Overview
ISO/IEC 27033-2:2012 - Information technology - Security techniques - Network security - Part 2 - provides practical guidelines for the design and implementation of network security. It helps organizations plan, document and validate network security measures so that information flows that support business processes are enabled while harmful flows are prevented. The standard emphasizes structured preparation (asset and requirements identification), defensible design patterns, controlled implementation, testing and formal sign‑off.
Key topics and technical requirements
- Preparing for design
- Asset identification: catalog physical (routers, switches, servers) and logical assets (configs, data, protocols) to prioritize protection.
- Requirements collection: capture legal/regulatory, business and performance requirements, including cross‑jurisdictional considerations.
- Design principles
- Defence in depth: layered controls across the network stack to reduce single points of failure.
- Network zones: segmentation of networks based on trust, function and risk.
- Design resilience: fault tolerance and continuity measures to maintain availability.
- Scenarios, models and frameworks: use threat and use‑case scenarios to validate designs.
- Implementation
- Selection criteria: guidance for choosing network components and vendors based on security, manageability and interoperability.
- Network management: operational controls for configuration, patching, and secure administration.
- Logging, monitoring and incident response: requirements for audit logs, continuous monitoring and procedures to detect and respond to security events.
- Documentation and testing: templates, test plans, and formal sign‑off processes to validate and record the implemented design.
- Supporting material
- Informative annexes include cross‑references to ISO/IEC 27001/27002 controls, example documentation templates (network architecture, functional security requirements), and mappings to ITU‑T X.805.
Practical applications and who uses it
ISO/IEC 27033-2 is intended for:
- Network architects and security engineers designing secure network topologies and controls.
- IT managers and system integrators selecting products, vendors and operational processes.
- Compliance officers and auditors aligning network design with ISO/IEC 27001/27002 controls and regulatory obligations.
- Security operations teams implementing logging, monitoring and incident response processes.
Practical uses include producing network security architecture documents, defining segmentation and access controls, creating test plans for security validation, and providing auditable evidence of design decisions and sign‑offs.
Related standards
Keywords: ISO/IEC 27033-2:2012, network security guidelines, design and implementation, asset identification, defence in depth, network zones, logging and monitoring, incident response, network management, security architecture.