Network Management Security Recommendation from ISO27002/27001
Below several checklist and recommendation for Network Security Management, based on ISO 27002 / 27001
1. Following the principle of segregation of duties, operational responsibility for networks should, wherever possible, be separated from computer operations. The organization should describe within its ISMS (perhaps through a minute of the forum, or the job descriptions of the individuals) how this is achieved.
2. There should be clear responsibilities and procedures for the management of remote equipment, including in remote user areas.
3. There should, if necessary (ie if a risk assessment identifies it as so), be special controls to protect data passing over wireless and public networks. These could include cryptographic techniques, controls to protect the network from access and controls to maintain the availability of computers connected to the network.
4. Close coordination of management activity should ensure consistent application, across the entire network, of the ISMS controls.








