Reduce unnecessary access
Identify rules, objects and services that are broader or longer-lived than the business requirement.
Damocles Firewall Security Review examines firewall architecture and policy in the context of real routing, NAT, application flows, administrative access and business requirements so risky access can be removed without breaking production.
A firewall can have thousands of technically valid rules while still failing to enforce the intended security model. Rules become duplicated, broad, stale or shadowed; objects lose ownership; temporary access becomes permanent; and NAT or routing changes create paths the policy reviewer cannot see from the rulebase alone.
Damocles reviews the policy against the intended zones, business flows and network behaviour so the customer can remove unnecessary access, tighten risky rules and identify architecture changes that a simple rule cleanup cannot solve.
Identify rules, objects and services that are broader or longer-lived than the business requirement.
Identify shadowing, duplicates, stale access, unsafe ANY rules, management exposure and exception debt.
Use routing, NAT, hit context, ownership and application dependency to avoid breaking required traffic.
The review can cover one firewall pair, a site, a data-centre policy set or a broader multi-firewall environment.
Trust zones, interfaces, virtual systems or contexts and the security purpose assigned to each boundary.
Source, destination, service, application, user, action, logging and rule-order behaviour.
Address, service, application and group objects including ownership, duplication and stale entries.
Source and destination NAT behaviour where translation changes the effective traffic path or policy interpretation.
Management services, permitted sources, administrative authentication and control-plane exposure.
Temporary, emergency, vendor or legacy access that requires an owner, reason and review decision.
Compare rulebases, objects, administration and logging with required traffic flows to identify excessive access, stale policy and control gaps.
Whether rules align with current business and security needs.
Broad sources, destinations, services and permissive actions.
Unused, duplicate, shadowed and expired rules.
Accuracy and maintainability of referenced network objects.
Management-plane exposure, identity and privilege controls.
Ownership, approval and expiry of policy changes.
Useful records for denied, permitted and administrative activity.
These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.
Damocles maps interfaces and zones to the intended trust model and identifies ambiguous, overlapping or unintended boundary relationships.
Damocles reviews each sampled rule for source, destination, service or application, action, logging, owner, justification and last-use evidence.
Damocles resolves network and service objects and groups, identifying overly broad, stale, duplicate, recursive or misleading definitions.
Damocles traces source and destination NAT for published and outbound services and compares translated flows with intended exposure.
Damocles reviews static and dynamic routes, return paths and policy routing for asymmetric or bypass conditions affecting enforcement.
Damocles traces site-to-site and remote-access VPN traffic through zones, routes and rules to identify unintended policy interaction.
Showing 6 representative areas. The full governed matrix contains 10 coverage areas.
References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.
Testing is structured by the governed service profile and the procedures expressly included in the authorised scope.
Findings are reported against the governed service coverage and customer impact. Separate classification references are shown only where they are part of the approved profile.
Reviews and tests representative firewall boundary protections across zones, rules, NAT, routes, VPN interactions and approved paths.
Tests representative information-flow decisions by comparing intended source, destination, service or application policy with observed allowed and denied outcomes.
Checks sampled firewall logging for security-relevant rule decisions and available event content where supplied.
+ 9 additional governed mappings in the full control matrix.
Jump to full control mapping ↓A prioritised firewall review with rule-level evidence, risk context, cleanup actions and validation outcomes.
What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.
Damocles reviews rulebase, objects, NAT, routing, VPN, management and logging evidence, then validates representative permitted and denied paths where test hosts are supplied. Configuration conclusions remain point-in-time and production changes or disruptive traffic require separate authorisation.
Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.
Examines zones, rules, objects, NAT, routing, VPN, management and logging configuration.
Sends approved traffic from supplied sources to representative allowed and denied destinations.
