ISO 27001 Annex A.8.20 — What Evidence Does Network Security Require?
Reviewed: 24 August 2026 — reviewed quarterly
Quick Answer
Annex A.8.20 of ISO/IEC 27001:2022 requires networks and network devices to be secured, managed, and monitored to protect information in systems and applications. Auditors typically look for a documented network security policy, a current network architecture diagram, and evidence the external network perimeter and cloud network configuration have been independently assessed — distinct from A.8.8 (general vulnerability management) and A.8.29 (application security testing).
What Does Annex A.8.20 Actually Say?
Annex A.8.20, "Network security", asks an organisation to secure, manage, and monitor its networks and network devices in order to protect information within systems and applications. Unlike A.8.8, which is about vulnerabilities generally, A.8.20 is specifically about the network layer itself: how it's segmented, how the perimeter is controlled, and how network activity is monitored.
In practice, an auditor assessing this control is trying to answer: is the network segmented in a way that limits how far an incident could spread; are external-facing hosts and services identified and controlled; and — increasingly relevant as organisations move to the cloud — is the cloud environment's network configuration (security groups, exposed endpoints, public storage) actually reviewed, or just assumed to be secure by default.
What Evidence Do Auditors Accept?
No single document satisfies this control on its own. Auditors are typically looking for a combination of the four items below.
| Type of evidence | What this looks like in practice | Who produces it |
|---|---|---|
| Documented network security policy | A written policy covering network segmentation, access boundaries, and monitoring, with a named owner | Internal — written by the organisation |
| Independent network/cloud testing report | An external network and cloud configuration assessment covering the in-scope perimeter, with dated findings | External tester or internal security team |
| Network architecture diagram | A current diagram showing segmentation, trust zones, and where the external perimeter sits | Internal — maintained and version-controlled |
| Cloud configuration baseline | Evidence the cloud environment is checked against a recognised benchmark (e.g. CIS Benchmarks), not just default settings | External assessment or internal cloud security team |
A.8.8 vs A.8.20 vs A.8.29 — All Three, Side by Side
These three controls are the ones most commonly confused in ISO 27001 audits involving security testing, because they sound related but expect different evidence.
| Annex A.8.8 | Annex A.8.20 | Annex A.8.29 | |
|---|---|---|---|
| Control name | Management of technical vulnerabilities | Network security | Security testing in development and acceptance |
| What it's about | Ongoing identification and remediation of vulnerabilities in systems already in operation | Securing, managing, and monitoring the networks and network devices carrying information | Testing performed as part of the development and acceptance lifecycle |
| Typical scope | Application and infrastructure vulnerabilities generally | Network perimeter, segmentation, external-facing infrastructure, cloud network configuration | The application/API being built or released |
| What typically satisfies it | Regular vulnerability scanning with manual validation | External network and cloud configuration assessment, network architecture review | Penetration testing, most auditors expect manual exploitation |
| Our matching service | Vulnerability Assessment, €539 | External Infrastructure & Cloud Security Assessment, €899 | Focused Pentest, from €1,800 |
See also our Annex A.8.8 evidence page for the vulnerability-management control in more depth.
What Auditors Most Often Flag
Evidence Checklist
Need evidence that satisfies A.8.20 specifically? Our €899 External Infrastructure & Cloud Security Assessment covers the network perimeter and cloud configuration review this evidence checklist describes — see our cloud configuration review checklist for exactly what's reviewed. If your requirement is Annex A.8.29 (application testing) instead, see our full ISO 27001 readiness assessment.
Start With Infrastructure & Cloud Assessment