UNCLASSIFIED 5.7 Network Security Controls Proportionate risk-based technical security controls can help achieve the mandated NISF minimum-security outcomes outlined below. IS6 – All organisations must apply technical security controls appropriate to the protected computer’s value, sensitivity and criticality. As a minimum requirement, the controls must include: (a) a formally documented security architecture providing end-to-end network security; (b) the segregation of networks handling information of different business impact levels; (c) the enforcement of service minimisation; (d) the use of unified authentication and authorisation services; (e) the matching of security levels with information protection needs; and, (f) the adoption of the defence-in-depth principle. To achieve the security outcomes mandated above, organisations must:  Adopt a security architecture that provides end-to-end network security by enabling the detection, identification and correction of security vulnerabilities;  Ensure that users only gain access to network services e.g. web browsing and file upload if they have a legitimate business reason for the access;  Enforce sufficient segregation, zoning or variable depth security to separate specific areas of the network, groups of information services and information systems handling data of different security classification levels;  Implement boundary protection measures for shared networks, especially those extending across organisational boundaries, in compliance with the access control policy and requirements of the business applications;  Enforce network routing controls to ensure that connections and information flows do not breach the access control policy of the business applications;  Apply the principle of service minimisation consistently across the network by disabling services that do not satisfy business and security needs for access;  Adopt solutions that use techniques such as encryption to offer converged voice, data and video packets protection appropriate to their security needs;  Adopt the “defence in depth” or “layered‟ approach to network security through the use of different technical security controls and security products to mitigate security threats collectively; and  In accordance with ISO/IEC 18043, install network intrusion detection (NIDS) and network intrusion protection (NIPS) devices to monitor network traffic for unusual or suspicious activity and prevent cyber attacks; and  Build survivability into networks to ensure that technical solutions continue to deliver a minimum set of essential functionality in a timely manner even if parts of the network are unreachable or have failed due to an attack. 28

Select target paragraph3