Firewall Rules & Least Privilege
We identify overly broad rules, any-to-any access, unused rules, duplicate rules, risky services, missing logging, and policies that should be narrowed by source, destination, port, user, application, or schedule.
Your firewall should do more than pass traffic. It should reduce exposure, protect VPN access, inspect threats, log critical activity, and support compliance readiness for your business.
OC Security Audit, with 25+ years of experience under the management of Ali Hassani, has worked on dozens of networks for businesses in Southern California, Irvine, Orange County, and Los Angeles. With experience and certifications such as CISSP, CCISO, MCSE, MCSA Security, MCITP, CCNA, CCNP, and related security credentials, we help make your network and data more secure and your business better prepared for compliance requirements.
OC Security Audit reviews the settings that determine whether your firewall is actively protecting your organization or quietly exposing systems, users, data, and cloud services.
We identify overly broad rules, any-to-any access, unused rules, duplicate rules, risky services, missing logging, and policies that should be narrowed by source, destination, port, user, application, or schedule.
We review SSL VPN, IPsec VPN, site-to-site tunnels, MFA, inactive accounts, vendor access, administrator roles, secure management interfaces, and privileged access controls.
We check public exposure, NAT policies, port forwarding, remote access services, database exposure, web applications, vendor rules, and legacy systems that may need safer access methods.
We verify whether IPS, anti-malware, DNS filtering, URL filtering, botnet filtering, application control, SSL/TLS inspection, geo-blocking, and threat intelligence are licensed, updated, and applied correctly.
We review denied and allowed traffic logs, VPN events, administrator logins, configuration changes, SIEM forwarding, Microsoft Sentinel readiness, log retention, NTP, and security alerting.
We assess Microsoft Azure Firewall, Azure Network Security Groups, cloud routes, hybrid connectivity, and cloud firewall controls. For deeper cloud review, visit Azure Cloud Security Audit.
Many firewall risks appear over time: emergency rules, old vendor access, exposed management portals, outdated firmware, VPN changes, cloud migrations, and temporary exceptions that were never removed.
A Firewall Security Assessment focuses on technical firewall configuration, hardening, attack surface reduction, VPN security, open ports, NAT, logging, firmware, and threat prevention.
A Firewall Security Audit focuses on audit evidence, control validation, governance, documentation, policy alignment, and compliance readiness.
The assessment is structured so business leaders understand the risk and technical teams receive specific, prioritized actions they can implement.
Review firewall platform, interfaces, zones, VLANs, VPNs, NAT, cloud connectivity, logging, subscriptions, and management access.
Analyze firewall rules, exposure, firmware, threat prevention, VPN, MFA, cloud firewall settings, backups, and segmentation.
Separate high-risk issues from normal configuration improvements so your team can focus on the items that matter most.
Receive actionable recommendations, security hardening steps, and a practical roadmap for stronger protection.
Ransomware, credential attacks, exposed ports, weak VPN, outdated firmware, and missing logs can affect operations, customers, vendors, and compliance readiness. OC Security Audit helps you identify and reduce these risks before they become incidents.
A firewall assessment is strongest when connected to network security, cloud security, compliance readiness, risk management, and executive security governance.
Strong firewall controls can support compliance readiness, gap analysis, documentation support, control review, and audit preparation for organizations working toward HIPAA, PCI-DSS, SOC 2, NIST, ISO/IEC 27000, or CMMC 2.0 alignment.
For businesses in Southern California, Irvine, Orange County, and Los Angeles, OC Security Audit provides practical firewall security assessments focused on reducing exposure, hardening VPN access, improving logging, validating cloud controls, and creating a prioritized remediation plan.
This firewall security assessment checklist is used for IT managers, CISOs, cybersecurity consultants, network engineers, and network administrators who want to make sure that everything on the firewall is considered, secured, and locked. It helps teams review firewall rules, exposed services, VPN access, identity protection, logging, threat prevention, cloud firewall controls, backups, segmentation, and remediation priorities before small configuration gaps become serious business risks.
OC Security Audit helps organizations make networks and data more secure, improve compliance readiness, and prioritize firewall remediation with practical findings that IT teams can act on.
