{"id":11891,"date":"2017-08-28T16:54:42","date_gmt":"2017-08-28T16:54:42","guid":{"rendered":"https:\/\/www.process.st\/templates\/firewall-audit-checklist\/"},"modified":"2024-02-28T20:45:50","modified_gmt":"2024-02-28T20:45:50","slug":"firewall-audit-checklist","status":"publish","type":"post","link":"https:\/\/www.process.st\/templates\/firewall-audit-checklist\/","title":{"rendered":"Firewall Audit Checklist"},"content":{"rendered":"<section id=\"introduction-to-firewall-audit-checklist\">\n<h2>Introduction to Firewall Audit Checklist:<\/h2>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/tsV-E4HkNpj07jV_ODtBMA.png\" alt=\"Firewall Audit Checklist - Process Street\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/tsV-E4HkNpj07jV_ODtBMA.png\"> <\/a><figcaption>\n     Firewall Audit Checklist - Process Street<br \/>\n   <\/figcaption><\/figure>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>This <a href=\"https:\/\/www.process.st\" rel=\"nofollow noopener\" target=\"_blank\">Process Street<\/a> firewall audit checklist is engineered to provide a <strong>step by step walkthrough of how to check your firewall is as secure as it can be<\/strong>.<\/p>\n<p>We recommend utilizing this firewall audit checklist along with the other <a href=\"https:\/\/www.process.st\/it-security-processes\" rel=\"nofollow noopener\" target=\"_blank\">IT security processes<\/a> as part of a continuous security review within your organization, provided you are able to do so with the resources you have.<\/p>\n<p>This checklist <strong>searches for vulnerabilities in your security defenses<\/strong> and also serves as a maintenance tool to habitually clear away clutter and update your restrictions and permissions for relevancy.<\/p>\n<p>This template is entirely editable and allows you to add and remove tasks while also editing the content inside them. This means <strong>you can tweak this checklist to fit the exact needs of your organization<\/strong>.<\/p>\n<p>Throughout the template, you will see form fields where data can be entered. Any information inputted into the form fields is then stored in the <a href=\"https:\/\/www.process.st\/help\/docs\/template-overview\/\" rel=\"nofollow noopener\" target=\"_blank\">template overview tab<\/a> for further reference, which you can also download as a CSV file if you want to store your own logs.<\/p>\n<p>If you want more information on firewalls, <strong>watch the video below<\/strong>:<\/p>\n<\/p><\/div>\n<div class=\"video-content\">\n<div class=\"iframe-container\">\n   <iframe src=\"https:\/\/www.youtube.com\/embed\/KJw9EC6ZZuI?modestbranding=1&amp;showinfo=0\" frameborder=\"0\" allowfullscreen=\"true\"> <\/iframe>\n  <\/div>\n<div class=\"description\">\n    Firewall Rules - CompTIA Security+ SY0-401: 1.2 - Professor Messer\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"record-checklist-details\">\n<h2>Record checklist details<\/h2>\n<div class=\"text-content\">\n<p>Record the details of the checklist in <strong>the form fields below<\/strong>.<\/p>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Name of person delivering the audit <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Details of the system to be audited <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Person who requested the audit <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<div class=\"date-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Date the audit begins <\/label> <\/p>\n<div class=\"date-container\">\n    <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-calendar btn-icon\"><\/i> Date will be set here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"text-content\">\n<h4 style=\"text-align: center;\">Audit approver details<\/h4>\n<\/p><\/div>\n<div class=\"text-content\">\n<p>Certain tasks in this Firewall Audit Checklist will require approval from the relevant personnel in your team, You can fill in the details of the relevant audit approver below.<\/p>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Audit approver name <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"preaudit-information-gathering\">\n<h2>Pre-Audit Information Gathering:<\/h2>\n<\/section>\n<section id=\"make-sure-you-have-copies-of-security-policies\">\n<h2>Make sure you have copies of security policies<\/h2>\n<div class=\"text-content\">\n<p>Locate copies of all security policies and procedure documents for review.