Skip to main content
Category: Technical Security Controls

Firewall

Also known as: network firewall
Simply put

A firewall is a network security device or service that monitors and controls the traffic entering and leaving a network based on a set of security rules. It typically acts as a barrier between a trusted internal network and an untrusted external network such as the internet, helping to block cyber threats and protect sensitive data. Its purpose is to safeguard the network from intentional or unintentional intrusion.

Formal definition

A firewall is a network security device, application, or service that monitors, filters, and controls incoming and outgoing network traffic based on predetermined security rules. It commonly enforces a boundary between a trusted internal network and an external network deemed untrustworthy, permitting or denying traffic according to an organization's established policy. In a compliance context, firewalls typically serve as a technical control supporting network protection and access restriction; the specific configuration, rule sets, and scope depend on the environment and are evaluated against the applicable criteria or controls of the relevant framework.

Why it matters

Firewalls are among the most widely relied-upon technical controls for enforcing a boundary between a trusted internal network and untrusted external networks such as the internet. By monitoring and filtering incoming and outgoing traffic against predetermined security rules, they help block cyber threats and protect sensitive data, which is why they frequently appear as evidence when organizations demonstrate network protection and access restriction to auditors and certification bodies.

In a SOC 2 examination, a firewall is typically examined as part of the controls supporting the Security category (the Common Criteria), where the CPA firm assesses whether such controls are suitably designed and, in a Type II engagement, whether they operated effectively over the defined review period. In an ISO/IEC 27001 context, firewall-related controls are selected through the Statement of Applicability and informed by the organization's risk assessment, with the specific reference controls depending on the version of Annex A in use. In both frameworks, the value of a firewall lies in how it is configured, maintained, and evidenced rather than in its mere presence.

It is important to recognize the limits of this control. A firewall attests only to the traffic-filtering behavior enforced by its rule set and scope; it does not by itself guarantee freedom from breaches, nor does its deployment satisfy the full range of criteria or controls in either framework. A SOC 2 report speaks only to the controls and period covered, and an ISO 27001 certificate covers only the defined scope of the ISMS, so a firewall must be understood as one element within a broader control environment.

Who it's relevant to

Compliance Managers
Compliance managers coordinate the evidence that demonstrates a firewall supports network protection and access restriction. Because the specific configuration and scope depend on the environment, they typically need to map firewall controls to the applicable criteria in a SOC 2 examination or, for ISO 27001, to the controls selected in the Statement of Applicability.
Auditors and Assessors
For a SOC 2 engagement, the CPA firm evaluates whether firewall controls are suitably designed and, in a Type II engagement, whether they operated effectively over the defined review period. Assessors examine the rule sets and configuration against the applicable Trust Services Criteria or, in an ISO 27001 audit, against the selected Annex A reference controls.
Security Engineers
Security engineers configure and maintain the firewall's rule sets that enforce the boundary between trusted internal networks and untrusted external networks. They are responsible for ensuring the predetermined rules reflect the organization's policy and produce the evidence that filtering behavior operates as intended.
GRC Professionals
GRC professionals position the firewall within the broader control environment, recognizing that it addresses network protection but does not by itself satisfy any framework or guarantee freedom from breaches. They help ensure its scope aligns with the boundaries covered by a SOC 2 report or an ISO 27001 ISMS certification.

Inside Firewall

Network Firewall
A control that filters inbound and outbound network traffic based on defined rulesets, typically deployed at network boundaries to enforce segmentation between trusted and untrusted zones.
Ruleset / Access Control List
The configured set of allow and deny rules that determine which traffic is permitted, forming the enforceable logic of the firewall and the primary artifact reviewed during an assessment.
Default-Deny Posture
A configuration principle whereby traffic is blocked unless explicitly permitted, commonly expected in most engagements to demonstrate restrictive access control.
Logging and Monitoring Capability
The firewall's ability to record permitted and denied connections, supporting detection, investigation, and evidence that the control operated over a review period.
Change Management Linkage
The processes governing how firewall rules are requested, approved, and modified, which auditors typically examine to confirm the control is maintained rather than static.
Relationship to Framework Criteria
In SOC 2, a firewall commonly supports the Security category (Common Criteria) related to logical and boundary protection; under ISO 27001, it may map to relevant Annex A reference controls selected via the Statement of Applicability, depending on the applicable version and scope.

Common questions

Answers to the questions practitioners most commonly ask about Firewall.

