Skip to content

Home Expertise / Audits & assessments

AUD / AUD-05

Network, segmentation and firewall audit

A review of communication paths and filtering rules to understand what can reach what and identify unjustified exposure.

WHEN IT HELPS

A focused response
to a defined need.

Network manager; accumulated rules, flat networks, partner interconnections or firewall replacement.

AT A GLANCE

Family
Audits & assessments

Engagement
Assessment

Reference
AUD-05

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Review zones and routing
  • analyse rules and exceptions
  • check administration, logging and critical flows

Deliverables

  • Flow matrix
  • rules requiring review
  • target architecture and change sequence

Acceptance evidence

Proposed changes have an application owner and both allow and deny tests.

DELIVERY

How the work is structured.

Approach

Scope assets and criteria; gather evidence and interviews; validate gaps; present priorities and limitations.

Prerequisites & responsibilities

Customer: inventory, read access, documents and business contacts. Provider: assessment and debrief. Production changes are not included by default.

Scope factors

Sites, assets, technologies and interviews; assessment depth; inventory quality; access constraints; required reporting. One-off project with optional follow-up.

Questions to clarify

Who owns each rule? Which flows are essential? What rollback is available?

IMPORTANT BOUNDARIES

An inactive rule is not necessarily unnecessary; encrypted traffic can limit visibility.

Sampling and observation date are explicit. No assessment certifies the absence of flaws; remediation, penetration testing and recurring follow-up are separate scopes.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A company with three branches has inherited any-to-any rules. Project: reconcile rules, logs and application needs. Target outcome: staged cleanup; a rule with no recent traffic is not removed before checking periodic workloads.

Scenario 02

A hosting provider’s backup network is reachable from workstations. Project: analyse communication paths. Target outcome: a segmentation design and isolation tests for the remediation project.

Technology and reference context

Palo Alto Networks and other firewalls; scoped configuration exports and logs.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.