A4
CE Montpellier
Firewalls
Technical protection between network devices and the internet. Covers boundary firewalls, software firewalls, and remote/home worker device protection.
15 questions
A4.1
A4.1.1
A4.2
A4.2.1
A4.3
A4.4
A4.5
A4.5.1
A4.6
A4.7
A4.8
A4.9
A4.10
A4.11
A4.12
Do you have firewalls at the boundaries between your organisation's internal networks, laptops, desktops, servers, and the internet?
yesno
When your devices (including computers used by homeworkers) are being used away from your workplace, how do you ensure they are protected?
text
When you first receive an internet router or hardware firewall device, it may have had a default password on it. Have you changed all the default passwords on your boundary firewall devices?
yesno
Please describe the process for changing your firewall password.
text
Is your new firewall password configured to meet the 'Password-based authentication' requirements?
choice
Do you change your firewall password when you know or suspect it has been compromised?
yesno
Do you have any services enabled that can be accessed externally from your internet router, hardware firewall or software firewall?
yesno
Do you have a documented business case for all of these services?
yesno
If you do have services enabled on your firewall, do you have a process to ensure they are disabled in a timely manner when they are no longer required?
text
Have you configured your boundary firewalls so that they block all other services from being advertised to the internet?
yesno
Are your boundary firewalls configured to allow access to their configuration settings over the internet?
yesno
If you answered yes in question A4.8, is there a documented business requirement for this access?
yesno
If you answered yes in question A4.8, is the access to your firewall settings protected by either multi-factor authentication or by only allowing trusted IP addresses combined with managed authentication?
choice
Do you have software firewalls enabled on all of your desktop computers, laptops and servers?
yesno
If you answered no to question A4.11, is this because software firewalls are not installed by default as part of the operating system you are using? Please list the operating systems.
text
Does your organisation meet the Firewalls requirements?
Check your real-world posture across all 5 Cyber Essentials control areas in 3 minutes. Free, no account needed.