This is true. In the current release of FOG NFS is used to transfer the images from the fog server to the target computers. This needs to be open for the target computers to be able to read the images. You can restrict mounting the nfs share to a specific subnet, but that is it as of now.
While this version is still a years off, FOG 2.0 will have security built in from the start. But that isn’t here today.