Network Security Audit Checklist — Free Preview

This free preview includes the perimeter security checklist from the full Network Security Audit guide. The complete guide covers 124 audit items across 8 domains: perimeter, endpoint, identity, cloud, wireless, IoT/OT, incident response, and compliance — with remediation steps and tool recommendations.

Free Preview: Perimeter Security Checklist

PERIMETER SECURITY (20 items)
=============================

[ ] 1. Firewall rules reviewed in last 90 days
[ ] 2. Default-deny policy on all ingress rules
[ ] 3. No any-any firewall rules (source or destination)
[ ] 4. Firewall management access restricted to jump host/VPN
[ ] 5. All public-facing services behind WAF or reverse proxy
[ ] 6. DDoS protection enabled (Cloudflare/AWS Shield/on-prem)
[ ] 7. DNS server version hidden (recursion limited to internal)
[ ] 8. SMTP ports (25/465/587) restricted to mail server IPs only
[ ] 9. RDP/SSH not exposed to internet (use VPN/bastion)
[ ] 10. Port scan detection enabled on IDS/IPS
[ ] 11. Geo-blocking for non-essential countries
[ ] 12. Rate limiting on authentication endpoints
[ ] 13. TLS 1.2+ enforced on all external endpoints
[ ] 14. HSTS header present on all HTTPS services
[ ] 15. Certificate expiry monitoring (alert at 30 days)
[ ] 16. VPN requires MFA
[ ] 17. Split-tunneling disabled for corporate VPN
[ ] 18. IPSec/IKEv2 preferred over legacy VPN protocols
[ ] 19. Guest network isolated from production network
[ ] 20. External vulnerability scan performed quarterly

Tools recommended: Nmap, Nessus, Cloudflare, fail2ban
      

What's in the full guide (124 items, 8 domains):

Download Free Guide — No Email Required

Instant download. 100% free.

Affiliate disclosure: Product links in the full guide include affiliate links. We may earn a commission on purchases at no extra cost to you.