=[{type:"Documented network security policy",practice:"A written policy covering network segmentation, access boundaries, and monitoring, with a named owner",issuedBy:"Internal â written by the organisation"},{type:"Independent network/cloud testing report",practice:"An external network and cloud configuration assessment covering the in-scope perimeter, with dated findings",issuedBy:"External tester or internal security team"},{type:"Network architecture diagram",practice:"A current diagram showing segmentation, trust zones, and where the external perimeter sits",issuedBy:"Internal â maintained and version-controlled"},{type:"Cloud configuration baseline",practice:"Evidence the cloud environment is checked against a recognised benchmark (e.g. CIS Benchmarks), not just default settings",issuedBy:"External assessment or internal cloud security team"}],I=[{dimension:"Control name",a88:"Management of technical vulnerabilities",a820:"Network security",a829:"Security testing in development and acceptance"},{dimension:"What it's about",a88:"Ongoing identification and remediation of vulnerabilities in systems already in operation",a820:"Securing, managing, and monitoring the networks and network devices carrying information",a829:"Testing performed as part of the development and acceptance lifecycle"},{dimension:"Typical scope",a88:"Application and infrastructure vulnerabilities generally",a820:"Network perimeter, segmentation, external-facing infrastructure, cloud network configuration",a829:"The application/API being built or released"},{dimension:"What typically satisfies it",a88:"Regular vulnerability scanning with manual validation",a820:"External network and cloud configuration assessment, network architecture review",a829:"Penetration testing, most auditors expect manual exploitation"},{dimension:"Our matching service",a88:"Vulnerability Assessment, â¬539",a820:"External Infrastructure & Cloud Security Assessment, â¬899",a829:"Focused Pentest, from â¬1,800"}],S=["No evidence the external network perimeter itself was ever assessed â only the web application was tested","Cloud environment configuration never independently reviewed against a benchmark, only against internal assumptions","Network diagram is outdated or doesn't reflect the current segmentation","Testing evidence conflates A.8.20 (network) with A.8.8 (application vulnerabilities) or A.8.29 (app security testing), leaving the network control genuinely unaddressed"],F=["A documented network security policy with a named owner","A dated external network and cloud configuration assessment report","A current network architecture diagram showing segmentation and trust zones","Evidence your cloud environment is checked against a recognised benchmark (CIS Benchmarks for AWS/Azure/GCP)","A clear answer for which control â A.8.8, A.8.20, or A.8.29 â each piece of evidence is meant to satisfy"],r=[{q:"Does a web application penetration test satisfy Annex A.8.20?",a:"Not on its own. A web-application pentest (our Focused, Standard, or Enterprise tiers) tests your application code and API surface, which is generally the evidence auditors expect for A.8.29, not A.8.20. Annex A.8.20 is about the network itself â perimeter, segmentation, and cloud network configuration â which is why it typically needs its own dedicated evidence."},{q:"What's the difference between A.8.20 and A.8.8?",a:"A.8.8 is about ongoing technical vulnerability management across your systems generally. A.8.20 is specifically about the network layer â segmentation, perimeter controls, and how network devices and cloud network configuration are secured and monitored. A single vulnerability assessment of a web application typically doesn't cover A.8.20 on its own."},{q:"Does A.8.20 cover cloud environments?",a:"Yes, in practice â cloud network configuration (security groups, VPC/VNet segmentation, exposed management ports, public endpoints) falls within the spirit of A.8.20's network security scope, alongside traditional on-premises network controls. An assessment that only checks traditional firewalls and ignores cloud network configuration is an incomplete answer for organisations that are meaningfully cloud-hosted."