&nbsp;<\/p>\n<p>Upload or link to them in <strong>the form fields below<\/strong>.<\/p>\n<\/p><\/div>\n<div class=\"file-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Security policies upload <\/label> <\/p>\n<div class=\"file-container\">\n    <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"check-you-have-access-to-all-firewall-logs\">\n<h2>Check you have access to all firewall logs<\/h2>\n<div class=\"text-content\">\n<p>Make sure you have access to all relevant logs.&nbsp;<\/p>\n<p><strong>Record in the form field below<\/strong> the person who gave you access, if applicable.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"text-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Granted access by: <\/label><br \/>\n   <input type=\"text\" placeholder=\"Something will be typed here...\" disabled class=\"form-control\">\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"gain-a-diagram-of-the-current-network\">\n<h2>Gain a diagram of the current network<\/h2>\n<div class=\"text-content\">\n<p>A network diagram is a useful tool to provide a <strong>simple visual overview of the network's structure<\/strong>.&nbsp;<\/p>\n<p>This can help you make sure you have investigated all relevant areas.&nbsp;<\/p>\n<p><strong>See the image below<\/strong> for tips on what to gather.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"image-content\">\n<figure>\n   <a href=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/oeTqa8wGJbKAu-CEm19JxQ.png\" alt=\"Firewall Audit Network Diagrams\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/www.process.st\/templates\/wp-content\/uploads\/2024\/02\/oeTqa8wGJbKAu-CEm19JxQ.png\"> <\/a><figcaption>\n     Firewall Audit Network Diagrams<br \/>\n   <\/figcaption><\/figure>\n<\/p><\/div>\n<\/section>\n<section id=\"review-documentation-from-previous-audits\">\n<h2>Review documentation from previous audits<\/h2>\n<div class=\"text-content\">\n<p><strong>Gather and review any reports from previous audits<\/strong>.&nbsp;<\/p>\n<p>This should help you understand how the firewall has evolved over time while revealing previous areas of weakness which you can pay extra attention to.&nbsp;<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"identify-all-relevant-isps-and-vpns\">\n<h2>Identify all relevant ISPs and VPNs<\/h2>\n<div class=\"text-content\">\n<p><strong>Use the form fields below<\/strong> to provide notes on relevant ISPs and VPNs.<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> ISPs <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> VPNs <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"obtain-all-firewall-vendor-information\">\n<h2>Obtain all firewall vendor information<\/h2>\n<div class=\"text-content\">\n<p>Gather as much information as you can about the vendor and the product.<\/p>\n<p><strong>Upload this information<\/strong> in the form field below.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"file-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Firewall vendor information <\/label> <\/p>\n<div class=\"file-container\">\n    <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"understand-the-setup-of-all-key-servers\">\n<h2>Understand the setup of all key servers<\/h2>\n<div class=\"text-content\">\n<p>Review the setup of key servers and<strong> record any notes in the form field provided<\/strong>.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Setup of key servers <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"review-the-change-management-process\">\n<h2>Review the Change Management Process:<\/h2>\n<\/section>\n<section id=\"review-the-procedures-for-rulebase-maintenance\">\n<h2>Review the procedures for rule-base maintenance<\/h2>\n<div class=\"text-content\">\n<p>Maintaining effective firewall systems is as much about procedural setup as it is about software or hardware. &nbsp;<\/p>\n<p><strong>Request, assess, and analyze the existing procedures<\/strong>&nbsp;for&nbsp;maintaining the rule-base. &nbsp;<\/p>\n<p>Leave any notes below.