INF-005 Secure Network Architecture and Defence
Description
Network architecture is documented, including trust zones, data flows and perimeter boundaries. Defence-in-depth controls, including firewalls, intrusion detection or prevention systems and egress filtering, are deployed at network boundaries. Outbound web access from production systems and corporate devices is filtered against malicious and unauthorised destinations under a documented egress policy. The architecture and the egress policy are reviewed at defined intervals.
Rationale
Documented architecture supports threat modelling and audit verification. Layered network defences reduce exposure to external and internal network-based attacks.
Applicability (9 profiles)
Annex points 6.7.2(j), (k) and (l) require three forward-looking artefacts the control does not name: an implementation plan for the transition to latest generation network layer communication protocols, an implementation plan for the deployment of modern e-mail communications standards, and best practice for DNS security and for Internet routing security and routing hygiene. Recital 32 of the Regulation records that the standards themselves are not yet settled, so the duty is to hold a plan rather than to have arrived.
Framework Mappings (23)
| I&S-03 | Network Security | full |
| I&S-08 | Network Architecture Documentation | full |
| I&S-09 | Network Defense | full |
| I&S-03 | Network Security | full |
| I&S-08 | Network Architecture Documentation | full |
| I&S-09 | Network Defense | full |
| 8.20 | Networks security | full |
| 8.21 | Security of network services | full |
| 8.23 | Web filtering | full |
| NIS2-CIR-6.7 | Network Security | partial |
| NIS2-CIR-6.8 | Network Segmentation | informative |
| AC-4 | Information Flow Enforcement | partial |
| CA-3 | Information Exchange | partial |
| CA-9 | Internal System Connections | partial |
| PL-8 | Security and Privacy Architectures | informative |
| SC-35 | External Malicious Code Identification | partial |
| SC-5 | Denial-of-service Protection | full |
| SC-7 | Boundary Protection | partial |
| SC-7(3) | Boundary Protection | Access Points | partial |
| SC-7(4) | Boundary Protection | External Telecommunications Services | partial |
| SC-7(5) | Boundary Protection | Deny by Default — Allow by Exception | partial |
| SC-7(8) | Boundary Protection | Route Traffic to Authenticated Proxy Servers | partial |
| SI-4(1) | System Monitoring | System-wide Intrusion Detection System | informative |
Evidence (4)
Firewall, IDS/IPS, and egress filtering configuration deployed at network boundaries, evidencing defence-in-depth controls.
Example: AWS WAF rule group export, GCP Cloud Armor policy, or equivalent firewall and IDS/IPS configuration showing boundary control rules for production network perimeters
Test: Export boundary control configurations (WAF, firewall, IDS/IPS). Verify: (1) ingress traffic is restricted to defined permitted ports and sources; (2) egress filtering is configured to restrict outbound traffic to known destinations or service endpoints; (3) IDS or IPS rules are current and enabled; (4) rules are reviewed on the documented schedule.
Network architecture document including trust zone definitions, data flow diagrams, and documented review schedule.
Example: Network Architecture Design or Security Architecture document with current data flow diagrams, showing perimeter boundaries, trust zones, and last review date
Test: Request the network architecture document and the last scheduled review record. Verify: (1) trust zones and data flows are documented; (2) the document reflects the current production architecture; (3) a review was completed within the defined interval (typically annually); (4) the document is approved by a named owner.
Web filtering policy configuration showing categories of restricted destinations applied to outbound web traffic from production systems and corporate devices.
Example: Zscaler, Cisco Umbrella, Palo Alto DNS security, or equivalent web filtering policy export showing blocked categories, custom blocklist entries, and enforcement scope
Test: Export the web filtering policy configuration. Verify: (1) web filtering is enforced for outbound traffic from all in-scope devices and production systems; (2) malicious and prohibited destination categories are blocked; (3) the policy was reviewed within the defined interval; (4) test a request to a known malicious domain indicator from an in-scope device, confirming it is blocked.
Egress filtering policy document defining approved egress destinations, blocked categories, and the review cycle for egress rules.
Example: Web Filtering and Egress Control Policy (version-controlled, approved within last 12 months) with defined egress rules and a documented review schedule
Test: Request the egress filtering policy. Verify: (1) permitted and prohibited outbound destinations or categories are defined; (2) the policy explicitly addresses production system egress and corporate device egress; (3) a review schedule is documented and the last review was completed within the required interval.
Questions (3)
Is your production network architecture documented?
Documentation should include current data flow diagrams and a network diagram showing trust zones. Defence controls should include at minimum a firewall or WAF and egress filtering.
Which network defence controls are deployed at production network boundaries?
A WAF and egress filtering are baseline expectations at an internet-facing boundary. IDS/IPS and DDoS protection indicate a more mature defence-in-depth posture.
Is outbound web access from production systems and corporate devices filtered to restrict access to malicious or unauthorised external destinations?
Web filtering should block known malicious categories and command-and-control infrastructure. Egress filtering policies should be documented and applied to both production and corporate traffic.