},{q:"How is this different from the ISO 27001 A.8.8 evidence page?",a:"That page covers ongoing vulnerability management evidence generally. This page is specific to the network security control â the evidence auditors expect to see that your network perimeter and segmentation, not just your applications, have been assessed. See our A.8.8 evidence page if your requirement is the broader vulnerability-management control instead."},{q:"What if we've never had our network perimeter tested?",a:"This is typically raised as a nonconformity with a corrective action period, not an automatic certification failure â but starting with an external network and cloud assessment before the audit is a straightforward way to close the gap. Our External Infrastru
1cture & Cloud Security Assessment (â¬899, 8 business days) is scoped for exactly this evidence requirement."}],E={"@context":"https://schema.org","@type":"FAQPage",mainEntity:r.map(i=>({"@type":"Question",name:i.q,acceptedAnswer:{"@type":"Answer",text:i.a}}))},q={"@context":"https://schema.org","@type":"Article",headline:"ISO 27001 Annex A.8.20 (Network Security) â What Evidence Does It Require?",datePublished:"2026-08-24",dateModified:"2026-08-24",author:{"@type":"Person",name:"Vasili Pascal",jobTitle:"CTO & Partner"},publisher:{"@id":"https://www.optimum-web.com/#organization"},mainEntityOfPage:"https://www.optimum-web.com/resources/iso-27001-annex-a-8-20-network-security/"};function P(){const{ref:i,isInView:o}=s(),{ref:c,isInView:l}=s(),{ref:d,isInView:m}=s(),{ref:u,isInView:x}=s(),{ref:h,isInView:p}=s(),{ref:y,isInView:f}=s(),{ref:g,isInView:w}=s();return e.jsxs(v,{title:"ISO 27001 Annex A 8.20: Network Security Evidence | Optimum Web",description:"What ISO/IEC 27001:2022 Annex A 8.20 (network security) requires, what auditors accept as evidence, and how it differs from A 8.8 and A 8.29.",canonical:"https://www.optimum-web.com/resources/iso-27001-annex-a-8-20-network-security/",breadcrumbs:[{label:"Resources",href:"/resources/"},{label:"ISO 27001 Annex A.8.20 Evidence"}],additionalSchemas:[E,q],children:[e.jsx("section",{className:"bg-[#0A1628] pt-20 pb-14",children:e.jsxs("div",{ref:i,className:`container transition-all duration-700 ${o?"opacity-100 translate-y-0":"opacity-0 translate-y-8"}`,children:[e.jsx("div",{className:"inline-flex items-center gap-2 px-4 py-2 bg-[#00D4AA]/10 rounded-full mb-6",children:e.jsx("span",{className:"text-[#00D4AA] text-sm font-semibold tracking-wide uppercase",children:"Resource · ISO 27001"})}),e.jsx("h1",{className:"text-3xl md:text-4xl font-bold text-white mb-4 max-w-3xl",style:{fontFamily:"'Space Grotesk', sans-serif"},children:"ISO 27001 Annex A.8.20 â What Evidence Does Network Security Require?"}),e.jsxs("p",{className:"text-white/40 text-xs mb-6",style:{fontFamily:"'JetBrains Mono', monospace"},children:["Reviewed: ",N," â reviewed quarterly"]}),e.jsx(k,{text:"Annex A.8.20 of ISO/IEC 27001:2022 requires networks and network devices to be secured, managed, and monitored to protect information in systems and applications. Auditors typically look for a documented network security policy, a current network architecture diagram, and evidence the external network perimeter and cloud network configuration have been independently assessed â distinct from A.8.8 (general vulnerability management) and A.8.29 (application security testing).",contentClassName:"speakable speakable-answer"})]})}),e.jsx("section",{className:"bg-white py-14",children:e.jsxs("div",{ref:c,className:`container max-w-3xl transition-all duration-700 ${l?"opacity-100 translate-y-0":"opacity-0 translate-y-8"}`,children:[e.jsx("h2",{className:"text-2xl font-bold text-[#0A1628] mb-4",style:{fontFamily:"'Space Grotesk', sans-serif"},children:"What Does Annex A.8.20 Actually Say?"