Network and Systems Security Policy
Segmentation, firewall, IDS/IPS, monitoring, logs and email protection
1. Network Architecture and Segmentation
The organisation applies network segmentation, limiting traffic flow between zones to the necessary minimum (zero trust network access – ZTNA).
| Network zone | Description | Contents | Isolation |
|---|---|---|---|
| Internet / Untrusted | External – outside organisation's control | Public internet | Perimeter firewall |
| DMZ | Demilitarised zone – public servers | Web servers, reverse proxy, MX, VPN endpoint | Internal and external firewall (dual firewall) |
| Corporate network (LAN) | Main user network | Workstations, laptops, printers | Firewall rules, VLAN |
| Server network | Application and database servers | AD servers, ERP, databases | VLAN, ACL, micro-segmentation |
| OT/ICS network (if applicable) | Industrial control systems network | PLC, SCADA, HMI | Physical or logical isolation from IT (air-gap or data diode) |
| Management network | Infrastructure management network | IPMI, out-of-band management, SNMP | Separate VLAN, admin-only access |
▸ Organisation completes – network diagram
Network diagram: ▸ [current network diagram location]
VLAN technology: ▸ [switch make/model]
2. Firewall and Traffic Control
| Requirement | Standard | Implementation |
|---|---|---|
| Firewall rules | Default deny, permit only required traffic | ▸ [FW make/model, e.g. Palo Alto / Fortinet / pfSense] |
| Firewall rule review | ▸ quarterlymin. 2×/year | ▸ CISO / IT Admin |
| Web Application Firewall (WAF) | Required for public web applications | ▸ [e.g. ModSecurity / Cloudflare WAF / Azure Application Gateway] |
| IDS/IPS | Required in DMZ and server network | ▸ [e.g. Suricata / Snort / Zeek / Cisco IPS] |
| Network Access Control (NAC) | Recommended | ▸ [e.g. Cisco ISE / ForeScout / 802.1X] |
3. Logging and Monitoring – NIS2 Requirement
⚠ Critical – obligation to collect logs for min. 12 months (NIS2)
| Log source | Retention | SIEM / log management tool |
|---|---|---|
| Server system logs (OS) | ▸ [12 months]min. 12 months – NIS2 | ▸ |
| Firewall / IPS logs | ▸ [12 months]min. 12 months | ▸ |
| Active Directory logs (authentications) | ▸ [12 months]min. 12 months | ▸ |
| VPN logs | ▸ [12 months]min. 12 months | ▸ |
| Web application logs | ▸ [12 months]min. 12 months | ▸ |
| OT/SCADA logs (if applicable) | ▸ [12 months]min. 12 months | ▸ |
SIEM platform: ▸ [e.g. Microsoft Sentinel / Splunk / Elastic SIEM / OSSIM / Wazuh]
Logs stored in tamper-proof manner: ▸ [YES / NO – describe mechanism: immutable storage / write-once]
4. Endpoint Protection
| Control | Requirement | Tool |
|---|---|---|
| Antivirus / EDR | REQUIRED on all workstations | ▸ [e.g. CrowdStrike Falcon / MS Defender / SentinelOne] |
| Patch management (endpoint) | Per SLA from DOC-014 | ▸ [e.g. WSUS / Intune / SCCM / Ansible] |
| Disk encryption | REQUIRED on laptops and mobile devices | ▸ [e.g. BitLocker / FileVault] |
| MDM (Mobile Device Management) | Required for mobile devices with access to org data | ▸ [e.g. Microsoft Intune / JAMF] |
| DLP (Data Loss Prevention) | Recommended for CONFIDENTIAL and SECRET data | ▸ [e.g. Microsoft Purview / Symantec DLP] |
5. Email Security
| Mechanism | Requirement | Deployment status |
|---|---|---|
| SPF (Sender Policy Framework) | REQUIRED | ▸ [Deployed / In progress] – DNS record: ▸ [TXT value] |
| DKIM (DomainKeys Identified Mail) | REQUIRED | ▸ [Deployed / In progress] |
| DMARC | REQUIRED – policy at least quarantine | ▸ [Deployed – policy: quarantine/reject]min. quarantine |
| Anti-spam / anti-phishing filter | REQUIRED | ▸ [e.g. MS Defender for Office / Proofpoint / Mimecast] |
| Email encryption (S/MIME / PGP) | Required for CONFIDENTIAL data in email | ▸ [Deployed / In progress / Not applicable] |
6. DNS and Wireless Network Security
| Element | Requirement | Implementation |
|---|---|---|
| DNS Filtering (protection against malware C2) | Recommended | ▸ [e.g. Cisco Umbrella / Cloudflare Gateway / Pi-hole] |
| Corporate Wi-Fi | ▸ WPA3 / WPA2-Enterprise (802.1X)min. WPA2-Enterprise | ▸ [e.g. Aruba / Ubiquiti / Cisco WLC] |
| Guest Wi-Fi | Isolated from corporate network | ▸ [separate SSID with captive portal] |
| Remote worker home Wi-Fi | ▸ [WPA2/WPA3, separate network for company devices] | ▸ [employee guidance] |
Change History
| Version | Date | Author | Description | Approved by |
|---|---|---|---|---|
| ▸ 1.0 | ▸ | ▸ | ▸ Initial release | ▸ Board |
DOC-019 Network and Systems Security | v1.0 | NIS2/ISMS