ISO/IEC 27033-5:2013
Information technology — Security techniques — Network security — Part 5: Securing communications across networks using Virtual Private Networks (VPNs)
Information technology — Security techniques — Network security — Part 5: Securing communications across networks using Virtual Private Networks (VPNs)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 14
- Дата публикации:
- 29 июля 2013 г.
- Издание:
- ISO/IEC IS 27033 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 27033-5:2013 gives guidelines for the selection, implementation, and monitoring of the technical controls necessary to provide network security using Virtual Private Network (VPN) connections to interconnect networks and connect remote users to networks.
Abstract
Overview
ISO/IEC 27033-5:2013 - part of the ISO/IEC 27033 family - provides guidelines for the selection, implementation and monitoring of technical controls required to secure communications across networks using Virtual Private Networks (VPNs). The standard covers VPN use to interconnect sites and to support remote-user access over private or public infrastructures, and sets out a framework for assessing threats, defining security requirements and applying design and operational controls.
Key topics and technical requirements
- VPN types and architectures: Layer 2 VPNs (simulated LAN), Layer 3 VPNs (simulated WAN), and higher‑layer VPNs (application/transport layer tunneling) and their implications for addressing, routing and service models.
- Security threats: Intrusions, Denial‑of‑Service (DoS), unauthorized tunnel access, label spoofing and information leakage from core networks.
- Security objectives: Protection of confidentiality, integrity, authenticity, authorization, availability, and tunnel endpoint security.
- Security controls and design techniques: Guidance on ingress filtering, address‑space/routing separation, resistance to DoS and unauthorized access, and ensuring the hosting or provider network does not expose core topology. The standard includes sections on regulatory/legislative considerations, VPN management, architectural design and technical considerations.
- Product and protocol selection: Advice on carrier protocol choices, VPN appliances and managed‑service considerations (e.g., MPLS, IPsec, SSL/TLS implications are referenced in abbreviation lists).
- Monitoring and lifecycle: Guidance for implementing controls, ongoing monitoring and adapting VPN controls to evolving threats.
Practical applications
- Designing secure site‑to‑site and remote access VPN deployments for enterprises.
- Evaluating and procuring VPN appliances, managed VPN services and carrier offerings.
- Integrating VPN security into broader information security management and risk‑management programs.
- Defining technical requirements for compliance, audits and operational procedures to mitigate intrusion and DoS risks.
Who should use this standard
- Network architects and engineers designing VPN topologies.
- IT/security managers responsible for secure remote access and WAN interconnection.
- Service providers offering managed VPN or MPLS solutions.
- Procurement teams selecting VPN hardware and services, and auditors assessing VPN controls.
Related standards
- ISO/IEC 27033‑1 (Overview and concepts) and other parts of the 27033 series.
- ISO/IEC 27001, ISO/IEC 27002 and ISO/IEC 27005 (referenced normative documents for ISMS, security practices and risk management).
ISO/IEC 27033-5:2013 is practical, vendor‑neutral guidance for implementing robust VPN security aligned with organizational risk and compliance needs. Keywords: ISO/IEC 27033-5:2013, VPN security, network security, VPN design, IPsec, remote access VPN, VPN best practices.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27033-5:2013
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 27033-1:2015
ДействующийInformation technology — Security techniques — Network security — Part 1: Overview and concepts
Overview ISO/IEC 27033-1:2015 - Information technology - Security techniques - Network security - Part 1: Overview and concepts - provides a high-level framework and management guidance for network s…
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…