Network and infrastructure security is the set of controls that protects the systems carrying your data: routers, switches, firewalls, servers, virtual machines, cloud tenants and the links between them. If access rules decide who gets in, network and infrastructure security decides what the road inside looks like and how far anyone can travel on it.
Most security incidents do not begin with a clever exploit. They begin with a forgotten test server, a firewall rule nobody removed, or a flat network where one compromised laptop can reach the finance database. Good network and infrastructure security closes those easy paths before anyone finds them.
This page sets out the controls that matter, how ISO 27001 treats them, and what evidence an auditor will ask to see.
What Network and Infrastructure Security Covers
The scope is wider than most teams expect. It usually includes:
- Network devices such as routers, switches, wireless access points, firewalls and load balancers
- Servers and endpoints that store or process business information
- Virtual infrastructure: hypervisors, containers, cloud instances and storage buckets
- Connections including internet links, VPN tunnels, site to site circuits and third party integrations
- The rooms and cabinets holding this equipment, which is why physical security sits beside the technical controls rather than apart from them
You cannot protect what has never been written down. A current inventory with owners and sensitivity levels, built through asset identification and classification, is the starting point for every control that follows.
Why Network Security Matters Inside an ISMS
An information security management system works on the principle that risk is managed rather than eliminated. A large share of that risk sits in infrastructure, because infrastructure is shared. One weak component can expose many services at once.
There is a second reason. Infrastructure changes constantly: new servers, new rules, new integrations, new people with admin rights. A policy written once and filed away drifts out of date within months. Treating network and infrastructure security as a live process, with owners, review dates and records, is what keeps the management system truthful.
Core Network Security Controls

Network Segmentation
Segmentation splits the network into zones so trouble in one area does not spread across the rest. Production separated from development. User devices separated from servers. Payment and cardholder systems separated from everything else.
Segmentation is the single control that most reduces the damage of an incident. When malicious code lands on one laptop, segmentation decides whether it reaches ten machines or ten thousand.
Firewall and Perimeter Rules
Firewalls should deny by default and permit only what the business needs. The hard part is upkeep, not setup. Rules get added during projects and almost never removed afterwards.
Review the rule set at least twice a year. Record who asked for each rule, the reason, and an expiry date. Any rule without a named owner should be closed rather than kept for comfort.
Secure Configuration and Hardening
Devices arrive with default settings that favor convenience. Hardening means removing default accounts, closing unused ports, switching off outdated protocols, and applying a documented baseline to every new build so no two servers are configured by memory.
Patching belongs here too. Agree a timeline by severity, for example critical patches applied within seven days, and track approved exceptions openly instead of letting them go unrecorded.
Remote and Privileged Access
Remote work has moved the perimeter to the user. VPN or zero trust connectivity, multi factor authentication, and disciplined access control management on administrative accounts are now baseline expectations rather than advanced measures.
Privileged accounts deserve separate handling: named accounts only, no shared credentials, session logging, and a quarterly check on who still needs the rights they were given last year.
Network Monitoring and Logging
Logs from firewalls, servers and cloud platforms help only if someone reads them. Central collection, alerts tuned to events that matter, and a defined response path turn raw logs into security operations rather than expensive storage.
Set retention on purpose. Many investigations stall because the logs covering the relevant week had already been overwritten.
ISO 27001 Requirements for Network and Infrastructure Security
ISO 27001 does not name products. It asks you to select controls based on risk and then show they work. Several Annex A controls apply directly to infrastructure:
- Networks security and security of network services
- Segregation of networks
- Configuration management and secure system architecture
- Protection against malware
- Logging, monitoring activities and clock synchronisation
- Management of technical vulnerabilities
- Use of cryptography, including encryption of data in transit
An auditor will ask for the firewall rule set, the hardening baseline, the patch record, the log review evidence and the dates those reviews happened. Screenshots generated the week before the audit are usually spotted.
Cloud and Hybrid Infrastructure Security
Cloud providers secure the platform. You secure what you place on it. Misconfigured storage, over permissive identity roles and management ports left open to the internet remain among the most common causes of exposure, and none of them require a skilled attacker.
Practical steps: enable provider logging on day one, restrict administrative access by identity or IP range, review roles every quarter, and treat infrastructure as code templates as controlled documents. Your cyber security compliance obligations follow the data wherever it runs, whoever owns the hardware.
What Usually Goes Wrong
Patterns that show up again and again during implementations:

- Flat networks in fast growing companies, because segmentation was postponed during expansion and never revisited
- Firewall rule sets nobody can explain, holding entries older than the current IT team
- Test and staging environments carrying real production data under weaker controls
- Vendor remote access left permanently open after a project closed
- Monitoring switched on with no named person reviewing the alerts
None of these need advanced attackers. They need a schedule and an owner, which is why information system security belongs to the management system rather than to one engineer's memory.
Try Effivity for Free and see how network controls, review cycles and audit evidence stay in one place.
How to Build a Network Security Plan That Holds Up
- List every asset, connection and cloud service, with an owner against each entry.
- Run an information security risk assessment so control choices trace back to real exposure, not habit.
- Define network zones and the rules for traffic allowed to cross between them.
- Write hardening baselines for each device and platform type, then apply them to new builds automatically.
- Set review cycles: firewall rules twice yearly, privileged accounts quarterly, patch status monthly.
- Test the design. Vulnerability scans on a regular schedule, penetration testing at least once a year, and a documented fix path for what they find.
Measuring Network and Infrastructure Security
Useful metrics are the ones a manager can act on:
- Percentage of assets built on an approved hardening baseline
- Average time to patch critical vulnerabilities
- Number of firewall rules with no owner or no business justification
- Percentage of privileged accounts reviewed in the current period
- Time taken to detect and contain a network event during testing
Track a small set consistently. Five numbers reported every month tell a clearer story than thirty reported once.
Managing Network Security With Effivity
Effivity's information security management software holds the asset register, risk assessments, controls, review schedules, incidents and audit records in a single system. Reviews are assigned to named people with due dates, evidence is attached where the control sits, and reports for management and certification bodies come from live data rather than a rushed spreadsheet.
Get a Free Personalized Demo to see how your network controls and ISO 27001 evidence would sit inside Effivity.
Frequently Asked Questions
It is the protection of network devices, servers, cloud services and the connections carrying business data. It covers segmentation, firewalls, hardening, access, monitoring and patching.
Network security focuses on traffic and connections between systems. Infrastructure security is broader and also covers the servers, virtual platforms and facilities those networks run on.
Annex A covers network security, segregation of networks, secure configuration, malware protection, logging and technical vulnerability management. Each one needs supporting records.
Most organisations review firewall rules every six months and after any major change. Every rule should carry a named owner, a business reason and a review date.
Yes, at a basic level. Separating guest wi-fi, user devices and servers limits how far an incident can spread and needs no expensive equipment.