Cyber Insurance Subjectivity Tracker

Controls / Other controls proposal forms ask about

Every device sits behind a correctly configured boundary or host firewall, with inbound rules signed off and unused rules removed

What the applicant reports, the rules behind it in each jurisdiction, and the evidence an assessor asks for. In the applicant's words: put every device behind a configured boundary or host firewall, and remove unused rules.

In Australia

No Essential Eight requirement covers this control; in Australia it is on the schedule as a condition beyond the core list.

In the United States

ClauseThe held text, and the evidence an assessor asks for
CIS 4.4
CIS Controls v8.1
Implement and Manage a Firewall on Servers

Where servers support it, run and manage a firewall on them, for example a virtual firewall, the operating system's own firewall, or a firewall agent from a third party.

evidence an assessor asks for Server firewall policy configuration showing default-deny rules; Compliance report of server firewall status across the server estate; Host firewall rule sets for sampled servers showing inbound allowed only for required services; Cloud security group or virtual firewall rules for server workloads with the rule owner recorded; Change tickets for server firewall rule changes with approval

CIS 4.5
CIS Controls v8.1
Implement and Manage a Firewall on End-User Devices

On end-user devices, run and manage a firewall on the host or a tool that filters ports, set to deny by default so that all traffic is dropped apart from explicitly permitted services and ports.

evidence an assessor asks for End-user device firewall policy with default-deny and explicitly allowed ports; Endpoint compliance report of firewall status; Endpoint firewall profile settings showing default inbound block on domain, private and public networks; List of explicitly permitted ports and services with the business reason for each; Report of endpoints where users have disabled the firewall and the remediation raised

In United Kingdom

ClauseThe held text, and the evidence an assessor asks for
CE-FW.1
Cyber Essentials
Boundary Firewalls Deployed

Every device in scope must be protected by a correctly configured firewall (or network device with firewall functionality) at the boundary of the internet connection.

evidence an assessor asks for firewall device list; topology diagram showing boundary; rule base export

CE-FW.4
Cyber Essentials
Approve and Document Inbound Rules

Every inbound firewall rule that permits traffic must be approved and documented by an authorised individual with documented business need.

evidence an assessor asks for firewall change tickets; rule register with owner/justification; approval workflow evidence

CE-FW.5
Cyber Essentials
Remove or Disable Unused Rules

Remove or disable permissive firewall rules promptly when no longer required to limit attack surface.

evidence an assessor asks for periodic firewall rule review records; disabled/removed rule log

CE-FW.6
Cyber Essentials
Host-Based Firewall for Remote Workers

Where devices are used on untrusted networks (home, public Wi-Fi), the host-based software firewall must be enabled and configured.

evidence an assessor asks for endpoint firewall policy; MDM compliance report; sample screenshots

Questions

What does the applicant report for this control?
Whether it is in place, partly in place, not in place or not sure. Partly, not in place and not sure are gaps; not sure reads as a question.
When is it due on the 90-day schedule?
Day 60 by the default rule for a core line, day 90 when it is beyond the core list for the jurisdiction or marked not sure. The underwriter or broker can move it.
Does this page check the control?
No. The applicant reports a closure with a date and a note; the schedule records it as reported and never checks it.

Put this control on a schedule