top of page

27033 network security update

21 hours ago
2 min read

Updated: 47 minutes ago


A Preliminary Work Item within ISO/IEC JTC 1/SC 27/WG4 has produced a detailed plan for the revision of the multi-part ISO/IEC 27033 network security standard.  


The plan is a work of art given the complexities involved.  I'm impressed - and that's saying something.  [Although I'd love to share it with you, the copyright belongs to ISO/IEC, not me. Sorry.]  


Here are some of the highlights (as I understand them at the moment - this is a busy, actively-developing field and I'm just an intrerested bystander observing from a safe distance).

New netsec topics to be added include:

  • Distributed policy enforcement - a distributed network security architecture in which centrally-managed network security policies from Policy Administration Points are evaluated by Policy Decision Points and applied to network devices and services by Policy Enforcement Points throughout the network.

  • Zero trust with distributed and frequent reauthentication.

  • Cloud native security designed specifically for today's cloud environment with applications built dynamically by connnecting distributed information services, using containers and automated orchestration.

  • Edge networking security - where processing and connectivity are moved out of the data centre or cloud towards semi-autonomous distributed devices, sensors and control systems.

  • Quantum-safe network security with implications for the many cryptographic algorithms and functions involved in networking (e.g. controlling backwards-compatibility so that various quantum-unsafe bits can be properly disabled when appropriate and eventually withdrawn completely).

  • 5G and 6G - security for current and future cellular networks.



References to other relevant standards will also be updated or added e.g. ISO/IEC 27001, 27002, 27032, 27039, 27071, 19086, Wi-Fi 7, millimeter-wave and ultra-wideband etc.


There is an enormous amount of painstaking technical standards work to be done behind the scenes. Three project management approaches have been suggested for WG4 and SC27 to decide between and then plan.

 
 

​

© 2026 IsecT Limited 

 

  • Link
  • LinkedIn
bottom of page