Provides rule intent, ownership, last-use and change context for ambiguous or high-risk entries.
| Coverage area | What Damocles tests | Perspective and access | Evidence produced | References and limits |
|---|---|---|---|---|
| Security zones and trust model | Damocles maps interfaces and zones to the intended trust model and identifies ambiguous, overlapping or unintended boundary relationships. | Firewall or service owner Assessment requires native configuration exports, diagrams, flow intent, rule owners, usage evidence and approved test points, selected specifically for security zones and trust model. | Evidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to security zones and trust model. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Security zones and trust model when the firewall function and supporting evidence are included. Limit: The conclusion is limited to the sampled security zones and trust model; configuration is point-in-time and only selected live paths are proven; no production change is authorised. |
| Rulebase intent and enforcement | Damocles reviews each sampled rule for source, destination, service or application, action, logging, owner, justification and last-use evidence. | Firewall or service owner Assessment requires native configuration exports, diagrams, flow intent, rule owners, usage evidence and approved test points, selected specifically for rulebase intent and enforcement. | Evidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to rulebase intent and enforcement. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Rulebase intent and enforcement when the firewall function and supporting evidence are included. Limit: The conclusion is limited to the sampled rulebase intent and enforcement; configuration is point-in-time and only selected live paths are proven; no production change is authorised. |
| Network and service objects | Damocles resolves network and service objects and groups, identifying overly broad, stale, duplicate, recursive or misleading definitions. | Rulebase and configuration reviewer Assessment requires native configuration exports, diagrams, flow intent, rule owners, usage evidence and approved test points, selected specifically for network and service objects. | Evidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to network and service objects. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Network and service objects when the firewall function and supporting evidence are included. Limit: The conclusion is limited to the sampled network and service objects; configuration is point-in-time and only selected live paths are proven; no production change is authorised. |
| NAT and published services | Damocles traces source and destination NAT for published and outbound services and compares translated flows with intended exposure. | Rulebase and configuration reviewer Assessment requires native configuration exports, diagrams, flow intent, rule owners, usage evidence and approved test points, selected specifically for nat and published services. | Evidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to nat and published services. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to NAT and published services when the firewall function and supporting evidence are included. Limit: The conclusion is limited to the sampled nat and published services; configuration is point-in-time and only selected live paths are proven; no production change is authorised. |
| Routing and asymmetric paths | Damocles reviews static and dynamic routes, return paths and policy routing for asymmetric or bypass conditions affecting enforcement. | Firewall or service owner Named source and destination test points, expected flow matrix and a safe test window. | Source-to-destination results linked to rule, route or boundary evidence; the record names the tested routing and asymmetric paths object, path or control and its observed result. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing. Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity. |
| VPN policy interaction | Damocles traces site-to-site and remote-access VPN traffic through zones, routes and rules to identify unintended policy interaction. | Rulebase and configuration reviewer Current configuration export or read-only access, diagrams, owners and representative validation endpoints. | Configuration excerpts, object or rule identifiers and observed validation results. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing. Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity. |
| Administrative access | Damocles examines management interfaces, permitted sources, administrator authentication, protocols and separation from data-plane access. | Authorised traffic-path validator Assessment requires native configuration exports, diagrams, flow intent, rule owners, usage evidence and approved test points, selected specifically for administrative access. | Evidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to administrative access. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Administrative access when the firewall function and supporting evidence are included. Limit: The conclusion is limited to the sampled administrative access; configuration is point-in-time and only selected live paths are proven; no production change is authorised. |
| Logging and alerting | Damocles checks rule logging, event fields, destinations, alert coverage and sampled event receipt for material security decisions. | Firewall or service owner Log-source inventory, representative event identifiers, workflow records and responsible contacts. | Source-health state, event timestamps, investigation timeline and linked action or escalation record. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when the relevant telemetry and analyst or customer workflow can be observed during the review window. Limit: Absent or delayed telemetry prevents a detection conclusion, and observation of one event cannot prove continuous detection of all attacks. |
