Overview
ISO/IEC 27033-4:2014 - part of the ISO/IEC 27033 network security family - provides guidance for securing communications between networks by using security gateways (for example, firewalls, application firewalls, intrusion prevention systems). The standard focuses on aligning gateway configuration and deployment with a documented information security policy, covering threat identification, requirements definition, design and implementation techniques, and ongoing operation, monitoring and review of gateway controls.
Key technical topics and requirements
The standard addresses practical, technical topics that form the basis for secure gateway deployments:
- Threat analysis and security requirements: identify network threats associated with gateways and derive technical requirements from that analysis.
- Security controls and filtering techniques: guidance on stateless packet filtering, stateful packet inspection, application firewalling, content filtering, and use of IDS/IPS.
- Security management and APIs: management interfaces and programmatic control for secure administration.
- Design techniques: structuring gateway components, deployment patterns for different network scenarios (e.g., perimeter networks, DMZs), and approaches to integrate multiple gateway controls.
- Implementation and operational issues: configuration best practices, logging and audit capabilities, high availability considerations, and monitoring and review processes.
- Product selection guidance: selecting architectures, hardware/software platforms, security features, administration and logging capabilities, and training needs.
Practical applications and intended users
ISO/IEC 27033-4 is practical for organizations that need to secure network boundaries and inter-network communications. Typical applications include:
- Designing and deploying enterprise perimeter defenses (firewalls, IPS/IDS, application firewalls).
- Protecting connections between corporate networks, branch offices, partners, and public networks.
- Specifying procurement and evaluation criteria for security gateway products.
- Integrating gateway controls into an organization’s information security management system.
Intended users:
- Network architects and designers
- Network managers and administrators
- Network security officers and security architects
- System integrators and procurement teams
Related Standards
ISO/IEC 27033-4 is part of the ISO/IEC 27033 series. Relevant related parts include:
For implementation-level details and compliance, consult the full ISO/IEC 27033-4:2014 document from ISO.