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Rule base procedures notes <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"analyze-the-process-for-firewall-changes\">\n<h2>Analyze the process for firewall changes<\/h2>\n<div class=\"text-content\">\n<p>Analyze the overall process for changes to the firewall.&nbsp;<\/p>\n<ul>\n<li>Does authorization have to be given every time?<\/li>\n<li>If so, who are the involved&nbsp;participants?<\/li>\n<li>What is the workflow like?<\/li>\n<\/ul>\n<p><strong>Leave any notes on this process in the field below.<\/strong><\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Change management process notes <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"determine-whether-all-previous-changes-were-authorized\">\n<h2>Determine whether all previous changes were authorized<\/h2>\n<div class=\"text-content\">\n<p>With this new knowledge of the existing procedures, processes, and workflows, gain access to firewall change logs.&nbsp;<\/p>\n<p>You should <strong>review the previous changes to the firewall<\/strong> to assess whether or not the procedures and processes were appropriately followed.&nbsp;<\/p>\n<p>There is little point in having strong processes in place if they are not being followed by the staff involved.&nbsp;<\/p>\n<p><strong>Use the form field below<\/strong> to record your notes.<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Process adherence notes <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"audit-the-firewalls-physical-and-os-security\">\n<h2>Audit the Firewall's Physical and OS Security:<\/h2>\n<\/section>\n<section id=\"make-sure-your-management-servers-are-physically-secure\">\n<h2>Make sure your management servers are physically secure<\/h2>\n<div class=\"text-content\">\n<p>Access to your systems is not only digital. Your physical security could be compromised also.<\/p>\n<p><strong>Review the security of the servers<\/strong> to make sure they cannot be tampered with without authorization. &nbsp;<\/p>\n<p>Leave any notes below.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Server physical security notes <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"check-the-access-procedures-to-these-restricted-locations\">\n<h2>Check the access procedures to these restricted locations<\/h2>\n<div class=\"text-content\">\n<p>These secure locations still require access. What are the procedures for gaining access to the restricted locations?<\/p>\n<p><strong>Request, review, and analyze the access procedures<\/strong> and authorization processes for restricted areas.&nbsp;<\/p>\n<p>Provide notes below.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Access procedures notes <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"verify-all-vendor-updates-have-been-applied\">\n<h2>Verify all vendor updates have been applied<\/h2>\n<div class=\"text-content\">\n<p>Review the vendor information you gathered previously in the process and analyze that against the recorded updates for the firewall.&nbsp;<\/p>\n<p><strong>Make sure that all updates and patches have been applied.&nbsp;<\/strong><\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"make-sure-the-os-passes-common-hardening-checks\">\n<h2>Make sure the OS passes common hardening checks<\/h2>\n<div class=\"text-content\">\n<p>Your OS will need regular review to make sure it is as secure as it can be.&nbsp;<\/p>\n<p>For an in-depth assessment of hardening read: <a href=\"http:\/\/www.professormesser.com\/security-plus\/sy0-401\/operating-system-hardening-2\/\" rel=\"nofollow noopener\" target=\"_blank\">Operating System Hardening \u2013 CompTIA Security+ SY0-401: 3.6<\/a>&nbsp;<\/p>\n<p>Or, <strong>watch the video below<\/strong>.<\/p>\n<\/p><\/div>\n<div class=\"video-content\">\n<div class=\"iframe-container\">\n   <iframe src=\"https:\/\/www.youtube.com\/embed\/YSwTfealIV4?modestbranding=1&amp;showinfo=0\" frameborder=\"0\" allowfullscreen=\"true\"> <\/iframe>\n  <\/div>\n<div class=\"description\">\n    Operating System Hardening - CompTIA Security+ SY0-401: 3.6 - Professor Messer\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"assess-the-procedures-for-device-administration\">\n<h2>Assess the procedures for device administration<\/h2>\n<div class=\"text-content\">\n<p>How we deal with extra devices on the network should be standardized in clear and actionable procedures.