| ID | Assessment Domain | Assessment Item | Description | Evidence / What to Collect | Risk Score | Risk Rating | Risk Impact | Risk Likelihood | Likelihood This Might Occur | Priority | Last Checked | Owner | Status | Additional Notes | Related Service |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| FW-001 | Discovery & Scope | Firewall inventory completeness | Confirm every physical, virtual, branch, cloud, SD-WAN, VPN concentrator, and security gateway is included in the review scope. | Asset inventory, firewall dashboard exports, CMDB records, topology diagrams, configuration exports | 72 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-002 | Discovery & Scope | Firewall model and platform identification | Record vendor, model, serial number, OS, license tier, HA role, and management platform. | Asset inventory, firewall dashboard exports, CMDB records, topology diagrams, configuration exports | 55 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-003 | Discovery & Scope | Interface and zone mapping | Verify WAN, LAN, DMZ, guest, server, management, IoT, VPN, wireless, and cloud zones. | Asset inventory, firewall dashboard exports, CMDB records, topology diagrams, configuration exports | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-004 | Discovery & Scope | Network diagrams accuracy | Compare diagrams with actual firewall interfaces, VLANs, routes, NAT, and VPN connections. | Asset inventory, firewall dashboard exports, CMDB records, topology diagrams, configuration exports | 52 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-005 | Discovery & Scope | Internet circuit and public IP inventory | Document WAN circuits, public IP blocks, failover circuits, and provider responsibilities. | Asset inventory, firewall dashboard exports, CMDB records, topology diagrams, configuration exports | 66 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-006 | Discovery & Scope | Security subscription status | Confirm IPS, AV, DNS, URL filtering, sandboxing, and threat intelligence subscriptions are active. | Asset inventory, firewall dashboard exports, CMDB records, topology diagrams, configuration exports | 73 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-007 | Discovery & Scope | Management configuration baseline | Export current configuration and identify the standard configuration baseline for comparison. | Asset inventory, firewall dashboard exports, CMDB records, topology diagrams, configuration exports | 60 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-008 | Firmware & Updates | Firewall firmware version | Verify firewall firmware or operating system is currently supported by the vendor. | Firmware page screenshots, vendor advisory comparison, patch history, maintenance tickets, support portal records | 86 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-009 | Firmware & Updates | Security patch level | Check whether recent security patches, hotfixes, and maintenance releases are installed. | Firmware page screenshots, vendor advisory comparison, patch history, maintenance tickets, support portal records | 88 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-010 | Firmware & Updates | Threat signature update status | Validate IPS, malware, content filtering, DNS, and URL signatures are current. | Firmware page screenshots, vendor advisory comparison, patch history, maintenance tickets, support portal records | 70 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-011 | Firmware & Updates | End-of-life / end-of-support status | Identify unsupported firewalls, modules, OS versions, and subscriptions. | Firmware page screenshots, vendor advisory comparison, patch history, maintenance tickets, support portal records | 82 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-012 | Firmware & Updates | Vendor support contract | Confirm support contract status and access to firmware downloads and emergency support. | Firmware page screenshots, vendor advisory comparison, patch history, maintenance tickets, support portal records | 55 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-013 | Firmware & Updates | Upgrade path and maintenance window | Confirm upgrades have an approved maintenance window, pre-checks, and post-checks. | Firmware page screenshots, vendor advisory comparison, patch history, maintenance tickets, support portal records | 64 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-014 | Firmware & Updates | Rollback planning | Verify backups and rollback steps exist before firmware or policy changes. | Firmware page screenshots, vendor advisory comparison, patch history, maintenance tickets, support portal records | 68 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-015 | Rulebase Hardening | Any-to-any firewall rules | Identify unrestricted source, destination, and service combinations. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 92 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-016 | Rulebase Hardening | Any-source access rules | Find rules allowing access from any source when restrictions should exist. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 84 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-017 | Rulebase Hardening | Any-destination access rules | Find rules allowing broad access to any destination. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 79 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-018 | Rulebase Hardening | Any-service rules | Review rules allowing all ports, protocols, or applications. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 83 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-019 | Rulebase Hardening | Broad network ranges | Identify rules using large subnets where narrow ranges are appropriate. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 74 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-020 | Rulebase Hardening | Overly permissive outbound rules | Review broad outbound access that could enable data exfiltration or command-and-control. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-021 | Rulebase Hardening | Overly permissive inbound rules | Review inbound rules that expose internal services unnecessarily. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 89 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-022 | Rulebase Hardening | High-risk protocol allowance | Review RDP, SSH, Telnet, SMB, SQL, FTP, SNMP, and management protocols. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 87 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-023 | Rulebase Hardening | Legacy protocol rules | Identify rules allowing outdated or insecure protocols. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 76 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-024 | Rulebase Hardening | Temporary rules not removed | Find emergency, vendor, or project rules that remained enabled after use. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 76 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-025 | Rulebase Hardening | Unused rules | Find zero-hit or low-hit rules over the review period. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 45 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Unlikely | Unlikely | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-026 | Rulebase Hardening | Duplicate rules | Identify duplicate rules that complicate management. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 38 | Low | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Unlikely | Unlikely | Low | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-027 | Rulebase Hardening | Disabled rules | Review disabled rules to determine whether they should be removed. