Firewall security review

Find the firewall rules and architecture decisions that create access you no longer intend.

Damocles Firewall Security Review examines firewall architecture and policy in the context of real routing, NAT, application flows, administrative access and business requirements so risky access can be removed without breaking production.

Architecture and zonesRulebase and objectsNAT and traffic pathsAdministrative access and exceptions
Why customers buy this service

Bring firewall access back to a clear, defensible policy.

A firewall can have thousands of technically valid rules while still failing to enforce the intended security model. Rules become duplicated, broad, stale or shadowed; objects lose ownership; temporary access becomes permanent; and NAT or routing changes create paths the policy reviewer cannot see from the rulebase alone.

Damocles reviews the policy against the intended zones, business flows and network behaviour so the customer can remove unnecessary access, tighten risky rules and identify architecture changes that a simple rule cleanup cannot solve.

01

Reduce unnecessary access

Identify rules, objects and services that are broader or longer-lived than the business requirement.

02

Find hidden policy risk

Identify shadowing, duplicates, stale access, unsafe ANY rules, management exposure and exception debt.

03

Make cleanup safe

Use routing, NAT, hit context, ownership and application dependency to avoid breaking required traffic.

What we review

Firewall architecture, rulebase and traffic-control dependencies in the agreed devices or policy set.

The review can cover one firewall pair, a site, a data-centre policy set or a broader multi-firewall environment.

ZN

Zones and interfaces

Trust zones, interfaces, virtual systems or contexts and the security purpose assigned to each boundary.

RL

Security rules

Source, destination, service, application, user, action, logging and rule-order behaviour.

OB

Objects and groups

Address, service, application and group objects including ownership, duplication and stale entries.

NT

NAT

Source and destination NAT behaviour where translation changes the effective traffic path or policy interpretation.

AD

Administrative access

Management services, permitted sources, administrative authentication and control-plane exposure.

EX

Exceptions

Temporary, emergency, vendor or legacy access that requires an owner, reason and review decision.

Technical assurance

Validate that firewall policy enforces the intended trust model.

Compare rulebases, objects, administration and logging with required traffic flows to identify excessive access, stale policy and control gaps.

Policy intent

Whether rules align with current business and security needs.

Excessive access

Broad sources, destinations, services and permissive actions.

Rule hygiene

Unused, duplicate, shadowed and expired rules.

Objects and groups

Accuracy and maintainability of referenced network objects.

Administrative access

Management-plane exposure, identity and privilege controls.

Change and exceptions

Ownership, approval and expiry of policy changes.

Logging and visibility

Useful records for denied, permitted and administrative activity.

10governed test areas
3authorised testing perspectives
6controlled evidence outputs
12framework / control evidence mappings
What we actually test

Representative technical coverage with the evidence produced.

These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.

Jump to full coverage matrix ↓
Coverage area

Security zones and trust model

Damocles maps interfaces and zones to the intended trust model and identifies ambiguous, overlapping or unintended boundary relationships.

Evidence producedEvidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to security zones and trust model.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Rulebase intent and enforcement

Damocles reviews each sampled rule for source, destination, service or application, action, logging, owner, justification and last-use evidence.

Evidence producedEvidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to rulebase intent and enforcement.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Network and service objects

Damocles resolves network and service objects and groups, identifying overly broad, stale, duplicate, recursive or misleading definitions.

Evidence producedEvidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to network and service objects.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

NAT and published services

Damocles traces source and destination NAT for published and outbound services and compares translated flows with intended exposure.

Evidence producedEvidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to nat and published services.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

Routing and asymmetric paths

Damocles reviews static and dynamic routes, return paths and policy routing for asymmetric or bypass conditions affecting enforcement.

Evidence producedSource-to-destination results linked to rule, route or boundary evidence; the record names the tested routing and asymmetric paths object, path or control and its observed result.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
Coverage area

VPN policy interaction

Damocles traces site-to-site and remote-access VPN traffic through zones, routes and rules to identify unintended policy interaction.

Evidence producedConfiguration excerpts, object or rule identifiers and observed validation results.
Framework references
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Showing 6 representative areas. The full governed matrix contains 10 coverage areas.

Standards and assurance coverage

See how this engagement is structured, classified and mapped before opening the full evidence matrix.

References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.

01 · Test method

How testing is structured

Testing is structured by the governed service profile and the procedures expressly included in the authorised scope.