&nbsp;<\/p>\n<p>Without this, we risk creating a loophole in our security by having an unsecured device on the network.&nbsp;<\/p>\n<p>For more information device administration read: <a href=\"http:\/\/www.comptechdoc.org\/man\/Business_guide\/it-business-structure\/Job-functions\/firewall-router-administrator.html\" rel=\"nofollow noopener\" target=\"_blank\">Policies Affecting Network Device Administrators<\/a><\/p>\n<p><strong>Request, review, and analyze the existing procedures<\/strong> for device administration.<\/p>\n<p>Leave any notes in <strong>the form field below<\/strong>.<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Device administration notes <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"optimize-your-rule-base\">\n<h2>Optimize Your Rule Base:<\/h2>\n<\/section>\n<section id=\"delete-redundant-rules\">\n<h2>Delete redundant rules<\/h2>\n<div class=\"text-content\">\n<p>Clutter within a firewall's rule-base&nbsp;should be removed like clutter of any other kind.&nbsp;<\/p>\n<p>If there are rules which are deemed redundant, <strong>simply delete them<\/strong>.&nbsp;<\/p>\n<p>Record deleted rules below.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Deleted rules <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"delete-or-disable-unused-objects\">\n<h2>Delete or disable unused objects<\/h2>\n<div class=\"text-content\">\n<p>Again, this is part of a process of de-cluttering.&nbsp;<\/p>\n<p>If there are unused objects present, disable or delete them as appropriate.&nbsp;<\/p>\n<p><strong>Record your activity below<\/strong>.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Disabled objects <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Deleted objects <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"evaluate-the-order-of-firewall-rules-for-performance\">\n<h2>Evaluate the order of firewall rules for performance<\/h2>\n<div class=\"text-content\">\n<p>Assess the order of your rules to maximize the performance of your system.<\/p>\n<p>Leave any notes on changes in <strong>the form field below<\/strong>.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Firewall rules order notes <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"remove-unused-connections\">\n<h2>Remove unused connections<\/h2>\n<div class=\"text-content\">\n<p>If a connection is not in use it can be removed.&nbsp;<\/p>\n<p><strong>Record your activity below<\/strong>.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"textarea-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Unused connections <\/label><br \/>\n   <textarea placeholder=\"Something will be typed here...\" rows=\"3\" disabled class=\"form-control\"><\/textarea>\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"document-the-rules-and-changes-for-future-reference\">\n<h2>Document the rules and changes for future reference<\/h2>\n<div class=\"text-content\">\n<p>Make sure you have documented these changes appropriately.&nbsp;<\/p>\n<p>If you included all changes in the form fields in the previous tasks, then you will be able to export that data as a CSV file for easy future review. <strong>Proper use of Process Street will make sure your work is always documented<\/strong>.&nbsp;<\/p>\n<p>Otherwise, take this opportunity to make sure the changes were documented.&nbsp;<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"conduct-a-risk-assessment\">\n<h2>Conduct a Risk Assessment:<\/h2>\n<\/section>\n<section id=\"review-industry-best-practices-for-methodology\">\n<h2>Review industry best practices for methodology<\/h2>\n<div class=\"text-content\">\n<p>As part of a risk assessment, it is important to review industry guidelines to understand best practices and to better assess what constitutes&nbsp;<em>risk<\/em> in this scenario.