Network Security Audit Checklist — Free Preview
This free preview includes the perimeter security checklist from the full Network Security Audit guide. The complete guide covers 124 audit items across 8 domains: perimeter, endpoint, identity, cloud, wireless, IoT/OT, incident response, and compliance — with remediation steps and tool recommendations.
Free Preview: Perimeter Security Checklist
PERIMETER SECURITY (20 items)
=============================
[ ] 1. Firewall rules reviewed in last 90 days
[ ] 2. Default-deny policy on all ingress rules
[ ] 3. No any-any firewall rules (source or destination)
[ ] 4. Firewall management access restricted to jump host/VPN
[ ] 5. All public-facing services behind WAF or reverse proxy
[ ] 6. DDoS protection enabled (Cloudflare/AWS Shield/on-prem)
[ ] 7. DNS server version hidden (recursion limited to internal)
[ ] 8. SMTP ports (25/465/587) restricted to mail server IPs only
[ ] 9. RDP/SSH not exposed to internet (use VPN/bastion)
[ ] 10. Port scan detection enabled on IDS/IPS
[ ] 11. Geo-blocking for non-essential countries
[ ] 12. Rate limiting on authentication endpoints
[ ] 13. TLS 1.2+ enforced on all external endpoints
[ ] 14. HSTS header present on all HTTPS services
[ ] 15. Certificate expiry monitoring (alert at 30 days)
[ ] 16. VPN requires MFA
[ ] 17. Split-tunneling disabled for corporate VPN
[ ] 18. IPSec/IKEv2 preferred over legacy VPN protocols
[ ] 19. Guest network isolated from production network
[ ] 20. External vulnerability scan performed quarterly
Tools recommended: Nmap, Nessus, Cloudflare, fail2ban
What's in the full guide (124 items, 8 domains):
- 20 Perimeter security items (firewall, WAF, DNS, TLS)
- 25 Endpoint security items (EDR, patching, hardening)
- 15 Identity & access items (MFA, RBAC, privilege review)
- 20 Cloud security items (IAM, storage, network, logging)
- 15 Wireless security items (WPA3, rogue AP, guest isolation)
- 10 IoT/OT security items (segmentation, firmware, monitoring)
- 10 Incident response items (runbooks, tabletop, forensics)
- 9 Compliance items (NIST, ISO 27001, CIS, SOC 2)
Download Free Guide — No Email Required
Instant download. 100% free.
Affiliate disclosure: Product links in the full guide include affiliate links. We may earn a commission on purchases at no extra cost to you.