Does having a firewall satisfy the SOC 2 or ISO 27001 requirements on its own?
No. A firewall is one technical control among many, and neither framework treats any single control as sufficient by itself. In a SOC 2 examination, a firewall may serve as evidence supporting the Security (Common Criteria) category, but the CPA firm evaluates the broader control environment. In ISO 27001, firewalls typically relate to reference controls in Annex A, which are selected via the Statement of Applicability and informed by risk assessment; the certifiable requirements themselves reside in clauses 4 through 10. Whether a firewall is expected at all depends on scope and the results of your risk assessment.
Is a specific firewall configuration mandatory for passing a SOC 2 or ISO 27001 audit?
Not universally. Neither framework prescribes a particular firewall product, ruleset, or configuration. In most engagements the auditor or certification body assesses whether the controls you have implemented are suitably designed and, for a SOC 2 Type II or an operating ISMS, operating effectively over the relevant period. The appropriate configuration depends on your scope, risk assessment, and the criteria selected, rather than a fixed mandatory standard.
How should firewall rules be documented for audit evidence?
Documentation typically includes the ruleset itself, the business justification for rules, ownership, and records of review and approval. For a SOC 2 Type II engagement, evidence usually needs to demonstrate that controls operated over the defined review period, so retaining change records across that period is generally advisable. For ISO 27001, documentation should align with what your Statement of Applicability and risk assessment indicate is relevant. Exact expectations vary by auditor, certification body, and scope.
How often should firewall rules be reviewed?
There is no single fixed frequency required across all engagements. Many organizations conduct periodic reviews to confirm that rules remain necessary and correctly scoped, with the cadence driven by their own policy and risk assessment. Auditors and certification bodies typically look for evidence that reviews occur consistently and are documented, rather than mandating a specific interval. The appropriate frequency depends on scope, risk, and applicable criteria.
Who should be responsible for firewall change management?
Responsibility is usually assigned to defined roles within your change management process, with separation of duties considered where feasible. Both frameworks generally expect that changes are authorized, tested where appropriate, and documented. The specific assignment depends on your organizational structure and the controls you have implemented; neither framework prescribes a particular role, so this should reflect your own policy and risk decisions.
How do firewall controls map between SOC 2 and ISO 27001?
Firewall-related controls can often be referenced against both frameworks, but the mapping is partial. In SOC 2, firewalls may support the Security (Common Criteria) category; in ISO 27001, they typically relate to Annex A reference controls selected through the Statement of Applicability. Satisfying firewall expectations in one framework does not automatically satisfy the other, because the criteria, evidence expectations, and assessment approach differ. Any cross-mapping should be validated against the specific scope and applicable criteria of each engagement.

Common misconceptions

Deploying a firewall is a mandatory control that satisfies a SOC 2 or ISO 27001 requirement on its own.
Neither framework mandates a firewall as a specific product. SOC 2 evaluates whether controls meet the applicable Trust Services Criteria, and ISO 27001 requires controls to be selected via risk assessment and documented in the Statement of Applicability. A firewall is one common way to address boundary protection, but the assessed outcome depends on scope, the auditor, and the certification body.
A firewall passing review in a SOC 2 examination guarantees the network is secure and free from breaches.
A SOC 2 report attests only to the controls and the period covered. For a Type II engagement it addresses design and operating effectiveness over a defined review period, and for a Type I it addresses suitability of design at a point in time; it does not guarantee freedom from breaches.
Configuring a firewall correctly for ISO 27001 automatically satisfies the equivalent SOC 2 requirement.
Mapping between the two frameworks is possible but partial. Satisfying a firewall-related control under one framework does not automatically satisfy the other, because the criteria, evidence expectations, and assessment approaches differ.

Best practices

Adopt a default-deny posture and explicitly justify each permitted rule so that the ruleset can be traced to a business or security need during assessment.
Document firewall changes through your change management process, retaining approvals so evidence of operating effectiveness is available across a SOC 2 Type II review period.
Conduct periodic reviews of firewall rules to remove stale or overly permissive entries, with the review cadence set according to your scope and risk assessment.
Enable and retain logging of permitted and denied traffic to support monitoring, investigation, and evidence collection.
Map firewall controls to the applicable framework requirements, noting them against the Security (Common Criteria) category for SOC 2 and, for ISO 27001, recording their selection in the Statement of Applicability against the relevant Annex A reference controls for the version in use.
Define the firewall's role within the documented ISMS or system boundary so its coverage aligns with the defined scope of the certification or examination.