TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

INFRA-5 Firewalls

Estimated reading: 2 minutes 2691 views

What is INFRA-5 firewalls control?

One of the many controls, INFRA-5 firewalls control, is a network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. This is an essential part of every organization’s network, and TrustCloud automates this control.

INFRA-5 firewalls control is a term used to describe a specific type of firewall configuration and management. Firewalls are essential components of network security, serving as a barrier between internal networks and external threats. INFRA-5 firewalls control refers to a set of rules and policies that are implemented to regulate the flow of network traffic in order to protect the network from unauthorized access and potential attacks.

These controls typically include features such as access control lists, intrusion detection systems, and virtual private networks. By implementing INFRA-5 firewalls control, organizations can ensure that their networks are protected from potential threats and vulnerabilities.

Evidence of “deny all” rules and NAT (Network Address Translation) rules is required.

Available tools in the marketplace

Tools
No tool recommendation is made for this section.

Available templates

TrustCloud has a curated list of templates, internally or externally sourced, to help you get started. Click on the link for a downloadable version.

  • N/A: no template recommendation

Control implementation

NOTE: INFRA-5 control is 100% automated by TrustCloud. Connect your system to enjoy the benefits of automation.

All organizations have an understanding of firewall implementation. There will be no further instructions on implementation.

What evidence do auditors look for?

Most auditors, at a minimum, are looking for the below-suggested action.

  1. Provide the firewall rules (Block, Allow, deny, etc.)

Evidence example

For the suggested action, an example is provided below:

  1. Evidence of “deny all” rules and NAT (Network Address Translation) rules is required.
    The following screenshot shows the rules for a specific firewall.
    (Google search results of “deny all firewall rules”)
    INFRA-5

Have a question?

Join our TrustCommunity to learn about security, privacy, governance, risk and compliance, collaborate with your peers, and share and review the trust posture of companies that value trust and transparency!

Join the conversation

You might also be interested in

Custom Frameworks

TrustCloud supports several standards and frameworks out of the box, including SOC 2, CMMC,...

Hybrid Data Fabric

Rather than chasing fragmented spreadsheets or outdated lists, hybrid data fabric gives you a...

Systems

A system is a piece of software, either built by the organization or purchased...

Groups in Controls

TrustCloud provides you with a comprehensive set of controls to get certified against several...

Mapping a Control

TrustCloud’s common controls framework maps a comprehensive set of certified standards controls and your...

Sharing Controls with customers

The TrustShare application in TrustCloud makes it easy for startups, SMBs, and enterprises to...

Excluding a control, test or attestation

The exclusion allows you to remove certain resources, controls or tests from your program...

Control Attributes

Every control has many attributes that help us understand it better for mapping and...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue