UNCLASSIFIED
5.7
Network Security Controls
Proportionate risk-based technical security controls can help achieve the
mandated NISF minimum-security outcomes outlined below.
IS6 – All organisations must apply technical security controls appropriate to the
protected computer’s value, sensitivity and criticality. As a minimum
requirement, the controls must include: (a) a formally documented security
architecture providing end-to-end network security; (b) the segregation of
networks handling information of different business impact levels; (c) the
enforcement of service minimisation; (d) the use of unified authentication and
authorisation services; (e) the matching of security levels with information
protection needs; and, (f) the adoption of the defence-in-depth principle.
To achieve the security outcomes mandated above, organisations must:
Adopt a security architecture that provides end-to-end network security by
enabling the detection, identification and correction of security vulnerabilities;
Ensure that users only gain access to network services e.g. web browsing
and file upload if they have a legitimate business reason for the access;
Enforce sufficient segregation, zoning or variable depth security to separate
specific areas of the network, groups of information services and information
systems handling data of different security classification levels;
Implement boundary protection measures for shared networks, especially
those extending across organisational boundaries, in compliance with the
access control policy and requirements of the business applications;
Enforce network routing controls to ensure that connections and information
flows do not breach the access control policy of the business applications;
Apply the principle of service minimisation consistently across the network by
disabling services that do not satisfy business and security needs for access;
Adopt solutions that use techniques such as encryption to offer converged
voice, data and video packets protection appropriate to their security needs;
Adopt the “defence in depth” or “layered‟ approach to network security
through the use of different technical security controls and security products
to mitigate security threats collectively; and
In accordance with ISO/IEC 18043, install network intrusion detection (NIDS)
and network intrusion protection (NIPS) devices to monitor network traffic for
unusual or suspicious activity and prevent cyber attacks; and
Build survivability into networks to ensure that technical solutions continue to
deliver a minimum set of essential functionality in a timely manner even if
parts of the network are unreachable or have failed due to an attack.
28