Best Practices for
Firewall Change Management
Continuous Compliance and Security With Every Change
Large enterprise networks are fluid — IT teams are
adding new users, opening and decommissioning
access and modifying rules daily. With the steady Centralize and Enhance Workflows with
stream of changes cycling through the network, it’s Intelligent Automation
impossible to rely on manual means to ensure that
changes don't compromise security, access or compli- A mix of ticketing systems, emails, spreadsheets
ance, and don't expose vulnerable assets. and eyeballed policy documents is no way to manage
firewall changes on an enterprise scale. You need
Especially amid a cybersecurity skills shortage, en- a fully integrated workflow that ushers tickets
terprises are turning to automation to deliver change through an automated process, adding intelligence
management that matches the speed of their business. at every step.
Automated workflows improve efficiency, reduce
the chance for human error and help continuously Establishing a consistent, automated change workflow
maintain compliance and security standards. through a centralized solution eliminates the chance of
human error that can occur during detail–heavy tasks,
Automation can also help systematically manage rule such as path analysis, risk assessment, tracking, etc.
life cycles to ensure risky rules are regularly evaluated, Benefits of such an approach range from error–free
and firewalls stay clean and optimized. implementation to continuous compliance, secure
firewalls, network optimization and more. Automation
But not all automation is created equal. Firewall
delivers ample business benefits as well. Skybox
change management workflows need to take into
customers who switched from manual methods to the
account the full context of the environment before the
automated workflow described in this guide reported
change is made. Without proper context, automation
an 80 percent reduction in change management time.*
can compound security or compliance issues, increase
the risk of attack and waste resources on rollbacks. WHAT TO LOOK FOR:
The intelligently automated workflow outlined in this • Customizable workflow that integrates with your
best practices guide will ensure that change requests existing ticketing system or otherwise formalizes
are tracked, assessed and implemented as intended change requests
without introducing new risks.
• Correlation of network, policy and risk information
to enhance request data and intelligently guide the
entire change process
*Figures based on deployment analysis. Customer environments consisted of
approximately 150 firewalls. Results may vary.
4 Steps for Secure Firewall Change Management
1 2 3 4
CENTRALIZE USE MODELING ASSESS RISK WITH VERIFY, TRACK
AND ENHANCE AND AUTOMATION FULL CONTEXT AND REPORT
Usher tickets through a Pinpoint firewalls relevant Proactively identify Verify changes are
systematic, integrated to the change in seconds vulnerability exposures, authorized, implemented
change process, adding using automation and policy violations and as intended and tracked
intelligence at each step total network context misconfigurations for audit reporting
Use Network Modeling to Pinpoint Firewalls Assess Risk With Complete Context
Relevant to the Change Obviously, changes need to be assessed for policy
violations, but does your firewall change management
To identify firewalls relevant to a proposed change, process incorporate vulnerability data, too? If the
you need to look at more than just firewall configu- answer is no, changes may actually be increasing your
rations. You need to take into account the complete risk of cyberattack.
context of your current network infrastructure,
including routers, load balancers and NAT/PAT infor- Risk assessments are about more than misconfigura-
mation. Without an automated process, manual path tions and compliance violations — they need to look
analysis can take hours or even days, and the chance for vulnerability exposures as well. Without the cor-
of human error is high. relation of vulnerabilities and threat intelligence to
your network, a seemingly innocuous change could
Automated querying of a comprehensive network open up an attack path to a vulnerable asset. Not only
model reduces this step in the change process to a is this a security concern, it can also cause rollbacks,
matter of seconds, quickly determining the firewalls in creating double work for teams already coping with a
the path and which need to be modified. Aside from lack of resources.
saving time and resources, making changes to only
relevant firewalls will reduce overlapping rulesets and WHAT TO LOOK FOR:
optimize network performance.
• Ability to compare proposed changes against
WHAT TO LOOK FOR: established security policies, both internal and
regulatory compliance standards
• Comprehensive network modeling capabilities
• Risk assessments that check for compliance and
• End–to–end path analysis that includes the current security issues — as well as vulnerability exposures
state of firewalls and other network devices along — before changes go live
the path
Best Practices for Firewall Change Management 2
Next Steps
Verify, Track and Report Implementing these firewall change management
Once changes are made, it's important to ensure the best practices will ensure that firewall changes don’t
change performed was authorized and matches the introduce new security or compliance issues. With
initial request. Additionally, all changes should auto- automated change management capabilities, you
matically be tracked and reported to demonstrate can streamline workflows and keep firewalls clean
compliance with policies, or for on–demand reports to and optimized. Advanced modeling, simulation and
check compliance status at any time. analytics minimize the risk of proposed changes.
And automated verification closes the loop, ensuring
WHAT TO LOOK FOR: the observed change is authorized and matches the
original request.
• Verification that changes are authorized
Skybox™ Security provides a complete line of security
• Third–party validation that the ticket is management solutions to manage changes for
implemented as intended multiple firewall vendors from a centralized platform,
and analyze every change against the full context of
• Out–of–the–box reporting capabilities for
your attack surface in minutes. It gives you the vis-
regulatory compliance standards and
ibility and intelligence you need to make informed
customization for internal policies
security decisions to protect and optimize your
network — even as it changes.
About Skybox Security
Skybox provides the industry’s broadest cybersecurity management platform to address security chal-
lenges within large, complex networks. By integrating with 120 networking and security technologies, the REQUEST A DEMO
Skybox™ Security Suite gives comprehensive attack surface visibility and the context needed for informed
action. Our analytics, automation and intelligence improve the efficiency and performance of security
operations in vulnerability and threat management and firewall and security policy management for the
world’s largest organizations.
[Link] | info@[Link] | +1 408 441 8060
Copyright © 2017 Skybox Security, Inc. All rights reserved. Skybox is a trademark of Skybox Security, Inc. All other
registered or unregistered trademarks are the sole property of their respective owners. 12082017