
A firewall review evaluates and assesses your company’s network security capabilities as aligned with your organization’s business needs and risk tolerance to mitigate cyberattack risk.
Modern digitally transformed businesses often incorporate multiple firewall vendors with different naming conventions, making maintaining a consistent cybersecurity posture challenging.
With new data protection requirements every year, you should incorporate firewall reviews as part of your network security monitoring initiatives.
Identify Audit Plan Objectives and Scope
Every audit begins by identifying the purpose and objectives. For example, you may engage in audits for the following reasons:
- Document compliance: Compliance with security standards and industry standards, like PCI DSS, HIPAA, NIST, ECB, GDPR, SOX, or NERC CIP
- Reduce attack surface: Decommission unused, shadowed, or outdated rules
- Optimize performance: improve network speed by simplifying rules or deleting unnecessary rules
- Locations
- Connectivity
- Roles
- Manufacturers
- Security policies: Internal controls detailing best practices
- Firewall logs: Technical documentation showing protocols, IP addresses, and subnets
- Risk assessments: Risk identification, review, and remediation activities
- Rulesets: Firewall configurations
- Audit reports: Documents identifying previous audit outcomes or findings
- Allow specific traffic
- Block by default
- Source IP address
- Destination IP address
- Destination port
- Protocol, like TCP, ICMP, or UDP
- Limiting source and destination traffic as much as possible
- Explicitly defining the destination IP address or groups rather than using “any”
- Not allowing traffic from “any” source to “any” destination
- Not allowing all traffic to a destination or group of destination
- Limiting the number of open globally only ports, those defining the source as “any”
- User roles and permissions remain consistent across firewall vendors
- Policies remain consistent when user and network asset IP address changes
- User access was terminated appropriately
- All user access to critical network resources is justified
- Only current admins have access to the firewall console
- Risks associated with policy changes
- Effect policy changes have on the network
- Remediation and mitigation strategy
- Reasons and objectives for changing rulesets
- Audit trail detailing the who, why, and when for any modifications
- Scanning regularly for vulnerabilities
- Prioritizing remediation for high-risk vulnerabilities
- Ensuring that all updates are applied in compliance with your organizational vulnerability management policies
- Permitted, blocked, or dropped connections
- Activity from intrusion detection systems (IDS)/intrusion prevention systems (IPS)
- User activity
- Protocol usage
- Cut-through-proxy activity
- Anomalous traffic patterns indicating a potential security incident
- Inbound and outbound traffic analysis for rule effectiveness and efficiency
- Updates to blocklists and allowlists that can improve network security
- Impact to security policy conformance
- Source and destination vulnerabilities when changing access controls
- Business continuity risks
- “What-if” path analysis for path options that might impact risk
- Impact to attack surface and exposure
- Consistency with change management processes

