}),e.jsx("p",{className:"text-[#0A1628]/70 leading-relaxed mb-4",children:`Annex A.8.20, "Network security", asks an organisation to secure, manage, and monitor its networks and network devices in order to protect information within systems and applications. Unlike A.8.8, which is about vulnerabilities generally, A.8.20 is specifically about the network layer itself: how it's segmented, how the perimeter is controlled, and how network activity is monitored.`}),e.jsx("p",{className:"text-[#0A1628]/70 leading-relaxed",children:"In practice, an auditor assessing this control is trying to answer: is the network segmented in a way that limits how far an incident could spread; are external-facing hosts and services identified and controlled; and â increasingly relevant as organisations move to the cloud â is the cloud environment's network configuration (security groups, exposed endpoints, public storage) actually reviewed, or just assumed to be secure by default."})]})}),e.jsx("section",{className:"bg-[#F8F9FA] py-14",children:e.jsxs("div",{ref:d,className:`container max-w-4xl transition-all duration-700 ${m?"opacity-100 translate-y-0":"opacity-0 translate-y-8"}`,children:[e.jsx("h2",{className:"text-2xl font-bold text-[#0A1628] mb-4",style:{fontFamily:"'Space Grotesk', sans-serif"},children:"What Evidence Do Auditors Accept?"}),e.jsx("p",{className:"text-[#0A1628]/60 mb-6 max-w-2xl",children:"No single document satisfies this control on its own. Auditors are typically looking for a combination of the four items below."}),e.jsx("div",{className:"overflow-x-auto rounded-xl border border-[#0A1628]/10",children:e.jsxs("table",{className:"w-full text-sm",children:[e.jsx("thead",{children:e.jsxs("tr",{className:"bg-[#0A1628]/5",children:[e.jsx("th",{className:"text-left px-4 py-3 font-semibold text-[#0A1628]",children:"Type of evidence"}),e.jsx("th",{className:"text-left px-4 py-3 font-semibold text-[#0A1628]",children:"What this looks like in practice"}),e.jsx("th",{className:"text-left px-4 py-3 font-semibold text-[#0A1628]",children:"Who produces it"})]})}),e.jsx("tbody",{children:j.map((t,n)=>e.jsxs("tr",{className:"border-t border-[#0A1628]/8 bg-white",children:[e.jsx("td",{className:"px-4 py-3 font-medium text-[#0A1628]",children:t.type}),e.jsx("td",{className:"px-4 py-3 text-[#0A1628]/70",children:t.practice}),e.jsx("td",{className:"px-4 py-3 text-[#0A1628]/60 text-xs",children:t.issuedBy})]},n))})]})})]})}),e.jsx("section",{className:"bg-white py-14",children:e.jsxs("div",{ref:u,className:`container max-w-5xl transition-all duration-700 ${x?"opacity-100 translate-y-0":"opacity-0 translate-y-8"}`,children:[e.jsx("h2",{className:"text-2xl font-bold text-[#0A1628] mb-3",style:{fontFamily:"'Space Grotesk', sans-serif"},children:"A.8.8 vs A.8.20 vs A.8.29 â All Three, Side by Side"}),e.jsx("p",{className:"text-[#0A1628]/60 mb-6 max-w-2xl",children:"These three controls are the ones most commonly confused in ISO 27001 audits involving security testing, because they sound related but expect different evidence."}),e.jsx("div",{className:"overflow-x-auto rounded-xl border border-[#0A1628]/10",children:e.jsxs("table",{className:"w-full text-sm",children:[e.jsx("thead",{children:e.jsxs("tr",{className:"bg-[#0A1628]/5",children:[e.jsx("th",{className:"text-left px-4 py-3 font-semibold text-[#0A1628]"}),e.jsx("th",{className:"text-left px-4 py-3 font-semibold text-[#0A1628]",children:"Annex A.8.8"}),e.jsx("th",{className:"text-left px-4 py-3 font-semibold text-[#0A1628]",children:"Annex A.8.20"}),e.jsx("th",{className:"text-left px-4 py-3 font-semibold text-[#0A1628]",children:"Annex A.8.29"})]})}),e.jsx("tbody",{children:I.map((t,n)=>e.jsxs("tr",{className:"border-t border-[#0A1628]/8 bg-white",children:[e.jsx("td",{className:"px-4 py-3 font-medium text-[#0A1628]",children:t.dimension}),e.jsx("td",{className:"px-4 py-3 text-[#0A1628]/70",children:t.a88}),e.jsx("td",{className:"px-4 py-3 text-[#0A1628]/70",children:t.a820}),e.jsx("td",{className:"px-4 py-3 text-[#0A1628]/70",children:t.a829})]},n))})]})}),e.jsxs("p",{className:"text-[#0A1628]/60 text-xs mt-4",children:["See also our"," ",e.jsx(a,{href:"/resources/iso-27001-annex-a-8-8-evidence/",className:"text-[#00D4AA] underline underline-offset-2 hover:text-[#00D4AA]/80",children:"Annex A.8.8 evidence page"})," ","for the vulnerability-management control in more depth."]