Skip to content

docs(plugin): add manual validation guidance for security policy compliance (SANS-FW-011) #507

@unclesp1d3r

Description

@unclesp1d3r

Summary

SANS-FW-011 (Security Policy Compliance) always returns UNKNOWN because this is a procedural/organizational control that requires manual verification against the organization's security policy.

Suggested Manual Validation Steps

1. Obtain the organization's firewall security policy document
2. Compare current ruleset against documented policy requirements
3. Verify policy review schedule (annual minimum per SANS checklist)
4. Confirm policy change management process is followed
5. Check that policy exceptions are documented and approved

Related

Metadata

Metadata

Assignees

No one assigned

    Labels

    audit-modeRelated to audit and compliance functionalitycomplianceCompliance scanning and audit featuresdocumentationImprovements or additions to documentationpriority:normalNormal priority issuesp:1Story Points: 1 (trivial)

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions