Expert Advice Community

Guest

Internet Access

  Quote
Guest
Guest user Created:   May 27, 2020 Last commented:   May 27, 2020

Internet Access

With reference to the document ‘A.8.2_IT_Security_Policy_Premium_EN’ under ‘3.13 Internet Use’

Is it mandatory to define access to the Internet, only through organization and not direct access?

If yes, how do we restrict/ define actions for email services, cloud platforms which in general are accessible from the direct network?
If no, what set of restrictions are defined to comply with the requirements of ISO 27001?
 
Please let me know if more clarification required.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 27, 2020

Although ISO 27001 does not prescribe access to the Internet only through the organization as mandatory, what happens in real life is that this is more a common sense for business practice, as survival and competitive question than a standard's requirement (most of the businesses and their relations go through the Internet).

Considering that, when organizations resources, like email services, are available through direct access to the Internet (e.g., to allow remote work), a common practice is the usage of access through Virtual Private Networks (VPNs), where the organizations implement controls such as protected communication, and access control to limit external access to authorized users, only to needed information, and also can monitor activities and information flow.

A third important point is awareness activities, so employees can understand the importance to access the Internet only through the organization, and the consequences on direct access.

This article will provide you a further explanation about network controls:

This material will provide you further information about employee awareness:

Quote
0 1

Comment as guest or Sign in

HTML tags are not allowed

May 27, 2020

May 27, 2020