})]})}),e.jsx("section",{className:"bg-[#F8F9FA] py-14",children:e.jsxs("div",{ref:h,className:`container max-w-3xl transition-all duration-700 ${p?"opacity-100 translate-y-0":"opacity-0 translate-y-8"}`,children:[e.jsx("h2",{className:"text-2xl font-bold text-[#0A1628] mb-6",style:{fontFamily:"'Space Grotesk', sans-serif"},children:"What Auditors Most Often Flag"}),e.jsx("div",{className:"space-y-3",children:S.map((t,n)=>e.jsx("div",{className:"flex items-start gap-3 p-4 bg-white rounded-lg border border-[#0A1628]/8",children:e.jsx("span",{className:"text-sm text-[#0A1628]/70",children:t})},n))})]})}),e.jsx("section",{className:"bg-white py-14",children:e.jsxs("div",{ref:y,className:`container max-w-3xl transition-all duration-700 ${f?"opacity-100 translate-y-0":"opacity-0 translate-y-8"}`,children:[e.jsx("h2",{className:"text-2xl font-bold text-[#0A1628] mb-6",style:{fontFamily:"'Space Grotesk', sans-serif"},children:"Evidence Checklist"}),e.jsx("div",{className:"space-y-2 mb-8",children:F.map((t,n)=>e.jsxs("div",{className:"flex items-start gap-3 text-sm text-[#0A1628]/70",children:[e.jsx(A,{className:"w-4 h-4 text-[#00D4AA] shrink-0 mt-0.5"}),t]},n))}),e.jsxs("div",{className:"p-6 bg-[#0A1628] rounded-2xl flex flex-col sm:flex-row gap-3 items-start sm:items-center",children:[e.jsxs("p",{className:"text-white/70 text-sm flex-1",children:["Need evidence that satisfies A.8.20 specifically? Our"," ",e.jsx(a,{href:"/security/penetration-testing/infrastru
1cture-cloud/",className:"text-[#00D4AA] underline underline-offset-2 hover:text-[#00D4AA]/80",children:"â¬899 External Infrastructure & Cloud Security Assessment"})," ","covers the network perimeter and cloud configuration review this evidence checklist describes â see our"," ",e.jsx(a,{href:"/resources/cloud-configuration-review-checklist/",className:"text-[#00D4AA] underline underline-offset-2 hover:text-[#00D4AA]/80",children:"cloud configuration review checklist"})," ","for exactly what's reviewed. If your requirement is Annex A.8.29 (application testing) instead, see our full"," ",e.jsx(a,{href:"/compliance/certification/iso-27001/",className:"text-[#00D4AA] underline underline-offset-2 hover:text-[#00D4AA]/80",children:"ISO 27001 readiness assessment"}),"."]}),e.jsxs(a,{href:"/security/penetration-testing/infrastructure-cloud/",className:"inline-flex items-center justify-center gap-2 px-5 py-3 bg-[#FF6B35] hover:bg-[#e55a25] text-white font-semibold rounded-xl transition-colors text-sm whitespace-nowrap shrink-0","data-ga-event":"select_promotion","data-ga-label":"iso_a820_page_cta",children:["Start With Infrastructure & Cloud Assessment ",e.jsx(b,{className:"w-4 h-4"})]})]})]})}),e.jsx("section",{className:"bg-[#F8F9FA] py-14",children:e.jsxs("div",{ref:g,className:`container max-w-3xl transition-all duration-700 ${w?"opacity-100 translate-y-0":"opacity-0 translate-y-8"}`,children:[e.jsx("h2",{className:"text-2xl font-bold text-[#0A1628] mb-8",style:{fontFamily:"'Space Grotesk', sans-serif"},children:"Frequently Asked Questions"}),e.jsx("div",{className:"space-y-3",children:r.map((t,n)=>e.jsxs("details",{className:"group bg-white rounded-xl border border-gray-200 overflow-hidden",children:[e.jsxs("summary",{className:"flex items-center justify-between p-4 cursor-pointer text-[#0A1628] font-semibold text-sm hover:text-[#00D4AA] transition-colors",children:[t.q,e.jsx("span",{className:"ml-4 text-gray-400 group-open:rotate-45 transition-transform text-lg",children:"+"})]}),e.jsx("div",{className:"px-4 pb-4 text-gray-600 text-sm leading-relaxed border-t border-gray-100 pt-3",children:t.a})]},n))})]})})]})}export{P as default};
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.