3.1 Ensure that unused policies are reviewed regularly

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

All firewall policies should be reviewed regularly to verify the business purpose. Unused policies should be disabled and logged.

Rationale:

By reviewing policies regularly, we can determine if the policies are still needed by the business purpose. Thus, we can keep the firewall policies lean and efficient. It also prevents traffic being allowed or blocked accidently.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

The remediation is to review and decide if you should delete unused policies.

Default Value:

By default, the hit count value is obviously 0 at the beginning.

See Also

https://workbench.cisecurity.org/files/4077

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-9

Plugin: FortiGate

Control ID: dc8178417652c6f5b65ad8200cf550debc6b0bdea280b8943aec04afd1319f7b