&nbsp;<\/p>\n<p><strong>Important industry documentation<\/strong> to review might include:<\/p>\n<ul>\n<li>PCI-DSS,<\/li>\n<li>SOX,<\/li>\n<li>ISO 27001,<\/li>\n<li>NERC CIP,<\/li>\n<li>Basel-II,<\/li>\n<li>FISMA<\/li>\n<li>and J-SOX<\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"ask-a-series-of-thorough-questions\">\n<h2>Ask a series of thorough questions<\/h2>\n<div class=\"text-content\">\n<p><strong>Sam Erdheim of AlgoSec<\/strong> provides us with a series of potential questions to pose when we're considering risk within the context of our firewall:<\/p>\n<ul>\n<li>Are there firewall rules that violate your corporate security policy?<\/li>\n<li>Are there any firewall rules with \u201cANY\u201d in the source, destination, service\/protocol, application or user fields, and with a permissive action?<\/li>\n<li>Are there rules that allow risky services from your DMZ to your internal network?<\/li>\n<li>Are there rules that allow risky services inbound from the Internet?<\/li>\n<li>Are there rules that allow risky services outbound to the Internet?<\/li>\n<li>Are there rules that allow direct traffic from the Internet to the internal network (not the DMZ)?<\/li>\n<li>Are there any rules that allow traffic from the Internet to sensitive servers, networks, devices or databases?<\/li>\n<\/ul>\n<p><strong>Consider questions like these and more<\/strong> in order to thoroughly analyze your risk exposure.&nbsp;<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"document-your-assessment-and-save-as-a-report\">\n<h2>Document your assessment and save as a report<\/h2>\n<div class=\"text-content\">\n<p><strong>Use one of the form fields below<\/strong> to upload or link to your risk assessment report.<\/p>\n<\/p><\/div>\n<div class=\"file-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Risk assessment upload <\/label> <\/p>\n<div class=\"file-container\">\n    <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"improve-firewall-processes\">\n<h2>Improve Firewall Processes:<\/h2>\n<\/section>\n<section id=\"replace-errorprone-manual-tasks-with-automations\">\n<h2>Replace error-prone manual tasks with automations<\/h2>\n<div class=\"text-content\">\n<p>Where possible, it is advantageous to replace manual tasks with automated solutions.&nbsp;<\/p>\n<p><strong>This saves time and reduces errors<\/strong>, allowing the relevant member of staff to act as a reviewer - a second line of security.&nbsp;<\/p>\n<p>The level of reporting available from automated tasks will also make future audits easier.&nbsp;<\/p>\n<p><strong>Check out this article<\/strong> from CSO about picking your firewall tech: <a href=\"http:\/\/www.csoonline.com\/article\/2125166\/network-security\/firewall-audit-dos-and-don-ts.html\" rel=\"nofollow noopener\" target=\"_blank\">Firewall Audits Dos and Don'ts<\/a><\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"make-sure-all-auditing-activities-have-been-documented\">\n<h2>Make sure all auditing activities have been documented<\/h2>\n<div class=\"text-content\">\n<p>If you have utilized this checklist properly, then <strong>your auditing activities should be thoroughly documented<\/strong>.&nbsp;<\/p>\n<p>If you haven't been filling in your form fields, now is the time to make sure you document your actions and store that information in one accessible place.&nbsp;<\/p>\n<\/p><\/div>\n<\/section>\n<section id=\"create-an-actionable-firewall-change-workflow\">\n<h2>Create an actionable firewall change workflow<\/h2>\n<div class=\"text-content\">\n<p>You need to make sure that the results of this audit are actionable.&nbsp;<\/p>\n<p>Create a firewall change workflow to make maximum use of this audit.&nbsp;<\/p>\n<p><a href=\"https:\/\/www.process.st\/change-management-models\/\" rel=\"nofollow noopener\" target=\"_blank\">Change management<\/a> is vitally important within this process. <strong>Upload your report<\/strong> with your firewall change workflow in the form field provided. This report will be reviewed for approval by the relevant personnel. Completion of this checklist is not possible until your report has been approved.<\/p>\n<p>If you need further information about firewall change workflows, <strong>watch the video below<\/strong>.