Changes to the hardware or software components of the firewall can have significant effects on the overall security of the network. Therefore, the firewall implementation must be configured to use automated mechanisms to enforce access restrictions and prevent unauthorized changes or upgrades to firewall hardware or software.
Access restrictions may include the following controls.
(i) Physical and logical access controls, workflow automation, and media libraries;
(ii) Abstract layers (e.g., changes are implemented using third party interfaces rather than directly onto the firewall); and
(iii) Change windows (e.g., changes occur only during specified times, making unauthorized changes easy to discover). |