ISO/IEC 27033-2 is the second part of ISO/IEC 27033 that gives guidelines for organizations to plan, design, implement and document network security.
The network security architecture includes a description of the interfaces between an organization’s/community’s internal network and the outside world.
Guidance on general best practice design is provided in ISO/IEC 27033-2, and guidance on the network security architecture aspects related to specific networking technologies to address the requirements of today and the near future is provided in ISO/IEC 27033-4 and onward. Guidance on specific scenarios that are possible for an organization are covered in ISO/IEC 27033-3.
ISO/IEC 27033-2 on guidelines for the design and implementation of network security is useful for:
The objectives of network security are to enable the information flows that enhance an organization’s business processes, and to prevent information flows that degrade an organization’s business processes. The preparation work for the design and the implementation of network security involves the following stages:
These stages should result in the early documentation consisting of all the inputs for following design and implementation steps.
ISO/IEC 27033-2 provides guidelines for all the design and implementation of network security to enable you to ensure seamless information flow for enhancing the organization’s business processes.
ISO/IEC 27033-2:2012