A4
CE Danzell
Firewalls
Identical in structure to Willow. A4.1 through A4.11 unchanged.
14 questions
A4.1
A4.1.1
A4.1.2
A4.2
A4.2.1
A4.3
A4.4
A4.5
A4.6
A4.7
A4.8
A4.9
A4.10
A4.11
Do you have firewalls at the boundaries between your organisation's internal networks, laptops, desktops, servers, and the internet?
yesno
Do you have software firewalls enabled on all of your computers, laptops and servers?
yesno
If you answered no to question A4.1.1, is this because software firewalls are not installed by default as part of the operating system you are using? Please list the operating systems.
text
When you first receive an internet router or hardware firewall device, it may have had a default password on it. Have you changed all the default passwords on your boundary firewall devices?
yesno
Please describe the process for changing your firewall password.
text
How is your firewall password configured?
choice
Do you change your firewall password when you know or suspect it has been compromised?
yesno
Do you have a process to manage your firewall?
yesnodescribe
Have you reviewed your firewall rules in the last 12 months?
yesnodescribe
Is your firewall configured to allow unauthenticated inbound connections?
yesno
Please describe how you approve and document your allowed inbound connections.
text
Are your boundary firewalls configured to allow access to their configuration settings over the internet?
yesno
If you answered yes in question A4.9, is there a documented business requirement for this access?
yesno
If you answered yes in question A4.9, is the access to your firewall settings protected by either multi-factor authentication or by only allowing trusted IP addresses combined with managed authentication?
choice
Does your organisation meet the Firewalls requirements?
Check your real-world posture across all 5 Cyber Essentials control areas in 3 minutes. Free, no account needed.