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 32 | Low | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Unlikely | Unlikely | Low | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-028 | Rulebase Hardening | Shadowed rules | Identify rules hidden by earlier policies. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 58 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-029 | Rulebase Hardening | Rules bypassing inspection | Find rules that skip IPS, malware scanning, SSL inspection, logging, or app control. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 82 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-030 | Rulebase Hardening | Rules without logging | Identify important allow/deny rules where logging is disabled. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 67 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-031 | Rulebase Hardening | Weak naming conventions | Review whether rule names explain purpose, owner, and ticket. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 36 | Low | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Unlikely | Unlikely | Low | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-032 | Rulebase Hardening | Missing technical justification | Confirm each active rule has business purpose and approval evidence. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 62 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-033 | Rulebase Hardening | Least-privilege scope | Narrow source, destination, port, app, user, and schedule where possible. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-034 | Rulebase Hardening | Rule recertification process | Verify that rules are periodically reviewed by business and technical owners. | Rule export, hit counts, change tickets, business owner approval, screenshots, recertification records | 63 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-035 | Internet Exposure | Public RDP exposure | Review any Remote Desktop exposure from the internet. | External scan results, NAT rules, public IP map, firewall logs, business justification, screenshots | 95 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-036 | Internet Exposure | Public SSH exposure | Review direct SSH exposure and source restrictions. | External scan results, NAT rules, public IP map, firewall logs, business justification, screenshots | 82 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-037 | Internet Exposure | Public FTP / Telnet exposure | Identify insecure legacy remote access protocols exposed externally. | External scan results, NAT rules, public IP map, firewall logs, business justification, screenshots | 90 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-038 | Internet Exposure | Public SMB exposure | Confirm SMB is not exposed to the internet. | External scan results, NAT rules, public IP map, firewall logs, business justification, screenshots | 96 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-039 | Internet Exposure | Public database ports | Review SQL, MySQL, PostgreSQL, and database listener exposure. | External scan results, NAT rules, public IP map, firewall logs, business justification, screenshots | 91 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-040 | Internet Exposure | Remote management portals | Verify firewall, server, camera, VoIP, and application admin portals are not publicly exposed. | External scan results, NAT rules, public IP map, firewall logs, business justification, screenshots | 89 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-041 | Internet Exposure | VPN portal exposure | Assess VPN portal hardening, MFA, lockout, logging, and geo restrictions. | External scan results, NAT rules, public IP map, firewall logs, business justification, screenshots | 84 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-042 | Internet Exposure | Public web applications | Review public web applications for necessity, WAF or inspection, and logging. | External scan results, NAT rules, public IP map, firewall logs, business justification, screenshots | 74 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-043 | Internet Exposure | Mail service exposure | Review SMTP, OWA, mail gateways, and related exposure. | External scan results, NAT rules, public IP map, firewall logs, business justification, screenshots | 72 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-044 | Internet Exposure | Camera and IoT exposure | Identify cameras, NVRs, IoT devices, and building systems reachable from the internet. | External scan results, NAT rules, public IP map, firewall logs, business justification, screenshots | 86 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-045 | Internet Exposure | Vendor support access | Review vendor allowlists, schedules, authentication, and expiration dates. | External scan results, NAT rules, public IP map, firewall logs, business justification, screenshots | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-046 | Internet Exposure | Public-facing administrative interfaces | Remove or tightly restrict public administrative interfaces. | External scan results, NAT rules, public IP map, firewall logs, business justification, screenshots | 92 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Network Vulnerability Assessment |
| FW-047 | NAT & Port Forwarding | Destination NAT rules | Review public-to-private mappings for necessity, source limits, and logging. | NAT table export, policy match, public IP inventory, owner approval, external validation scan | 79 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-048 | NAT & Port Forwarding | Source NAT rules | Validate outbound NAT design and prevent unintended egress paths. | NAT table export, policy match, public IP inventory, owner approval, external validation scan | 55 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-049 | NAT & Port Forwarding | Static NAT rules | Review static mappings for exposure and business need. | NAT table export, policy match, public IP inventory, owner approval, external validation scan | 75 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-050 | NAT & Port Forwarding | Dynamic NAT rules | Validate dynamic NAT behavior and egress control. | NAT table export, policy match, public IP inventory, owner approval, external validation scan | 48 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Unlikely | Unlikely | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-051 | NAT & Port Forwarding | One-to-one NAT mappings | Review one-to-one NAT for unnecessary exposure of internal systems. | NAT table export, policy match, public IP inventory, owner approval, external validation scan | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-052 | NAT & Port Forwarding | Port forwarding rules | Identify old, broad, or undocumented port forwards. | NAT table export, policy match, public IP inventory, owner approval, external validation scan | 86 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-053 | NAT & Port Forwarding | Public-to-private IP mappings | Map all public addresses to internal systems and owners. | NAT table export, policy match, public IP inventory, owner approval, external validation scan | 74 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-054 | NAT & Port Forwarding | Hairpin NAT | Assess internal access paths and logging for hairpin NAT behavior. | NAT table export, policy match, public IP inventory, owner approval, external validation scan | 42 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Unlikely | Unlikely | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-055 | NAT & Port Forwarding | NAT rules without matching policies | Find NAT entries not governed by clear firewall rules. | NAT table export, policy match, public IP inventory, owner approval, external validation scan | 65 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-056 | NAT & Port Forwarding | Legacy server NAT | Confirm old server mappings are removed or protected. | NAT table export, policy match, public IP inventory, owner approval, external validation scan | 83 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-057 | NAT & Port Forwarding | Vendor NAT rules | Review vendor NAT access for expiration and source restrictions. | NAT table export, policy match, public IP inventory, owner approval, external validation scan | 74 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Firewall Security Audit |
| FW-058 | VPN Security | SSL VPN configuration | Review portal, cipher settings, access groups, split tunnel, idle timeout, and lockout. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 84 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-059 | VPN Security | IPsec VPN configuration | Review IKE version, proposals, PFS, lifetimes, and encryption strength. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-060 | VPN Security | Remote access VPN users | Validate active users, group membership, least privilege, and departed users. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 82 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-061 | VPN Security | Site-to-site VPN tunnels | Inventory site, vendor, and cloud tunnels. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 72 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-062 | VPN Security | VPN authentication settings | Review authentication source, conditional access, and fallback settings. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 84 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-063 | VPN Security | VPN user groups | Confirm groups match approved access roles. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 68 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-064 | VPN Security | VPN address pools | Review pool ranges and routing overlap. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 45 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Unlikely | Unlikely | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-065 | VPN Security | VPN access permissions | Confirm VPN users only reach required systems and ports. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 81 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-066 | VPN Security | Split tunneling | Determine whether split tunnel is approved and risk-managed. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 69 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-067 | VPN Security | Full tunnel configuration | Validate egress inspection for full-tunnel remote users. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 58 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-068 | VPN Security | VPN encryption algorithms | Remove weak ciphers, weak DH groups, and outdated proposals. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 82 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-069 | VPN Security | Pre-shared key strength | Assess PSK complexity, age, and rotation process. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-070 | VPN Security | Certificate-based VPN options | Determine whether certificate auth should replace or supplement PSKs. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 54 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-071 | VPN Security | Inactive VPN accounts | Disable stale accounts and review last login activity. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 88 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-072 | VPN Security | Shared VPN accounts | Identify and remove shared VPN credentials. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 93 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-073 | VPN Security | Vendor VPN accounts | Check vendor users for ownership, expiration, MFA, and monitoring. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 86 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-074 | VPN Security | Failed VPN login activity | Review brute-force attempts, lockouts, geo anomalies, and impossible travel. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 75 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-075 | VPN Security | VPN logging | Confirm logins, failures, session duration, and assigned IPs are retained. | VPN settings export, user list, authentication logs, group membership, access rules, screenshots | 65 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-076 | MFA & Identity Protection | MFA for firewall administrators | Verify administrative access requires MFA. | MFA policy screenshots, identity provider settings, admin lists, sign-in logs, conditional access policies | 93 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-077 | MFA & Identity Protection | MFA for remote access VPN users | Verify all VPN users complete MFA. | MFA policy screenshots, identity provider settings, admin lists, sign-in logs, conditional access policies | 94 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-078 | MFA & Identity Protection | MFA for SSL VPN users | Confirm SSL VPN authentication cannot rely on password-only access. | MFA policy screenshots, identity provider settings, admin lists, sign-in logs, conditional access policies | 94 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-079 | MFA & Identity Protection | MFA for cloud dashboards | Confirm Meraki, Azure, AWS, Google, Fortinet, SonicWall, and Palo Alto dashboards enforce MFA. | MFA policy screenshots, identity provider settings, admin lists, sign-in logs, conditional access policies | 88 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-080 | MFA & Identity Protection | Vendor account MFA | Ensure vendors with access use MFA and scoped roles. | MFA policy screenshots, identity provider settings, admin lists, sign-in logs, conditional access policies | 85 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-081 | MFA & Identity Protection | Privileged IT account protection | Confirm privileged firewall-related accounts use strong authentication and conditional access. | MFA policy screenshots, identity provider settings, admin lists, sign-in logs, conditional access policies | 86 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-082 | MFA & Identity Protection | Identity provider integration | Review Entra ID, AD, RADIUS, LDAP, SAML, Duo, Okta, or similar integrations. | MFA policy screenshots, identity provider settings, admin lists, sign-in logs, conditional access policies | 70 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-083 | Site-to-Site VPN | Tunnel peer IP validation | Confirm peer IPs and business owners for each site-to-site tunnel. | Tunnel config, peer list, route table, access rules, logs, approval records | 62 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-084 | Site-to-Site VPN | Tunnel encryption | Review IKE, Phase 1, Phase 2, PFS, DH groups, and cipher strength. | Tunnel config, peer list, route table, access rules, logs, approval records | 82 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-085 | Site-to-Site VPN | Allowed local networks | Limit local tunnel selectors to approved networks only. | Tunnel config, peer list, route table, access rules, logs, approval records | 84 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-086 | Site-to-Site VPN | Allowed remote networks | Limit remote tunnel selectors to approved networks only. | Tunnel config, peer list, route table, access rules, logs, approval records | 84 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-087 | Site-to-Site VPN | Routing through tunnels | Review route tables to prevent excessive trust or unwanted backhaul. | Tunnel config, peer list, route table, access rules, logs, approval records | 68 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-088 | Site-to-Site VPN | Tunnel monitoring and DPD | Confirm tunnel status monitoring, dead peer detection, and alerts. | Tunnel config, peer list, route table, access rules, logs, approval records | 49 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Unlikely | Unlikely | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-089 | Site-to-Site VPN | Vendor tunnel access | Validate vendor tunnels are segmented and time-bound. | Tunnel config, peer list, route table, access rules, logs, approval records | 86 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-090 | Site-to-Site VPN | Cloud site-to-site VPN | Review Azure, AWS, or Google VPN connections and route propagation. | Tunnel config, peer list, route table, access rules, logs, approval records | 72 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-091 | Site-to-Site VPN | Failover settings | Validate tunnel failover behavior and monitoring. | Tunnel config, peer list, route table, access rules, logs, approval records | 55 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-092 | Site-to-Site VPN | Tunnel logging | Confirm tunnel events and failures are logged. | Tunnel config, peer list, route table, access rules, logs, approval records | 56 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-093 | Site-to-Site VPN | Access rules for VPN traffic | Confirm policies inspect and restrict tunnel traffic. | Tunnel config, peer list, route table, access rules, logs, approval records | 82 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-094 | Administrator Access | Local administrator accounts | Review local accounts, ownership, last login, and necessity. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 82 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-095 | Administrator Access | Directory-integrated admin accounts | Validate AD or Entra-integrated admin group membership. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 74 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-096 | Administrator Access | Role-based access control | Confirm admins have appropriate least-privilege roles. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 69 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-097 | Administrator Access | Read-only accounts | Validate view-only accounts cannot make changes. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 52 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-098 | Administrator Access | Helpdesk accounts | Confirm helpdesk access is limited to approved support tasks. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 55 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-099 | Administrator Access | Vendor administrator accounts | Review vendor admin access, expiration, MFA, and activity logs. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 86 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-100 | Administrator Access | Shared administrator accounts | Identify and remove shared admin credentials. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 94 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-101 | Administrator Access | Default accounts | Disable or secure default accounts and default passwords. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 90 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-102 | Administrator Access | Password policy | Check length, complexity, rotation, and lockout policy. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 66 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-103 | Administrator Access | Management interface restrictions | Restrict admin portals to approved management networks and VPN. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 91 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-104 | Administrator Access | Allowed management IPs | Verify admin access allowlists are narrow and current. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 85 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-105 | Administrator Access | HTTPS management | Disable insecure web management and enforce secure TLS. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 74 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-106 | Administrator Access | SSH management | Restrict SSH management and remove weak algorithms. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 72 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-107 | Administrator Access | SNMP configuration | Remove SNMP v1/v2 where possible and restrict SNMP sources. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 73 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-108 | Administrator Access | API access | Review API keys, integrations, privileges, and rotation. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 75 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-109 | Administrator Access | Cloud dashboard access | Review cloud-managed firewall dashboard users and permissions. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 82 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-110 | Administrator Access | Session timeout | Confirm admin sessions expire automatically. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 45 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Unlikely | Unlikely | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-111 | Administrator Access | Login lockout | Confirm failed admin login lockout is enabled. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-112 | Administrator Access | Failed login logging | Verify failed administrative logins are logged and alerted. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-113 | Administrator Access | Administrative change logging | Capture who changed what and when. | Admin list, RBAC settings, management ACLs, auth logs, config audit logs, screenshots | 85 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Security Governance |
| FW-114 | Threat Prevention | IPS / IDS | Verify intrusion prevention or detection is licensed, updated, and applied to traffic. | Security profile settings, policy attachments, subscription status, event logs, exception list | 82 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-115 | Threat Prevention | Gateway antivirus | Confirm gateway malware scanning is enabled where supported. | Security profile settings, policy attachments, subscription status, event logs, exception list | 76 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-116 | Threat Prevention | Anti-malware scanning | Review anti-malware settings and policy attachment. | Security profile settings, policy attachments, subscription status, event logs, exception list | 76 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-117 | Threat Prevention | Anti-spyware | Review spyware and command-and-control protections. | Security profile settings, policy attachments, subscription status, event logs, exception list | 75 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-118 | Threat Prevention | Botnet filtering | Confirm botnet detection and blocking are enabled. | Security profile settings, policy attachments, subscription