Cybersecurity GRC 15 items
Firewall & Network Device Configuration Review
Reviews firewall and network device rulesets, hardening, and change management to ensure secure and least-privilege network configurations.
CIS v8NIST 800-41PCI DSS 4.0
Free PDF · enter your email to download.
Ruleset Hygiene
- Do firewall rules follow deny-by-default with explicit allow rules? *
- Are rules documented with business justification and an owner? *
- Are overly permissive (any-any) rules identified and remediated? *
- Are unused, expired, or shadowed rules removed during periodic reviews? *
- How frequently are firewall rulesets reviewed?
Device Hardening
- Are network devices configured against a documented secure baseline? *
- Are default credentials changed and unnecessary services disabled? *
- Is management access restricted to dedicated administrative networks? *
- Is device firmware kept current with security updates? *
Segmentation & Perimeter
- Is the network segmented to isolate sensitive systems from general access? *
- Is inbound and outbound traffic filtered at trust boundaries? *
- Is outbound (egress) traffic restricted to required destinations?
Change Management & Logging
- Are firewall changes approved through a documented change process? *
- Are configuration backups maintained and version-controlled? *
- Are device and traffic logs sent to a central log repository? *
Download the full Firewall & Network Device Configuration Review checklist
Get it as a clean, printable PDF — free.
