🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Resource · ISO 27001

ISO 27001 Annex A.8.20 — What Evidence Does Network Security Require?

Reviewed: 24 August 2026 — reviewed quarterly

Quick Answer

Annex A.8.20 of ISO/IEC 27001:2022 requires networks and network devices to be secured, managed, and monitored to protect information in systems and applications. Auditors typically look for a documented network security policy, a current network architecture diagram, and evidence the external network perimeter and cloud network configuration have been independently assessed — distinct from A.8.8 (general vulnerability management) and A.8.29 (application security testing).

What Does Annex A.8.20 Actually Say?

Annex A.8.20, "Network security", asks an organisation to secure, manage, and monitor its networks and network devices in order to protect information within systems and applications. Unlike A.8.8, which is about vulnerabilities generally, A.8.20 is specifically about the network layer itself: how it's segmented, how the perimeter is controlled, and how network activity is monitored.

In practice, an auditor assessing this control is trying to answer: is the network segmented in a way that limits how far an incident could spread; are external-facing hosts and services identified and controlled; and — increasingly relevant as organisations move to the cloud — is the cloud environment's network configuration (security groups, exposed endpoints, public storage) actually reviewed, or just assumed to be secure by default.

What Evidence Do Auditors Accept?

No single document satisfies this control on its own. Auditors are typically looking for a combination of the four items below.

Type of evidenceWhat this looks like in practiceWho produces it
Documented network security policyA written policy covering network segmentation, access boundaries, and monitoring, with a named ownerInternal — written by the organisation
Independent network/cloud testing reportAn external network and cloud configuration assessment covering the in-scope perimeter, with dated findingsExternal tester or internal security team
Network architecture diagramA current diagram showing segmentation, trust zones, and where the external perimeter sitsInternal — maintained and version-controlled
Cloud configuration baselineEvidence the cloud environment is checked against a recognised benchmark (e.g. CIS Benchmarks), not just default settingsExternal assessment or internal cloud security team

A.8.8 vs A.8.20 vs A.8.29 — All Three, Side by Side

These three controls are the ones most commonly confused in ISO 27001 audits involving security testing, because they sound related but expect different evidence.

Annex A.8.8Annex A.8.20Annex A.8.29
Control nameManagement of technical vulnerabilitiesNetwork securitySecurity testing in development and acceptance
What it's aboutOngoing identification and remediation of vulnerabilities in systems already in operationSecuring, managing, and monitoring the networks and network devices carrying informationTesting performed as part of the development and acceptance lifecycle
Typical scopeApplication and infrastructure vulnerabilities generallyNetwork perimeter, segmentation, external-facing infrastructure, cloud network configurationThe application/API being built or released
What typically satisfies itRegular vulnerability scanning with manual validationExternal network and cloud configuration assessment, network architecture reviewPenetration testing, most auditors expect manual exploitation
Our matching serviceVulnerability Assessment, €539External Infrastructure & Cloud Security Assessment, €899Focused Pentest, from €1,800

See also our Annex A.8.8 evidence page for the vulnerability-management control in more depth.

What Auditors Most Often Flag

No evidence the external network perimeter itself was ever assessed — only the web application was tested
Cloud environment configuration never independently reviewed against a benchmark, only against internal assumptions
Network diagram is outdated or doesn't reflect the current segmentation
Testing evidence conflates A.8.20 (network) with A.8.8 (application vulnerabilities) or A.8.29 (app security testing), leaving the network control genuinely unaddressed

Evidence Checklist

A documented network security policy with a named owner
A dated external network and cloud configuration assessment report
A current network architecture diagram showing segmentation and trust zones
Evidence your cloud environment is checked against a recognised benchmark (CIS Benchmarks for AWS/Azure/GCP)
A clear answer for which control — A.8.8, A.8.20, or A.8.29 — each piece of evidence is meant to satisfy

Need evidence that satisfies A.8.20 specifically? Our €899 External Infrastructure & Cloud Security Assessment covers the network perimeter and cloud configuration review this evidence checklist describes — see our cloud configuration review checklist for exactly what's reviewed. If your requirement is Annex A.8.29 (application testing) instead, see our full ISO 27001 readiness assessment.

Start With Infrastructure & Cloud Assessment

Frequently Asked Questions

Does a web application penetration test satisfy Annex A.8.20?+
Not on its own. A web-application pentest (our Focused, Standard, or Enterprise tiers) tests your application code and API surface, which is generally the evidence auditors expect for A.8.29, not A.8.20. Annex A.8.20 is about the network itself — perimeter, segmentation, and cloud network configuration — which is why it typically needs its own dedicated evidence.
What's the difference between A.8.20 and A.8.8?+
A.8.8 is about ongoing technical vulnerability management across your systems generally. A.8.20 is specifically about the network layer — segmentation, perimeter controls, and how network devices and cloud network configuration are secured and monitored. A single vulnerability assessment of a web application typically doesn't cover A.8.20 on its own.
Does A.8.20 cover cloud environments?+
Yes, in practice — cloud network configuration (security groups, VPC/VNet segmentation, exposed management ports, public endpoints) falls within the spirit of A.8.20's network security scope, alongside traditional on-premises network controls. An assessment that only checks traditional firewalls and ignores cloud network configuration is an incomplete answer for organisations that are meaningfully cloud-hosted.
How is this different from the ISO 27001 A.8.8 evidence page?+
That page covers ongoing vulnerability management evidence generally. This page is specific to the network security control — the evidence auditors expect to see that your network perimeter and segmentation, not just your applications, have been assessed. See our A.8.8 evidence page if your requirement is the broader vulnerability-management control instead.
What if we've never had our network perimeter tested?+
This is typically raised as a nonconformity with a corrective action period, not an automatic certification failure — but starting with an external network and cloud assessment before the audit is a straightforward way to close the gap. Our External Infrastructure & Cloud Security Assessment (€899, 8 business days) is scoped for exactly this evidence requirement.