Documentation
HECVAT Full v3.0.6
Firewalls, IDS, IPS, and Networking
FIDP-02

Question FIDP-02

Is authority for firewall change approval documented? Please list approver names or titles in Additional Info

Weight20
High RiskNo
RequiredYes
Compliant AnswerYes

Standard Guidance

EDUCAUSE provides no guidance here

Answering "NO"

Describe how firewall changes are approved.

Answering "YES"

List approver names or titles.

Reason for Question

Modifications to firewall rule sets can have significant repercussions. To ensure the integrity of the rule set, this question targets the individual (or responsible party) for changes and the reasoning behind their authority.

Follow-Up Inquiries

Ensure that a separation of duties exists in network security configurations. Pay close attention to responsibility overlap in small organizations, where staff often fill multiple roles.

HECVAT Pro Advice

[Add expert insights and best practices]

Implementation Tips

[Add practical steps for SME SaaS vendors]

FAQ

[Add common questions related to this HECVAT item]

Resources

[Add links to relevant articles or tools]