02 · Finding language

How weaknesses and severity are classified

Findings are reported against the governed service coverage and customer impact. Separate classification references are shown only where they are part of the approved profile.

03 · Control evidence

What maps into compliance and assurance work

12governed evidence mappings across 7 approved frameworks and 9 referenced controls.
4 directly assessed4 supporting evidence4 contextual
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Directly assessed
SC-7

Reviews and tests representative firewall boundary protections across zones, rules, NAT, routes, VPN interactions and approved paths.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Directly assessed
AC-4

Tests representative information-flow decisions by comparing intended source, destination, service or application policy with observed allowed and denied outcomes.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Supporting evidence
AU-2AU-3

Checks sampled firewall logging for security-relevant rule decisions and available event content where supplied.

+ 9 additional governed mappings in the full control matrix.

Jump to full control mapping ↓
04 · Evidence package

What the customer can use after the engagement

A prioritised firewall review with rule-level evidence, risk context, cleanup actions and validation outcomes.

  • Authorised scope and rules of engagement
  • Coverage matrix
  • Retest and residual-risk record
  • + 3 additional controlled outputs

What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.

How we test

Manual validation backed by controlled evidence.

Damocles reviews rulebase, objects, NAT, routing, VPN, management and logging evidence, then validates representative permitted and denied paths where test hosts are supplied. Configuration conclusions remain point-in-time and production changes or disruptive traffic require separate authorisation.

How to read the mapping

Evidence is mapped to the part of a control we can actually assess.

Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.

All relevant frameworks
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Information Security Manual June 2026Prudential Standard CPS 234 Information Security effective 1 July 2019Prudential Practice Guide CPG 234 Information Security published June 2019ISO/IEC 27001 2022 with Amendment 1:2024ISO/IEC 27002 2022Payment Card Industry Data Security Standard 4.0.1
Testing perspectives3 authorised viewpoints and access models

Rulebase and configuration reviewer

Examines zones, rules, objects, NAT, routing, VPN, management and logging configuration.

Included when
Used for the complete firewall configuration review.
Access required
Current native export, diagrams, rule owners and intended flow matrix.
Limitations
A configuration snapshot cannot prove all live traffic outcomes.

Authorised traffic-path validator

Sends approved traffic from supplied sources to representative allowed and denied destinations.

Included when
Used to corroborate selected rule and segmentation decisions.
Access required
Source and destination test hosts, protocols, window and expected result.
Limitations
Only tested paths are established; load and denial-of-service testing are excluded.

Firewall or service owner

Provides rule intent, ownership, last-use and change context for ambiguous or high-risk entries.

Included when
Used where technical configuration lacks sufficient business context.
Access required
Named owners, tickets, usage evidence and exception approvals.
Limitations
Owner statements do not replace configuration or traffic evidence.
Exact test coverage and evidence10 governed coverage areas
What Damocles tests, the evidence produced and the scope boundary for each controlled coverage area.
Coverage areaWhat Damocles testsPerspective and accessEvidence producedReferences and limits
Security zones and trust modelDamocles maps interfaces and zones to the intended trust model and identifies ambiguous, overlapping or unintended boundary relationships.Firewall or service owner
Assessment requires native configuration exports, diagrams, flow intent, rule owners, usage evidence and approved test points, selected specifically for security zones and trust model.
Evidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to security zones and trust model.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Security zones and trust model when the firewall function and supporting evidence are included.

Limit: The conclusion is limited to the sampled security zones and trust model; configuration is point-in-time and only selected live paths are proven; no production change is authorised.

Rulebase intent and enforcementDamocles reviews each sampled rule for source, destination, service or application, action, logging, owner, justification and last-use evidence.Firewall or service owner
Assessment requires native configuration exports, diagrams, flow intent, rule owners, usage evidence and approved test points, selected specifically for rulebase intent and enforcement.
Evidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to rulebase intent and enforcement.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Rulebase intent and enforcement when the firewall function and supporting evidence are included.

Limit: The conclusion is limited to the sampled rulebase intent and enforcement; configuration is point-in-time and only selected live paths are proven; no production change is authorised.

Network and service objectsDamocles resolves network and service objects and groups, identifying overly broad, stale, duplicate, recursive or misleading definitions.Rulebase and configuration reviewer
Assessment requires native configuration exports, diagrams, flow intent, rule owners, usage evidence and approved test points, selected specifically for network and service objects.
Evidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to network and service objects.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Network and service objects when the firewall function and supporting evidence are included.