| Unused and shadowed rules | Damocles identifies unused, shadowed, redundant and conflicting rules using configuration, hit-count and ownership evidence. | Firewall or service owner Named source and destination test points, expected flow matrix and a safe test window. | Source-to-destination results linked to rule, route or boundary evidence; the record names the tested unused and shadowed rules object, path or control and its observed result. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Performed when the affected component and representative input are explicitly included in the engagement coverage matrix. Limit: The conclusion is limited to the sampled unused and shadowed rules; configuration is point-in-time and only selected live paths are proven; no production change is authorised. |
| Change validation and rollback | Damocles reviews proposed validation, change controls, acceptance criteria and rollback artefacts for material firewall changes. | Rulebase and configuration reviewer Assessment requires native configuration exports, diagrams, flow intent, rule owners, usage evidence and approved test points, selected specifically for change validation and rollback. | Evidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to change validation and rollback. | Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Applicability: Applies to Change validation and rollback when the firewall function and supporting evidence are included. Limit: The conclusion is limited to the sampled change validation and rollback; configuration is point-in-time and only selected live paths are proven; no production change is authorised. |
| Framework and controls | Mapping type | What Damocles assesses | Evidence produced | Applicability and limits |
|---|---|---|---|---|
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 SC-7 | Directly assessed | Reviews and tests representative firewall boundary protections across zones, rules, NAT, routes, VPN interactions and approved paths. | Rule and object evidence, boundary and route context, traffic-path validation results and policy identifiers. | Applies: Applies to in-scope firewall enforcement points, zones and representative traffic paths. Limit: Point-in-time configuration and sampled traffic do not establish every boundary path, alternate route or continuous policy operation. |
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 AC-4 | Directly assessed | Tests representative information-flow decisions by comparing intended source, destination, service or application policy with observed allowed and denied outcomes. | Expected flow matrix, rule identifiers, route or NAT context and source-to-destination results. | Applies: Applies where representative test points and expected traffic policy are supplied. Limit: Only sampled flows are established; excluded paths and unsampled protocols remain outside the conclusion. |
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 AU-2AU-3 | Supporting evidence | Checks sampled firewall logging for security-relevant rule decisions and available event content where supplied. | Representative firewall event records correlated with generated or observed traffic decisions. | Applies: Applies where logging destinations and representative event access are included. Limit: Does not establish complete event-selection policy, audit-record schema, retention, review process or continuous monitoring. |
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 CM-6 | Supporting evidence | Reviews point-in-time firewall configuration settings, policy objects, management exposure, exceptions and change or rollback evidence against intended security design. | Configuration excerpts, policy and object identifiers, deviations, ownership context and findings. | Applies: Applies to current native configuration and supporting design or change evidence supplied for review. Limit: Does not establish the organisation's complete configuration-management process, baseline governance, excluded devices or continuous configuration state. |
| Information Security Manual June 2026 ISM-0631 | Directly assessed | Tests whether sampled gateway and firewall paths permit only the explicitly authorised data flows represented in the approved flow matrix. | Expected flow matrix, rule or policy identifiers, source-to-destination results and exceptions. | Applies: Applies where the in-scope firewall operates as a gateway and representative authorised and denied flows can be validated. Limit: Only sampled paths are proven and the engagement does not establish every possible gateway data flow or continuous conformity with ISM-0631. |
| Information Security Manual June 2026 ISM-1774 | Directly assessed | Reviews representative firewall or gateway management interfaces, permitted sources and management-plane reachability against the intended isolated administration path. | Management interface configuration, source restrictions and observed reachability or authentication results. | Applies: Applies where gateway administration paths and representative source locations are in scope. Limit: Does not establish every management path, administrator identity or operational procedure and no production administration is performed. |
| Information Security Manual June 2026 ISM-0634 | Supporting evidence | Checks whether sampled security-relevant gateway traffic and intrusion events are available in the supplied central logging workflow. | Representative permitted or denied flow events, alert records and correlated timestamps where available. | Applies: Applies where the firewall is acting as a gateway and central event records are included. Limit: Sampling does not establish complete event coverage, retention, analysis, alert response or continuous compliance with ISM-0634. |
| Prudential Standard CPS 234 Information Security effective 1 July 2019 CPS 234 paragraph 27 | Supporting evidence | Produces scoped firewall security-review evidence that may support an APRA-regulated entity's systematic testing of information-security control effectiveness. | Governed scope, firewall configuration and traffic-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed firewall controls and evidence are applicable to its assurance or compliance scope. For APRA-regulated entities, the customer determines how the engagement contributes to its broader systematic control-testing program. Limit: A scoped engagement does not by itself establish the customer's systematic testing program, testing frequency, full control population, specialist independence, governance, reporting or compliance with other CPS 234 requirements. |