status, event logs, exception list | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-119 | Threat Prevention | DNS filtering | Confirm malicious domain blocking is enabled and logged. | Security profile settings, policy attachments, subscription status, event logs, exception list | 74 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-120 | Threat Prevention | URL filtering | Review malware, phishing, risky, and newly registered domain categories. | Security profile settings, policy attachments, subscription status, event logs, exception list | 70 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-121 | Threat Prevention | Content filtering | Review content categories and business exceptions. | Security profile settings, policy attachments, subscription status, event logs, exception list | 58 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-122 | Threat Prevention | Application control | Block or monitor risky applications and unauthorized remote tools. | Security profile settings, policy attachments, subscription status, event logs, exception list | 73 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-123 | Threat Prevention | Geo-IP blocking | Evaluate country restrictions for management, VPN, and inbound services. | Security profile settings, policy attachments, subscription status, event logs, exception list | 58 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-124 | Threat Prevention | Threat intelligence feeds | Confirm reputation feeds are active and applied. | Security profile settings, policy attachments, subscription status, event logs, exception list | 65 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-125 | Threat Prevention | File inspection | Review file inspection coverage and bypasses. | Security profile settings, policy attachments, subscription status, event logs, exception list | 68 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-126 | Threat Prevention | Sandboxing / zero-day protection | Review file detonation and zero-day protection. | Security profile settings, policy attachments, subscription status, event logs, exception list | 72 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-127 | Threat Prevention | Command-and-control detection | Confirm C2 detection policies are enabled. | Security profile settings, policy attachments, subscription status, event logs, exception list | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-128 | Threat Prevention | SSL/TLS inspection | Confirm encrypted traffic inspection strategy is approved and applied where appropriate. | Security profile settings, policy attachments, subscription status, event logs, exception list | 67 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-129 | Threat Prevention | Security profiles on policies | Verify security profiles are attached to rules, not just licensed. | Security profile settings, policy attachments, subscription status, event logs, exception list | 86 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-130 | Threat Prevention | Security license status | Confirm threat prevention licenses are active. | Security profile settings, policy attachments, subscription status, event logs, exception list | 73 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-131 | Threat Prevention | Exceptions and bypass rules | Review bypasses for necessity, approval, expiration, and compensating controls. | Security profile settings, policy attachments, subscription status, event logs, exception list | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-132 | Application, Web, DNS & TLS Controls | Application visibility | Confirm firewall identifies applications rather than only ports. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 54 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Endpoint Security |
| FW-133 | Application, Web, DNS & TLS Controls | Remote access tools | Review TeamViewer, AnyDesk, ScreenConnect, RMM, and other remote tools. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 82 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Endpoint Security |
| FW-134 | Application, Web, DNS & TLS Controls | File-sharing applications | Restrict unauthorized file-sharing services. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 62 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Endpoint Security |
| FW-135 | Application, Web, DNS & TLS Controls | Peer-to-peer applications | Restrict P2P traffic that increases malware and data exposure. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 62 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Endpoint Security |
| FW-136 | Application, Web, DNS & TLS Controls | Proxy avoidance | Block or monitor proxy avoidance tools. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 76 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-137 | Application, Web, DNS & TLS Controls | Anonymous VPN tools | Block or monitor unauthorized anonymizing VPN services. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 76 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-138 | Application, Web, DNS & TLS Controls | User-based filtering | Validate policies map to users or groups where supported. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 55 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Endpoint Security |
| FW-139 | Application, Web, DNS & TLS Controls | Group-based filtering | Confirm filtering aligns with department or role-based needs. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 50 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Endpoint Security |
| FW-140 | Application, Web, DNS & TLS Controls | Filtering exceptions | Review exceptions for approval, expiration, and risk acceptance. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 68 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-141 | Application, Web, DNS & TLS Controls | Unauthorized external DNS | Prevent clients from bypassing approved DNS resolvers. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-142 | Application, Web, DNS & TLS Controls | DNS over HTTPS | Review DoH behavior and whether it bypasses DNS inspection. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 66 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-143 | Application, Web, DNS & TLS Controls | Internal DNS forwarding | Confirm internal DNS flows are controlled and logged. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 50 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-144 | Application, Web, DNS & TLS Controls | DNS logging | Verify DNS queries and blocks are logged. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 60 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-145 | Application, Web, DNS & TLS Controls | Threat intelligence domain feeds | Confirm malicious domain feeds are active. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 70 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-146 | Application, Web, DNS & TLS Controls | TLS certificate deployment | Confirm inspection certificates are trusted and properly distributed. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 55 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-147 | Application, Web, DNS & TLS Controls | TLS included networks | Review which networks are included in SSL/TLS inspection. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 62 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-148 | Application, Web, DNS & TLS Controls | TLS excluded networks | Review exclusions for privacy, healthcare, banking, and compatibility. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 52 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-149 | Application, Web, DNS & TLS Controls | TLS bypass rules | Review bypass rules for excessive scope or missing justification. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 74 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-150 | Application, Web, DNS & TLS Controls | TLS version support | Disable outdated TLS versions where appropriate. | Configuration screenshots, policy exports, exception list, test results, DNS logs, TLS policy review | 72 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-151 | Logging, Monitoring & Alerting | Allowed traffic logging | Verify logging on important allow rules. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 58 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-152 | Logging, Monitoring & Alerting | Denied traffic logging | Verify deny/drop traffic is logged for investigations. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 62 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-153 | Logging, Monitoring & Alerting | Inbound access logging | Confirm public-facing access is logged with source, destination, and service. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-154 | Logging, Monitoring & Alerting | Outbound access logging | Confirm egress events support investigation and policy tuning. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 60 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-155 | Logging, Monitoring & Alerting | VPN login logging | Log successful VPN activity. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 76 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-156 | Logging, Monitoring & Alerting | VPN failure logging | Log failed VPN authentication and lockouts. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-157 | Logging, Monitoring & Alerting | Administrator login logging | Log admin success, failure, and source IP. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-158 | Logging, Monitoring & Alerting | Configuration change logging | Capture who changed what and when. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 85 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-159 | Logging, Monitoring & Alerting | NAT event logging | Log NAT events tied to public exposure and troubleshooting. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 55 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-160 | Logging, Monitoring & Alerting | IPS event logging | Confirm IPS alerts are logged and searchable. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-161 | Logging, Monitoring & Alerting | Malware event logging | Confirm malware detections are logged and alerted. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-162 | Logging, Monitoring & Alerting | Botnet event logging | Confirm botnet events are logged and alerted. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-163 | Logging, Monitoring & Alerting | Application control logging | Log blocked and risky application activity. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 65 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-164 | Logging, Monitoring & Alerting | URL filtering logging | Log web filtering allow, block, and category events. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 62 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-165 | Logging, Monitoring & Alerting | DNS filtering logging | Log malicious DNS blocks and suspicious lookups. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 72 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-166 | Logging, Monitoring & Alerting | Geo-IP blocking logs | Log geo-blocked events for review. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 52 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-167 | Logging, Monitoring & Alerting | Syslog forwarding | Forward important firewall events to syslog or SIEM. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-168 | Logging, Monitoring & Alerting | SIEM integration | Validate firewall events are searchable in the SIEM. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-169 | Logging, Monitoring & Alerting | Microsoft Sentinel / Log Analytics | Confirm cloud-forwarded events are searchable and retained. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 65 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-170 | Logging, Monitoring & Alerting | Splunk / FortiAnalyzer / Panorama / Meraki logs | Validate vendor log platform integration where applicable. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 58 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-171 | Logging, Monitoring & Alerting | Log retention | Confirm retention supports investigations and compliance readiness. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 72 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-172 | Logging, Monitoring & Alerting | NTP synchronization | Ensure firewall time is synchronized for event correlation. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 64 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-173 | Logging, Monitoring & Alerting | Critical event alerting | Alert on VPN brute force, admin failures, malware, IPS, and configuration changes. | Log settings, SIEM forwarding status, sample events, retention settings, alert rules, time sync settings | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Threat Detection |
| FW-174 | Backup, Segmentation & Cloud Firewalls | Automatic configuration backups | Confirm scheduled firewall backups are enabled. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 75 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Business Continuity & DR |
| FW-175 | Backup, Segmentation & Cloud Firewalls | Manual configuration backups | Verify backups are made before major changes and firmware upgrades. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 68 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Business Continuity & DR |
| FW-176 | Backup, Segmentation & Cloud Firewalls | Backup storage location | Confirm backups are stored in approved secure locations. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 62 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Business Continuity & DR |
| FW-177 | Backup, Segmentation & Cloud Firewalls | Encrypted backup storage | Protect configuration backups with encryption where available. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 76 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Business Continuity & DR |
| FW-178 | Backup, Segmentation & Cloud Firewalls | Backup access permissions | Limit who can access firewall configuration backups. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Business Continuity & DR |
| FW-179 | Backup, Segmentation & Cloud Firewalls | Backup retention | Confirm backup history supports rollback and investigation needs. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 55 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Business Continuity & DR |
| FW-180 | Backup, Segmentation & Cloud Firewalls | Restore testing | Validate firewall configurations can be restored. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 82 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Business Continuity & DR |
| FW-181 | Backup, Segmentation & Cloud Firewalls | High availability synchronization | Confirm HA peers synchronize configuration and failover settings. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 72 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Business Continuity & DR |
