Skip to main content

Firewalls / Security Groups

Example screenshots and guidance for firewall / security group evidence

D
Written by Drew Salisbury
Updated over 2 weeks ago

Guidance

  • If you do not restrict the inbound and/or outbound access to your in-scope production systems, explain why in the Evidence Description.

  • If you use a cloud service provider, you may have opted to use their firewall functionality. Each CSP implements firewall tools differently in order to filter network traffic to and from cloud resources:

  • AWS uses security groups and access control lists

  • Azure uses network security groups and virtual networks

  • GCP uses Google Cloud firewall rules

Common examples of firewall tools that are not cloud specific include:

  • Cisco ASA

  • Fortinet Fortigate

  • Palo Alto Networks Wildfire

Example Evidence

GCP

Azure

Did this answer your question?