INFRA-5 Firewalls

Estimated reading: 2 minutes 1492 views

What is INFRA-5 firewalls control?

Infra-5 firewalls control is a network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. This is an essential part of every organization’s network, and TrustCloud automates this control.

Evidence of “deny all” rules and NAT (Network Address Translation) rules is required.

Available tools in the marketplace 

No tool recommendation is made for this section.

Available templates

TrustCloud has a curated list of templates, internally or externally sourced, to help you get started. Click on the link for a downloadable version.

  • N/A: no template recommendation

Control implementation

NOTE: This control is 100% automated by TrustCloud. Connect your system to enjoy the benefits of automation.

All organizations have an understanding of firewall implementation. There will be no further instructions on implementation.

What evidence do auditors look for?

Most auditors, at a minimum, are looking for the below-suggested action.

  1. Provide the firewall rules (Block, Allow, deny, etc.)

Evidence example

For the suggested action, an example is provided below:

  1. Evidence of “deny all” rules and NAT (Network Address Translation) rules is required.
    The following screenshot shows the rules for a specific firewall.
    (Google search results of “deny all firewall rules”)
    INFRA 5 Firewalls

Join the conversation

You might also be interested in

Documentation Templates

Documentation Templates are documents that provide a content outline to meet certain documentation needs....

Backup policy template – Download for free

The Data Backup Plan template helps you document in detail the data backup needs...

HR-13 Employee Handbook/Code of Conduct

HR-13 Employee Handbook or Code of Conduct communicates the organization’s values and ethics. It...

AUTH-1 Single Sign On (SSO)

Single Sign On (SSO) Control is a best practice recommendation for critical systems....

Security Incident Report Template

The Security Incident Report template helps you document the steps used to assess and...

BIZOPS-6 Disaster Recovery Testing

BIZOPS-6 Disaster Recovery Testing control refers to the exercise of identifying the critical systems...

PDP-10 SDLC – Separation of environments

PDP-10 SDLC Separation of Environments is important to maintain separate environments to develop, test,...

Privacy Committee Charter Template

Privacy Committee Charter serves as a foundational document, establishing the framework for the committee's...