| FW-182 | Backup, Segmentation & Cloud Firewalls | User network segmentation | Restrict user VLAN access to server networks. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 84 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-183 | Backup, Segmentation & Cloud Firewalls | Server network segmentation | Limit server-to-server traffic by business need. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-184 | Backup, Segmentation & Cloud Firewalls | Domain controller segmentation | Limit DC access to required protocols and approved systems. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 88 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-185 | Backup, Segmentation & Cloud Firewalls | Backup system segmentation | Protect backup repositories from broad access. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 91 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-186 | Backup, Segmentation & Cloud Firewalls | Management network segmentation | Restrict management interfaces to dedicated admin networks. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 87 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-187 | Backup, Segmentation & Cloud Firewalls | Guest Wi-Fi isolation | Confirm guest Wi-Fi cannot reach corporate systems. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-188 | Backup, Segmentation & Cloud Firewalls | Corporate Wi-Fi segmentation | Ensure corporate Wi-Fi access follows identity and device controls. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 65 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-189 | Backup, Segmentation & Cloud Firewalls | IoT device isolation | Segment IoT, cameras, printers, and building systems. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-190 | Backup, Segmentation & Cloud Firewalls | POS segmentation | Restrict POS network access to approved systems only. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 90 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-191 | Backup, Segmentation & Cloud Firewalls | DMZ design | Confirm public-facing systems are isolated from internal networks. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 85 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-192 | Backup, Segmentation & Cloud Firewalls | Cloud workload segmentation | Review cloud network segmentation for workloads and data tiers. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-193 | Backup, Segmentation & Cloud Firewalls | Sensitive database segmentation | Restrict sensitive databases to approved application servers and admins. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 90 | Critical | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | Critical | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Internal Network Security |
| FW-194 | Backup, Segmentation & Cloud Firewalls | Azure Firewall policies | Review Azure Firewall rules, policy hierarchy, logging, and routing. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-195 | Backup, Segmentation & Cloud Firewalls | Azure Network Security Groups | Review NSGs for broad access and internet exposure. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 84 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-196 | Backup, Segmentation & Cloud Firewalls | Azure route tables | Confirm routes do not bypass inspection or segmentation. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 70 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-197 | Backup, Segmentation & Cloud Firewalls | Azure VPN Gateway | Review VPN gateway connections, routes, logging, and authentication. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 72 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-198 | Backup, Segmentation & Cloud Firewalls | Azure hub-and-spoke networking | Validate inspection and routing in hub-and-spoke designs. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 68 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-199 | Backup, Segmentation & Cloud Firewalls | Azure private endpoints | Validate private endpoint design and access restrictions. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 62 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-200 | Backup, Segmentation & Cloud Firewalls | AWS Network Firewall | Review AWS Network Firewall policies and logging. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 78 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-201 | Backup, Segmentation & Cloud Firewalls | AWS security groups | Review inbound and outbound rules for least privilege. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 84 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-202 | Backup, Segmentation & Cloud Firewalls | AWS network ACLs | Assess subnet-level access controls and unintended exposure. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 68 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-203 | Backup, Segmentation & Cloud Firewalls | AWS route tables and VPC endpoints | Confirm routing aligns with inspection and egress strategy. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 66 | Medium | Could weaken visibility, governance, consistency, or remediation planning if not reviewed. | Possible | Possible | Medium | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-204 | Backup, Segmentation & Cloud Firewalls | Google Cloud firewall rules | Review GCP firewall rules and policy hierarchy. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 80 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-205 | Backup, Segmentation & Cloud Firewalls | Google Cloud firewall policies | Confirm hierarchical policies align with security standards. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 74 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-206 | Backup, Segmentation & Cloud Firewalls | Virtual firewall appliances | Review marketplace and virtual appliance policy, routing, and HA. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 72 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-207 | Backup, Segmentation & Cloud Firewalls | Cloud logging | Ensure cloud firewall and flow logs are enabled and retained. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 74 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-208 | Backup, Segmentation & Cloud Firewalls | Cloud identity permissions | Review who can change cloud firewall rules and routes. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 88 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Likely | Likely | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
| FW-209 | Backup, Segmentation & Cloud Firewalls | Hybrid connectivity | Review ExpressRoute, VPN, Direct Connect, peering, and transit routes. | Configuration exports, diagrams, route tables, logs, backup records, access reviews, cloud policy exports | 72 | High | Could create material security exposure, compliance readiness gaps, operational disruption, or incident response limitations. | Possible | Possible | High | TBD | IT / Security | Not Assessed | Record findings, screenshots, rule IDs, business owner, ticket number, remediation decision, and follow-up date. | Azure Cloud Security Audit |
Start with discovery, firmware, exposed services, VPN, administrator access, and logging. Then review segmentation, cloud firewall controls, backups, and remediation ownership.
Critical and High items should be reviewed first because they often involve internet exposure, privileged access, weak VPN controls, unsupported firmware, or missing security monitoring.
OC Security Audit has worked on dozens of business networks and can help prioritize findings, reduce exposure, strengthen firewall controls, and support compliance readiness.