![Enterprise Cloud Security and Governance](https://wfqqreader-1252317822.image.myqcloud.com/cover/344/36700344/b_36700344.jpg)
上QQ阅读APP看书,第一时间看更新
Best practices
These are the best practices regarding tracking firewall changes:
- Always implement the approach of DENY ALL and ALLOW some for the firewalls
- Avoid the rule of 0.0.0.0/0 in the firewall, with a set of exceptions, such as HTTP or HTTPS port, which can be justified
- There should be a firewall justification document that contains each and every firewall rule along with the justification for why that rule is needed
- Set up alarms that will alert the Security Team whenever there are any changes to the firewall