What is ISO/IEC 27033-5 about?
ISO/IEC 27033-5 is the fifth part of the ISO/IEC 27033 series of standards on ICT network security. ISO/IEC 27033-5 is about strengthening the technical controls which underpin the security of Virtual Private Networks (VPNs).
Who is ISO/IEC 27033-5 for?
ISO/IEC 27033-5 on the governance of information security is useful for the organization:
- Systems architects and designers
- Network managers
- Network security officers
Why should you use ISO/IEC 27033-5?
VPNs have developed rapidly as a means of interconnecting networks and connecting remote users to networks. In their simplest form, they provide a mechanism for establishing a secure data channel over an existing network or point-to-point connection. They’re assigned to the exclusive use of a restricted user group and can be established and removed dynamically, as needed. However, organizations can expect increasingly sophisticated attacks to be mounted against their systems. Attempts at unauthorized access can be malicious, for example leading to a Denial of Service attack, the misuse of resources, or access to valuable information.
As a defence, ISO/IEC 27033-5 gives guidelines for the selection, implementation, and monitoring of the technical controls necessary to provide network security using Virtual Private Network (VPN) connections to interconnect networks and connect remote users to networks.
ISO/IEC 27033-5 guidance on how to:
- Address space and routing separation between vpns carried over the label switched network
- Provide resistance to unauthorized access attacks
- Ensure the internal structure of the label switched network core is not visible to outside networks
- Limit information available to potential attackers
- Protect against label spoofing