x
login about faq

How do I perorm a firewall audit?

What are some general best practices for performing a firewall audit within my organization?

more ▼

asked Oct 19 at 05:42 PM

mitchp\'s gravatar image

mitchp ♦♦
1.3k 117 140 277

(comments are locked)
10|600 characters needed characters left

1 answer: sort voted first

You will need to pull, at random, around 10 change requests since the last audit. The basic questions you should be asking when you audit a firewall change are:

Is the requester documented, and is s/he authorized to make firewall change requests?
Is the business reason for the change documented?
Are there proper reviewer and approval signatures (electronic or physical)?
Were the approvals recorded before the change was implemented?
Are the approvers all authorized to approve firewall changes (you will need to ask for a list of authorized individuals)?
Are the changes well documented in the change ticket?
Is there documentation of risk analysis for each change?
Is there documentation of the change window and/or install date for each change?
Is there an expiration date for the change?

http://www.techyv.com/article/10-system-admin-must-have-tools

more ▼

answered Nov 15 at 09:31 AM

mrsignacio\'s gravatar image

mrsignacio
1

(comments are locked)
10|600 characters needed characters left
Your answer
toggle preview:

Up to 2 attachments (including images) can be used with a maximum of 524.3 kB each and 1.0 MB total.

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Topics:

x59
x16
x5

asked: Oct 19 at 05:42 PM

Seen: 1345 times

Last Updated: Nov 15 at 09:31 AM

powered by AnswerHub - Enterprise Social Q&A