GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

INF-005 Secure Network Architecture and Defence

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Network architecture is documented, including trust zones, data flows and perimeter boundaries. Defence-in-depth controls, including firewalls, intrusion detection or prevention systems and egress filtering, are deployed at network boundaries. Outbound web access from production systems and corporate devices is filtered against malicious and unauthorised destinations under a documented egress policy. The architecture and the egress policy are reviewed at defined intervals.

Rationale

Documented architecture supports threat modelling and audit verification. Layered network defences reduce exposure to external and internal network-based attacks.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredrole duty

Annex points 6.7.2(j), (k) and (l) require three forward-looking artefacts the control does not name: an implementation plan for the transition to latest generation network layer communication protocols, an implementation plan for the deployment of modern e-mail communications standards, and best practice for DNS security and for Internet routing security and routing hygiene. Recital 32 of the Regulation records that the standards themselves are not yet settled, so the duty is to hold a plan rather than to have arrived.

Framework Mappings (23)

I&S-03Network Securityfull
I&S-08Network Architecture Documentationfull
I&S-09Network Defensefull
I&S-03Network Securityfull
I&S-08Network Architecture Documentationfull
I&S-09Network Defensefull
8.20Networks securityfull
8.21Security of network servicesfull
8.23Web filteringfull
NIS2-CIR-6.7Network Securitypartial
NIS2-CIR-6.8Network Segmentationinformative
AC-4Information Flow Enforcementpartial
CA-3Information Exchangepartial
CA-9Internal System Connectionspartial
PL-8Security and Privacy Architecturesinformative
SC-35External Malicious Code Identificationpartial
SC-5Denial-of-service Protectionfull
SC-7Boundary Protectionpartial
SC-7(3)Boundary Protection | Access Pointspartial
SC-7(4)Boundary Protection | External Telecommunications Servicespartial
SC-7(5)Boundary Protection | Deny by Default — Allow by Exceptionpartial
SC-7(8)Boundary Protection | Route Traffic to Authenticated Proxy Serverspartial
SI-4(1)System Monitoring | System-wide Intrusion Detection Systeminformative

Evidence (4)

configurationtechnicalautomated

Firewall, IDS/IPS, and egress filtering configuration deployed at network boundaries, evidencing defence-in-depth controls.

Example: AWS WAF rule group export, GCP Cloud Armor policy, or equivalent firewall and IDS/IPS configuration showing boundary control rules for production network perimeters

Test: Export boundary control configurations (WAF, firewall, IDS/IPS). Verify: (1) ingress traffic is restricted to defined permitted ports and sources; (2) egress filtering is configured to restrict outbound traffic to known destinations or service endpoints; (3) IDS or IPS rules are current and enabled; (4) rules are reviewed on the documented schedule.

policydocumentmanual

Network architecture document including trust zone definitions, data flow diagrams, and documented review schedule.

Example: Network Architecture Design or Security Architecture document with current data flow diagrams, showing perimeter boundaries, trust zones, and last review date

Test: Request the network architecture document and the last scheduled review record. Verify: (1) trust zones and data flows are documented; (2) the document reflects the current production architecture; (3) a review was completed within the defined interval (typically annually); (4) the document is approved by a named owner.

configurationtechnicalautomated

Web filtering policy configuration showing categories of restricted destinations applied to outbound web traffic from production systems and corporate devices.

Example: Zscaler, Cisco Umbrella, Palo Alto DNS security, or equivalent web filtering policy export showing blocked categories, custom blocklist entries, and enforcement scope

Test: Export the web filtering policy configuration. Verify: (1) web filtering is enforced for outbound traffic from all in-scope devices and production systems; (2) malicious and prohibited destination categories are blocked; (3) the policy was reviewed within the defined interval; (4) test a request to a known malicious domain indicator from an in-scope device, confirming it is blocked.

policydocumentmanual

Egress filtering policy document defining approved egress destinations, blocked categories, and the review cycle for egress rules.

Example: Web Filtering and Egress Control Policy (version-controlled, approved within last 12 months) with defined egress rules and a documented review schedule

Test: Request the egress filtering policy. Verify: (1) permitted and prohibited outbound destinations or categories are defined; (2) the policy explicitly addresses production system egress and corporate device egress; (3) a review schedule is documented and the last review was completed within the required interval.

Questions (3)

boolean

Is your production network architecture documented?

Documentation should include current data flow diagrams and a network diagram showing trust zones. Defence controls should include at minimum a firewall or WAF and egress filtering.

multi

Which network defence controls are deployed at production network boundaries?

Web Application Firewall (WAF)Cloud-native firewall or security group policyIntrusion Detection System (IDS)Intrusion Prevention System (IPS)DDoS protection service (e.g. AWS Shield, Cloudflare)Egress filtering / DNS-based outbound filteringNone of the above

A WAF and egress filtering are baseline expectations at an internet-facing boundary. IDS/IPS and DDoS protection indicate a more mature defence-in-depth posture.

boolean

Is outbound web access from production systems and corporate devices filtered to restrict access to malicious or unauthorised external destinations?

Web filtering should block known malicious categories and command-and-control infrastructure. Egress filtering policies should be documented and applied to both production and corporate traffic.