&nbsp;<\/p>\n<\/p><\/div>\n<div class=\"file-field-content form-field-content\">\n<div class=\"form-group\">\n   <label> Report + Firewall change workflow <\/label> <\/p>\n<div class=\"file-container\">\n    <button type=\"button\" disabled class=\"btn btn-default\"> <i class=\"fa fa-upload btn-icon\"><\/i> File will be uploaded here <\/button>\n   <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"video-content\">\n<div class=\"iframe-container\">\n   <iframe src=\"https:\/\/www.youtube.com\/embed\/37772q-lWeE?modestbranding=1&amp;showinfo=0\" frameborder=\"0\" allowfullscreen=\"true\"> <\/iframe>\n  <\/div>\n<div class=\"description\">\n    Firewall Workflow to Make the Right Change the First Time - FireMon\n  <\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"approval\">\n<h2>Approval: <\/h2>\n<div class=\"approval-content\">\n<div class=\"header\">\n<div class=\"list-title\">\n    Will be submitted for approval:\n   <\/div>\n<\/p><\/div>\n<div class=\"approval-rule-subject-tasks-list\">\n<ul class=\"list\">\n<li>\n<div class=\"approval-rule-subject-tasks-list-item\">\n<div class=\"item\">\n<div class=\"container\">\n        <span class=\"title\">Create an actionable firewall change workflow<\/span> <\/p>\n<div class=\"body\">\n         Will be submitted\n        <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/section>\n<section id=\"sources\">\n<h2>Sources:<\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"http:\/\/www.crn.com\/blogs-op-ed\/231903353\/how-to-conduct-a-firewall-audit.htm\" rel=\"nofollow noopener\" target=\"_blank\">How to Conduct a Firewall Audit - CRN<\/a><\/li>\n<li><a href=\"https:\/\/www.sans.org\/media\/score\/checklists\/FirewallChecklist.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Firewall Checklist - SANS Institute<\/a><\/li>\n<li><a href=\"https:\/\/www.algosec.com\/wp-content\/uploads\/2016\/03\/Firewall-Audit-Checklist-WEB.pdf\" rel=\"nofollow noopener\" target=\"_blank\">Firewall Audit Checklist - AlgoSec<\/a><\/li>\n<li><a href=\"http:\/\/www.thedatachain.com\/articles\/2013\/2\/mastering_your_next_audit_with_the_firewall_audit_checklist\" rel=\"nofollow noopener\" target=\"_blank\">Mastering Your Next Audit With the Firewall Audit Checklist - The Data Chain<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n<section id=\"related-checklists\">\n<h2>Related Checklists:<\/h2>\n<div class=\"text-content\">\n<ul>\n<li><a href=\"https:\/\/www.process.st\/templates\/privileged-password-management\/\" rel=\"nofollow\">Privileged Password Management<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/network-administrator-daily-tasks\/\" rel=\"nofollow\">Network Administrator Daily Tasks<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/network-security-audit-checklist\/\" rel=\"nofollow\">Network Security Audit Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/firewall-audit-checklist\/\" rel=\"nofollow\">Firewall Audit Checklist<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/vpn-configuration\/\" rel=\"nofollow\">VPN Configuration<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/setup-apache-server\/\" rel=\"nofollow\">Apache Server Setup<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/email-server-security\/\" rel=\"nofollow\">Email Server Security<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/penetration-testing\/\" rel=\"nofollow\">Penetration Testing<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/inventory-management-process\/\" rel=\"nofollow noopener\" target=\"_blank\">Inventory Management Process<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/network-security-management\/\" rel=\"nofollow noopener\" target=\"_blank\">Network Security Management<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/client-data-backup-best-practices\/\" rel=\"nofollow noopener\" target=\"_blank\">Client Data Backup Best Practices<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/computer-maintenance-guide\/\" rel=\"nofollow noopener\" target=\"_blank\">Computer Maintenance Guide<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/ubuntu-server-setup-process\/\" rel=\"nofollow noopener\" target=\"_blank\">Server Setup Process<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/virtual-private-server-setup\/\" rel=\"nofollow noopener\" target=\"_blank\">Virtual Private Server Setup<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/it-support-process\/\" rel=\"nofollow noopener\" target=\"_blank\">IT Support Process<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/helpdesk-management\/\" rel=\"nofollow noopener\" target=\"_blank\">Helpdesk Management<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/server-maintenance-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Server Maintenance<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/server-security-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">Server Security<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/information-security-incident-response\/\" rel=\"nofollow noopener\" target=\"_blank\">Information Security Incident Response<\/a><\/li>\n<li><a href=\"https:\/\/www.process.st\/templates\/sql-server-audit-checklist\/\" rel=\"nofollow noopener\" target=\"_blank\">SQL Server Audit Checklist<\/a><\/li>\n<\/ul><\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Introduction to Firewall Audit Checklist: Firewall Audit Checklist - Process Street This Process Street firewall audit checklist is engineered to provide a step by step walkthrough of how to check your firewall is as secure as it can be. We recommend utilizing this firewall audit checklist along with the other IT security processes as part [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":11892,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"ep_exclude_from_search":false,"cover_icon_emoji":"","cover_icon_url":"","tasks_count":"37","template_description":"Run this firewall audit checklist when you begin the review of a firewall with the intention of optimizing its security and performance.","template_id":"jr94KvVlFHvpx8ml2gZJFw","task_0":"Introduction to Firewall Audit Checklist:","task_slug_0":"introduction-to-firewall-audit-checklist","task_1":"Record checklist details","task_slug_1":"record-checklist-details","task_2":"Pre-Audit Information Gathering:","task_slug_2":"preaudit-information-gathering","task_3":"Make sure you have copies of security policies","task_slug_3":"make-sure-you-have-copies-of-security-policies","task_4":"Check you have access to all firewall logs","task_slug_4":"check-you-have-access-to-all-firewall-logs","task_5":"Gain a diagram of the current network","task_slug_5":"gain-a-diagram-of-the-current-network","task_6":"Review documentation from previous audits","task_slug_6":"review-documentation-from-previous-audits","task_7":"Identify all relevant ISPs and VPNs","task_slug_7":"identify-all-relevant-isps-and-vpns","task_8":"Obtain all firewall vendor information","task_slug_8":"obtain-all-firewall-vendor-information","task_9":"Understand the setup of all key servers","task_slug_9":"understand-the-setup-of-all-key-servers","task_10":"Review the Change Management Process:","task_slug_10":"review-the-change-management-process","task_11":"Review the procedures for rule-base maintenance","task_slug_11":"review-the-procedures-for-rulebase-maintenance","task_12":"Analyze the process for firewall changes","task_slug_12":"analyze-the-process-for-firewall-changes","task_13":"Determine whether all previous changes were authorized","task_slug_13":"determine-whether-all-previous-changes-were-authorized","task_14":"Audit the Firewall's Physical and OS Security:","task_slug_14":"audit-the-firewalls-physical-and-os-security","task_15":"Make sure your management servers are physically secure","task_slug_15":"make-sure-your-management-servers-are-physically-secure","task_16":"Check the access procedures to these restricted locations","task_slug_16":"check-the-access-procedures-to-these-restricted-locations","task_17":"Verify all vendor updates have been applied","task_slug_17":"verify-all-vendor-updates-have-been-applied","task_18":"Make sure the OS passes common hardening checks","task_slug_18":"make-sure-the-os-passes-common-hardening-checks","task_19":"Assess the procedures for device administration","task_slug_19":"assess-the-procedures-for-device-administration","task_20":"Optimize Your Rule Base:","task_slug_20":"optimize-your-rule-base","task_21":"Delete redundant rules","task_slug_21":"delete-redundant-rules","task_22":"Delete or disable unused