Willow A4.6

Have you reviewed your firewall rules in the last 12 months?

Section A4: Firewalls  ·  Cyber Essentials Willow

Danzell made the 12-month maximum review cycle explicit where it was previously implied.

What this question is really asking

Confirm that you review your firewall rules at least annually. Assessors look for evidence of a scheduled review — a calendar task, change management record, or audit log. The review should result in documented actions and must remove any rules that are no longer required.

What satisfies this requirement

Yes or No — if Yes, a written description is also required

Describe your review process. Must have a process to remove rules no longer needed: when reviewed, who decides, who checks completion. CE Requirement: remove or disable inbound firewall rules quickly when no longer needed.

Check how you answer this in the CE Explorer
Free tool — all 288 questions mapped across every CE version.
Open CE Explorer

What to prepare before your assessor visit

The annual review needs to produce a tangible output — a dated record of what was reviewed and what changed (or was confirmed still required). A verbal conversation between two people doesn't leave an audit trail. Create a calendar reminder and produce a brief written summary with a date and the name of who conducted the review. It does not need to be elaborate — it needs to exist.

How this question sits across CE versions

Willow You are here
Have you reviewed your firewall rules in the last 12 months?
Montpellier evolved View →
If you do have services enabled on your firewall, do you have a process to ensure they are disabled in a timely manner when they are no longer required?
Danzell View →
Have you reviewed your firewall rules in the last 12 months?

Related policy templates

Getting certified means having documentation to back it up. These policy templates cover the controls this question tests.

Does your organisation meet this requirement?

Answer 30 plain-English questions and find out exactly where you stand across all 5 Cyber Essentials control areas — with a prioritised list of what to fix first.