through a gateway in accordance with network controls policy before granting access to
internal systems.
The authentication, encryption and user level network access control technologies of modern,
standards based wireless networks may be sufficient for direct connection to the organization’s
internal network when properly implemented.
Networks often extend beyond organizational boundaries, as business partnerships are formed
that require the interconnection or sharing of information processing and networking facilities.
Such extensions can increase the risk of unauthorized access to the organization’s information
systems that use the network, some of which require protection from other network users
because of their sensitivity or criticality. (NL ISO/IEC, 2015)
4.3. Security of Network Services
Security mechanisms, service levels and management requirements of all network services
should be identified and included in network services agreements, whether these services are
provided in-house or outsourced.
The ability of the network service provider to manage agreed services in a secure way should be
determined and regularly monitored, and the right to audit should be agreed.
The security arrangements necessary for particular services, such as security features, service
levels and management requirements, should be identified. The organization should ensure
that network service providers implement these measures.
Network services include the provision of connections, private network services and value
added networks and managed network security solutions such as firewalls and intrusion
detection systems.
These services can range from simple unmanaged bandwidth to complex value-added offerings.
Security features of network services could be:
a) technology applied for security of network services, such as authentication,
encryption and network connection controls;
b) technical parameters required for secured connection with the network services in
accordance with the security and network connection rules;
c) procedures for the network service usage to restrict access to network services or
applications, where necessary.
(NL ISO/IEC, 2010)
4.4. Electronic Messaging
Information involved in electronic messaging should be appropriately protected.
Lebanese National Security Policy Guidelines v1.7
Page
27 |