DOC-019 ← Document Portal

Network and Systems Security Policy

Segmentation, firewall, IDS/IPS, monitoring, logs and email protection
Document Number
DOC-019
Version
▸ 1.0
Status
DRAFT
Issue Date
▸ DD/MM/YYYY
Owner
▸ IT Administrator / CISO
Approved by
▸ Board / CEO
Legal Basis
Art. 21(2) NIS2; ISO/IEC 27001:2022 A.8.20–A.8.23; NIST CSF
Related Documents
DOC-008 | DOC-009 | DOC-014

1. Network Architecture and Segmentation

The organisation applies network segmentation, limiting traffic flow between zones to the necessary minimum (zero trust network access – ZTNA).

Network zoneDescriptionContentsIsolation
Internet / Untrusted External – outside organisation's control Public internet Perimeter firewall
DMZ Demilitarised zone – public servers Web servers, reverse proxy, MX, VPN endpoint Internal and external firewall (dual firewall)
Corporate network (LAN) Main user network Workstations, laptops, printers Firewall rules, VLAN
Server network Application and database servers AD servers, ERP, databases VLAN, ACL, micro-segmentation
OT/ICS network (if applicable) Industrial control systems network PLC, SCADA, HMI Physical or logical isolation from IT (air-gap or data diode)
Management network Infrastructure management network IPMI, out-of-band management, SNMP Separate VLAN, admin-only access
▸ Organisation completes – network diagram

Network diagram: ▸ [current network diagram location]

VLAN technology: ▸ [switch make/model]

2. Firewall and Traffic Control

RequirementStandardImplementation
Firewall rules Default deny, permit only required traffic ▸ [FW make/model, e.g. Palo Alto / Fortinet / pfSense]
Firewall rule review ▸ quarterlymin. 2×/year ▸ CISO / IT Admin
Web Application Firewall (WAF) Required for public web applications ▸ [e.g. ModSecurity / Cloudflare WAF / Azure Application Gateway]
IDS/IPS Required in DMZ and server network ▸ [e.g. Suricata / Snort / Zeek / Cisco IPS]
Network Access Control (NAC) Recommended ▸ [e.g. Cisco ISE / ForeScout / 802.1X]

3. Logging and Monitoring – NIS2 Requirement

⚠ Critical – obligation to collect logs for min. 12 months (NIS2)
Log sourceRetentionSIEM / log management tool
Server system logs (OS) ▸ [12 months]min. 12 months – NIS2
Firewall / IPS logs ▸ [12 months]min. 12 months
Active Directory logs (authentications) ▸ [12 months]min. 12 months
VPN logs ▸ [12 months]min. 12 months
Web application logs ▸ [12 months]min. 12 months
OT/SCADA logs (if applicable) ▸ [12 months]min. 12 months

SIEM platform: ▸ [e.g. Microsoft Sentinel / Splunk / Elastic SIEM / OSSIM / Wazuh]

Logs stored in tamper-proof manner: ▸ [YES / NO – describe mechanism: immutable storage / write-once]

4. Endpoint Protection

ControlRequirementTool
Antivirus / EDR REQUIRED on all workstations ▸ [e.g. CrowdStrike Falcon / MS Defender / SentinelOne]
Patch management (endpoint) Per SLA from DOC-014 ▸ [e.g. WSUS / Intune / SCCM / Ansible]
Disk encryption REQUIRED on laptops and mobile devices ▸ [e.g. BitLocker / FileVault]
MDM (Mobile Device Management) Required for mobile devices with access to org data ▸ [e.g. Microsoft Intune / JAMF]
DLP (Data Loss Prevention) Recommended for CONFIDENTIAL and SECRET data ▸ [e.g. Microsoft Purview / Symantec DLP]

5. Email Security

MechanismRequirementDeployment status
SPF (Sender Policy Framework) REQUIRED ▸ [Deployed / In progress] – DNS record: ▸ [TXT value]
DKIM (DomainKeys Identified Mail) REQUIRED ▸ [Deployed / In progress]
DMARC REQUIRED – policy at least quarantine ▸ [Deployed – policy: quarantine/reject]min. quarantine
Anti-spam / anti-phishing filter REQUIRED ▸ [e.g. MS Defender for Office / Proofpoint / Mimecast]
Email encryption (S/MIME / PGP) Required for CONFIDENTIAL data in email ▸ [Deployed / In progress / Not applicable]

6. DNS and Wireless Network Security

ElementRequirementImplementation
DNS Filtering (protection against malware C2) Recommended ▸ [e.g. Cisco Umbrella / Cloudflare Gateway / Pi-hole]
Corporate Wi-Fi ▸ WPA3 / WPA2-Enterprise (802.1X)min. WPA2-Enterprise ▸ [e.g. Aruba / Ubiquiti / Cisco WLC]
Guest Wi-Fi Isolated from corporate network ▸ [separate SSID with captive portal]
Remote worker home Wi-Fi ▸ [WPA2/WPA3, separate network for company devices] ▸ [employee guidance]

Change History

VersionDateAuthorDescriptionApproved by
▸ 1.0▸ Initial release▸ Board
DOC-019 Network and Systems Security | v1.0 | NIS2/ISMS