Limit: The conclusion is limited to the sampled network and service objects; configuration is point-in-time and only selected live paths are proven; no production change is authorised.

NAT and published servicesDamocles traces source and destination NAT for published and outbound services and compares translated flows with intended exposure.Rulebase and configuration reviewer
Assessment requires native configuration exports, diagrams, flow intent, rule owners, usage evidence and approved test points, selected specifically for nat and published services.
Evidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to nat and published services.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to NAT and published services when the firewall function and supporting evidence are included.

Limit: The conclusion is limited to the sampled nat and published services; configuration is point-in-time and only selected live paths are proven; no production change is authorised.

Routing and asymmetric pathsDamocles reviews static and dynamic routes, return paths and policy routing for asymmetric or bypass conditions affecting enforcement.Firewall or service owner
Named source and destination test points, expected flow matrix and a safe test window.
Source-to-destination results linked to rule, route or boundary evidence; the record names the tested routing and asymmetric paths object, path or control and its observed result.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing.

Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity.

VPN policy interactionDamocles traces site-to-site and remote-access VPN traffic through zones, routes and rules to identify unintended policy interaction.Rulebase and configuration reviewer
Current configuration export or read-only access, diagrams, owners and representative validation endpoints.
Configuration excerpts, object or rule identifiers and observed validation results.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when both ends of the network path and the enforcing device are owned or expressly authorised for testing.

Limit: Results cover the tested source, destination, protocol and route; testing stops on instability and does not authorise third-party or denial-of-service activity.

Administrative accessDamocles examines management interfaces, permitted sources, administrator authentication, protocols and separation from data-plane access.Authorised traffic-path validator
Assessment requires native configuration exports, diagrams, flow intent, rule owners, usage evidence and approved test points, selected specifically for administrative access.
Evidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to administrative access.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Administrative access when the firewall function and supporting evidence are included.

Limit: The conclusion is limited to the sampled administrative access; configuration is point-in-time and only selected live paths are proven; no production change is authorised.

Logging and alertingDamocles checks rule logging, event fields, destinations, alert coverage and sampled event receipt for material security decisions.Firewall or service owner
Log-source inventory, representative event identifiers, workflow records and responsible contacts.
Source-health state, event timestamps, investigation timeline and linked action or escalation record.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when the relevant telemetry and analyst or customer workflow can be observed during the review window.

Limit: Absent or delayed telemetry prevents a detection conclusion, and observation of one event cannot prove continuous detection of all attacks.

Unused and shadowed rulesDamocles identifies unused, shadowed, redundant and conflicting rules using configuration, hit-count and ownership evidence.Firewall or service owner
Named source and destination test points, expected flow matrix and a safe test window.
Source-to-destination results linked to rule, route or boundary evidence; the record names the tested unused and shadowed rules object, path or control and its observed result.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Performed when the affected component and representative input are explicitly included in the engagement coverage matrix.

Limit: The conclusion is limited to the sampled unused and shadowed rules; configuration is point-in-time and only selected live paths are proven; no production change is authorised.

Change validation and rollbackDamocles reviews proposed validation, change controls, acceptance criteria and rollback artefacts for material firewall changes.Rulebase and configuration reviewer
Assessment requires native configuration exports, diagrams, flow intent, rule owners, usage evidence and approved test points, selected specifically for change validation and rollback.
Evidence records the zone, rule identifier, object, NAT, route, VPN, log or traffic-path result relevant to change validation and rollback.
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0

Applicability: Applies to Change validation and rollback when the firewall function and supporting evidence are included.

Limit: The conclusion is limited to the sampled change validation and rollback; configuration is point-in-time and only selected live paths are proven; no production change is authorised.

Framework and control mappings12 governed evidence mappings
Where scoped technical evidence maps to approved security frameworks and control objectives.
Framework and controlsMapping typeWhat Damocles assessesEvidence producedApplicability and limits
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
SC-7
Directly assessedReviews and tests representative firewall boundary protections across zones, rules, NAT, routes, VPN interactions and approved paths.Rule and object evidence, boundary and route context, traffic-path validation results and policy identifiers.

Applies: Applies to in-scope firewall enforcement points, zones and representative traffic paths.