| Prudential Practice Guide CPG 234 Information Security published June 2019 Framework-level context | Contextual | Produces scoped firewall security-review evidence consistent with CPG 234 guidance that testing techniques should be selected for the control and risk being assessed. | Governed scope, firewall configuration and traffic-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed firewall controls and evidence are applicable to its assurance or compliance scope. APRA-regulated customers determine how this evidence contributes to their broader assurance program. Limit: CPG 234 is prudential guidance rather than a standalone certification target; this mapping does not claim assessment of the complete guidance or customer compliance. |
| ISO/IEC 27001 2022 with Amendment 1:2024 Framework-level context | Contextual | Produces scoped firewall security-review evidence that may support customer assurance activities organised around ISO/IEC 27001 where the assessed systems and behaviours are relevant. | Governed scope, firewall configuration and traffic-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed firewall controls and evidence are applicable to its assurance or compliance scope. Limit: Licensed ISO/IEC 27001 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27001 certification, attestation or whole-framework conformity. |
| ISO/IEC 27002 2022 Framework-level context | Contextual | Produces scoped firewall security-review evidence that may support customer assurance activities organised around ISO/IEC 27002 where the assessed systems and behaviours are relevant. | Governed scope, firewall configuration and traffic-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed firewall controls and evidence are applicable to its assurance or compliance scope. Limit: Licensed ISO/IEC 27002 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27002 certification, attestation or whole-framework conformity. |
| Payment Card Industry Data Security Standard 4.0.1 Framework-level context | Contextual | Produces scoped firewall security-review evidence that may support customer assurance activities organised around PCI DSS where the assessed systems and behaviours are relevant. | Governed scope, firewall configuration and traffic-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed firewall controls and evidence are applicable to its assurance or compliance scope. Limit: Licensed PCI DSS control or requirement identifiers and text are intentionally withheld. The engagement does not establish PCI DSS certification, attestation or whole-framework conformity. |
Assurance boundary: Damocles maps assessed coverage and observations to agreed objectives as traceable technical evidence. The review is not a certification, does not establish complete compliance, and does not confirm controls outside the authorised scope.
Records authorised scope and rules of engagement produced from the authorised Firewall security review work.
Records coverage matrix produced from the authorised Firewall security review work.
Records retest and residual-risk record produced from the authorised Firewall security review work.
Records rulebase and object findings produced from the authorised Firewall security review work.
Records traffic-path validation record produced from the authorised Firewall security review work.
Records firewall configuration excerpts produced from the authorised Firewall security review work.
A prioritised firewall review with rule-level evidence, risk context, cleanup actions and validation outcomes.
The review distinguishes direct security issues from maintainability problems that make later change unsafe.
Large source/destination ranges, excessive services, ANY access or rules that cover more systems than the stated requirement.
Rules and objects that no longer have a valid owner, use case or observed need.
Policy entries that are ineffective, redundant or make the intended control difficult to understand.
Administrative services or control-plane paths reachable from unnecessarily broad networks.
Material allow/deny decisions without sufficient logging or operational visibility to support investigation.
Rules that look unnecessary until routing, NAT, load balancers, application tiers or provider dependencies are understood.
The statement of work identifies devices, virtual contexts, rule counts, exports, architecture data and whether production changes are included.
Review one firewall pair, rule set or high-risk boundary.
Review multiple zones, applications and north-south/east-west policy within a data-centre environment.
Review multiple firewalls or sites under a common architecture and rule-governance model.
Prioritise stale, duplicate, broad and exception rules for controlled removal or redesign.
The output is tied to the reviewed devices, rules, objects and architecture.
Material policy and architecture conditions requiring security or operational decisions.
Affected rules, objects, zones, conditions and remediation guidance.
Rules and objects suitable for removal, consolidation, expiry or owner review.
Conditions where rule changes alone cannot deliver the intended security boundary.
Sequence of policy and architecture changes based on risk, dependency and operational effort.
Expected tests or traffic checks for confirming the changed policy behaves as intended.
Where the customer wants Damocles to implement approved changes, the production work is scoped with change windows, backups, rollback, validation and ownership separate from the assurance review.
This keeps the review clear about what is risky while making the later engineering work safe and auditable.
Application design, endpoint configuration, identity architecture and wider network routing are assessed only where they materially support the agreed firewall scope.
A policy review does not imply production changes unless implementation is expressly included.
We will define the required exports, architecture context, review depth, deliverables and whether remediation implementation is included.