May 10, 2006
Firewall Management Tips
Managing Firewalls is at the core of any information security program. If you haven’t done it or mananged it, you will one day. The guys at secmanager have a Top 10 list that has some good foundational rules:
2. Use a stealth Rule at the top of the rule base…
4. Keep the rulebase as simple as possible…
I’d like to add one to their list:
11. Have an documented, auditable change management process for every rule you have in place. When your boss asks, “Why is that rule there and what will break if we remove it?” You don’t want your answer to be, “I don’t know.”
Top Ten Tips for Managing Your Firewall [secmanager]




you may also want to see the following related article at
February 11th, 2007 at 2:30 amwww.firewallfaqs.com/gfaq/firewall_best_practice_policy_guidelines.htm
which includes the above comment and more.