Limit: Point-in-time configuration and sampled traffic do not establish every boundary path, alternate route or continuous policy operation.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
AC-4
Directly assessedTests representative information-flow decisions by comparing intended source, destination, service or application policy with observed allowed and denied outcomes.Expected flow matrix, rule identifiers, route or NAT context and source-to-destination results.

Applies: Applies where representative test points and expected traffic policy are supplied.

Limit: Only sampled flows are established; excluded paths and unsampled protocols remain outside the conclusion.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
AU-2AU-3
Supporting evidenceChecks sampled firewall logging for security-relevant rule decisions and available event content where supplied.Representative firewall event records correlated with generated or observed traffic decisions.

Applies: Applies where logging destinations and representative event access are included.

Limit: Does not establish complete event-selection policy, audit-record schema, retention, review process or continuous monitoring.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
CM-6
Supporting evidenceReviews point-in-time firewall configuration settings, policy objects, management exposure, exceptions and change or rollback evidence against intended security design.Configuration excerpts, policy and object identifiers, deviations, ownership context and findings.

Applies: Applies to current native configuration and supporting design or change evidence supplied for review.

Limit: Does not establish the organisation's complete configuration-management process, baseline governance, excluded devices or continuous configuration state.

Information Security Manual June 2026
ISM-0631
Directly assessedTests whether sampled gateway and firewall paths permit only the explicitly authorised data flows represented in the approved flow matrix.Expected flow matrix, rule or policy identifiers, source-to-destination results and exceptions.

Applies: Applies where the in-scope firewall operates as a gateway and representative authorised and denied flows can be validated.

Limit: Only sampled paths are proven and the engagement does not establish every possible gateway data flow or continuous conformity with ISM-0631.

Information Security Manual June 2026
ISM-1774
Directly assessedReviews representative firewall or gateway management interfaces, permitted sources and management-plane reachability against the intended isolated administration path.Management interface configuration, source restrictions and observed reachability or authentication results.

Applies: Applies where gateway administration paths and representative source locations are in scope.

Limit: Does not establish every management path, administrator identity or operational procedure and no production administration is performed.

Information Security Manual June 2026
ISM-0634
Supporting evidenceChecks whether sampled security-relevant gateway traffic and intrusion events are available in the supplied central logging workflow.Representative permitted or denied flow events, alert records and correlated timestamps where available.

Applies: Applies where the firewall is acting as a gateway and central event records are included.

Limit: Sampling does not establish complete event coverage, retention, analysis, alert response or continuous compliance with ISM-0634.

Prudential Standard CPS 234 Information Security effective 1 July 2019
CPS 234 paragraph 27
Supporting evidenceProduces scoped firewall security-review evidence that may support an APRA-regulated entity's systematic testing of information-security control effectiveness.Governed scope, firewall configuration and traffic-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed firewall controls and evidence are applicable to its assurance or compliance scope. For APRA-regulated entities, the customer determines how the engagement contributes to its broader systematic control-testing program.

Limit: A scoped engagement does not by itself establish the customer's systematic testing program, testing frequency, full control population, specialist independence, governance, reporting or compliance with other CPS 234 requirements.

Prudential Practice Guide CPG 234 Information Security published June 2019
Framework-level context
ContextualProduces scoped firewall security-review evidence consistent with CPG 234 guidance that testing techniques should be selected for the control and risk being assessed.Governed scope, firewall configuration and traffic-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed firewall controls and evidence are applicable to its assurance or compliance scope. APRA-regulated customers determine how this evidence contributes to their broader assurance program.

Limit: CPG 234 is prudential guidance rather than a standalone certification target; this mapping does not claim assessment of the complete guidance or customer compliance.

ISO/IEC 27001 2022 with Amendment 1:2024
Framework-level context
ContextualProduces scoped firewall security-review evidence that may support customer assurance activities organised around ISO/IEC 27001 where the assessed systems and behaviours are relevant.Governed scope, firewall configuration and traffic-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed firewall controls and evidence are applicable to its assurance or compliance scope.

Limit: Licensed ISO/IEC 27001 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27001 certification, attestation or whole-framework conformity.

ISO/IEC 27002 2022
Framework-level context
ContextualProduces scoped firewall security-review evidence that may support customer assurance activities organised around ISO/IEC 27002 where the assessed systems and behaviours are relevant.Governed scope, firewall configuration and traffic-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed firewall controls and evidence are applicable to its assurance or compliance scope.

