simpl.
Cybersecurity GRC 15 items

Firewall & Network Device Configuration Review

Reviews firewall and network device rulesets, hardening, and change management to ensure secure and least-privilege network configurations.

CIS v8NIST 800-41PCI DSS 4.0

Free PDF · enter your email to download.

Ruleset Hygiene

  • Do firewall rules follow deny-by-default with explicit allow rules? *
  • Are rules documented with business justification and an owner? *
  • Are overly permissive (any-any) rules identified and remediated? *
  • Are unused, expired, or shadowed rules removed during periodic reviews? *
  • How frequently are firewall rulesets reviewed?

Device Hardening

  • Are network devices configured against a documented secure baseline? *
  • Are default credentials changed and unnecessary services disabled? *
  • Is management access restricted to dedicated administrative networks? *
  • Is device firmware kept current with security updates? *

Segmentation & Perimeter

  • Is the network segmented to isolate sensitive systems from general access? *
  • Is inbound and outbound traffic filtered at trust boundaries? *
  • Is outbound (egress) traffic restricted to required destinations?

Change Management & Logging

  • Are firewall changes approved through a documented change process? *
  • Are configuration backups maintained and version-controlled? *
  • Are device and traffic logs sent to a central log repository? *

Download the full Firewall & Network Device Configuration Review checklist

Get it as a clean, printable PDF — free.