objects","task_slug_22":"delete-or-disable-unused-objects","task_23":"Evaluate the order of firewall rules for performance","task_slug_23":"evaluate-the-order-of-firewall-rules-for-performance","task_24":"Remove unused connections","task_slug_24":"remove-unused-connections","task_25":"Document the rules and changes for future reference","task_slug_25":"document-the-rules-and-changes-for-future-reference","task_26":"Conduct a Risk Assessment:","task_slug_26":"conduct-a-risk-assessment","task_27":"Review industry best practices for methodology","task_slug_27":"review-industry-best-practices-for-methodology","task_28":"Ask a series of thorough questions","task_slug_28":"ask-a-series-of-thorough-questions","task_29":"Document your assessment and save as a report","task_slug_29":"document-your-assessment-and-save-as-a-report","task_30":"Improve Firewall Processes:","task_slug_30":"improve-firewall-processes","task_31":"Replace error-prone manual tasks with automations","task_slug_31":"replace-errorprone-manual-tasks-with-automations","task_32":"Make sure all auditing activities have been documented","task_slug_32":"make-sure-all-auditing-activities-have-been-documented","task_33":"Create an actionable firewall change workflow","task_slug_33":"create-an-actionable-firewall-change-workflow","task_34":"Approval:","task_slug_34":"approval","task_35":"Sources:","task_slug_35":"sources","task_36":"Related Checklists:","task_slug_36":"related-checklists","task_37":"","task_slug_37":"","task_38":"","task_slug_38":"","task_39":"","task_slug_39":"","task_40":"","task_slug_40":"","task_41":"","task_slug_41":"","task_42":"","task_slug_42":"","task_43":"","task_slug_43":"","task_44":"","task_slug_44":"","task_45":"","task_slug_45":"","task_46":"","task_slug_46":"","task_47":"","task_slug_47":"","task_48":"","task_slug_48":"","task_49":"","task_slug_49":"","task_50":"","task_slug_50":"","task_51":"","task_slug_51":"","task_52":"","task_slug_52":"","task_53":"","task_slug_53":"","task_54":"","task_slug_54":"","task_55":"","task_slug_55":"","task_56":"","task_slug_56":"","task_57":"","task_slug_57":"","task_58":"","task_slug_58":"","task_59":"","task_slug_59":"","task_60":"","task_slug_60":"","task_61":"","task_slug_61":"","task_62":"","task_slug_62":"","task_63":"","task_slug_63":"","task_64":"","task_slug_64":"","task_65":"","task_slug_65":"","task_66":"","task_slug_66":"","task_67":"","task_slug_67":"","task_68":"","task_slug_68":"","task_69":"","task_slug_69":"","task_70":"","task_slug_70":"","task_71":"","task_slug_71":"","task_72":"","task_slug_72":"","task_73":"","task_slug_73":"","task_74":"","task_slug_74":"","task_75":"","task_slug_75":"","task_76":"","task_slug_76":"","task_77":"","task_slug_77":"","task_78":"","task_slug_78":"","task_79":"","task_slug_79":"","task_80":"","task_slug_80":"","task_81":"","task_slug_81":"","task_82":"","task_slug_82":"","task_83":"","task_slug_83":"","task_84":"","task_slug_84":"","task_85":"","task_slug_85":"","task_86":"","task_slug_86":"","task_87":"","task_slug_87":"","task_88":"","task_slug_88":"","task_89":"","task_slug_89":"","task_90":"","task_slug_90":"","task_91":"","task_slug_91":"","task_92":"","task_slug_92":"","task_93":"","task_slug_93":"","task_94":"","task_slug_94":"","task_95":"","task_slug_95":"","task_96":"","task_slug_96":"","task_97":"","task_slug_97":"","task_98":"","task_slug_98":"","task_99":"","task_slug_99":"","footnotes":""},"categories":[42,7,1],"tags":[],"class_list":["post-11891","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-internal-audit","category-miscellaneous","category-uncategorized"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/11891","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/comments?post=11891"}],"version-history":[{"count":0,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/posts\/11891\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media\/11892"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/media?parent=11891"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/categories?post=11891"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.process.st\/templates\/wp-json\/wp\/v2\/tags?post=11891"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}