Limit: Licensed ISO/IEC 27002 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27002 certification, attestation or whole-framework conformity.

Payment Card Industry Data Security Standard 4.0.1
Framework-level context
ContextualProduces scoped firewall security-review evidence that may support customer assurance activities organised around PCI DSS where the assessed systems and behaviours are relevant.Governed scope, firewall configuration and traffic-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed firewall controls and evidence are applicable to its assurance or compliance scope.

Limit: Licensed PCI DSS control or requirement identifiers and text are intentionally withheld. The engagement does not establish PCI DSS certification, attestation or whole-framework conformity.

Assurance boundary: Damocles maps assessed coverage and observations to agreed objectives as traceable technical evidence. The review is not a certification, does not establish complete compliance, and does not confirm controls outside the authorised scope.

Report and evidence outputs6 controlled output types

Authorised scope and rules of engagement

Records authorised scope and rules of engagement produced from the authorised Firewall security review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Coverage matrix

Records coverage matrix produced from the authorised Firewall security review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Retest and residual-risk record

Records retest and residual-risk record produced from the authorised Firewall security review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Rulebase and object findings

Records rulebase and object findings produced from the authorised Firewall security review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Traffic-path validation record

Records traffic-path validation record produced from the authorised Firewall security review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Firewall configuration excerpts

Records firewall configuration excerpts produced from the authorised Firewall security review work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.
What you receive

A prioritised firewall review with rule-level evidence, risk context, cleanup actions and validation outcomes.

What we commonly find

Policy conditions that commonly create avoidable exposure or operational debt.

The review distinguishes direct security issues from maintainability problems that make later change unsafe.

AN

Over-broad rules

Large source/destination ranges, excessive services, ANY access or rules that cover more systems than the stated requirement.

ST

Stale access

Rules and objects that no longer have a valid owner, use case or observed need.

SH

Shadowed or duplicate rules

Policy entries that are ineffective, redundant or make the intended control difficult to understand.

MG

Management exposure

Administrative services or control-plane paths reachable from unnecessarily broad networks.

LG

Logging gaps

Material allow/deny decisions without sufficient logging or operational visibility to support investigation.

DP

Dependency risk

Rules that look unnecessary until routing, NAT, load balancers, application tiers or provider dependencies are understood.

Engagement options

Choose the policy set and depth required.

The statement of work identifies devices, virtual contexts, rule counts, exports, architecture data and whether production changes are included.

Focused
FR

Focused firewall review

Review one firewall pair, rule set or high-risk boundary.

Data centre
DC

Data-centre policy review

Review multiple zones, applications and north-south/east-west policy within a data-centre environment.

Enterprise
EP

Enterprise firewall policy review

Review multiple firewalls or sites under a common architecture and rule-governance model.

Cleanup
CL

Rulebase cleanup program

Prioritise stale, duplicate, broad and exception rules for controlled removal or redesign.

What you receive

A firewall review that gives security and network teams a safe cleanup and remediation plan.

The output is tied to the reviewed devices, rules, objects and architecture.

ES

Executive risk summary

Material policy and architecture conditions requiring security or operational decisions.

PF

Policy findings

Affected rules, objects, zones, conditions and remediation guidance.

CL

Cleanup candidates

Rules and objects suitable for removal, consolidation, expiry or owner review.

AR

Architecture observations

Conditions where rule changes alone cannot deliver the intended security boundary.

RP

Prioritised remediation plan

Sequence of policy and architecture changes based on risk, dependency and operational effort.

VR

Validation plan

Expected tests or traffic checks for confirming the changed policy behaves as intended.

Implementation and remediation

Damocles can separately scope the policy cleanup or firewall changes after the review.

Where the customer wants Damocles to implement approved changes, the production work is scoped with change windows, backups, rollback, validation and ownership separate from the assurance review.

This keeps the review clear about what is risky while making the later engineering work safe and auditable.

Scope boundaries

The review covers the approved firewall policy and supporting context available to the engagement.

Application design, endpoint configuration, identity architecture and wider network routing are assessed only where they materially support the agreed firewall scope.

A policy review does not imply production changes unless implementation is expressly included.

Scope the service

Give us the firewall scope, rulebase size and security boundaries you need reviewed.

We will define the required exports, architecture context, review depth, deliverables and whether remediation implementation is included.