312-50V10 · Question #807
The network team has well-established procedures to follow for creating new rules on the firewall. This includes having approval from a manager prior to implementing any new rules. While reviewing the
The correct answer is D. Immediately roll back the firewall rule until a manager can approve it. Change management procedures should require immediate rollback of any unauthorized firewall rule until proper managerial approval is obtained to preserve policy integrity.
Question
The network team has well-established procedures to follow for creating new rules on the firewall. This includes having approval from a manager prior to implementing any new rules. While reviewing the firewall configuration, you notice a recently implemented rule but cannot locate manager approval for it. What would be a good step to have in the procedures for a situation like this?
Options
- AHave the network team document the reason why the rule was implemented without prior
- BMonitor all traffic using the firewall rule until a manager can approve it.
- CDo not roll back the firewall rule as the business may be relying upon it, but try to get manager
- DImmediately roll back the firewall rule until a manager can approve it
How the community answered
(60 responses)- A3% (2)
- B5% (3)
- C15% (9)
- D77% (46)
Why each option
Change management procedures should require immediate rollback of any unauthorized firewall rule until proper managerial approval is obtained to preserve policy integrity.
Documenting the reason after the fact does not remediate the policy violation or remove the potential security risk introduced by the unapproved rule.
Monitoring traffic through an unapproved rule allows an unauthorized configuration to remain active, which continues to violate change management policy and may expose the network to additional risk.
Leaving the rule active on the assumption that the business relies on it circumvents the approval process and rewards bypassing established change controls, creating a precedent for future violations.
Immediately rolling back the unauthorized rule enforces the change management policy and removes a potentially risky configuration that bypassed required approval controls. This action preserves the integrity of the change control process and eliminates any security exposure introduced by the unapproved rule. The rule can be re-implemented correctly once manager approval is granted and the change is properly documented.
Concept tested: Firewall change management and unauthorized rule remediation
Source: https://csrc.nist.gov/publications/detail/sp/800-41/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.