Network Security Controls for IS Auditors
The auditor doesn't configure the firewall. The job is to check its rules are justified, reviewed, logged and tested.
Network controls decide who and what can reach a system before any login screen appears. A well-controlled ERP is still exposed if its database port is reachable from the branch Wi-Fi, or if a vendor's VPN account gives access to the whole internal network.
DISA Module 5 covers network threats, network and wireless security, endpoints, vulnerability assessment and penetration testing (VAPT), and how to monitor and audit all of it. The auditor rarely configures anything; the job is to check that the design follows the organisation's risk assessment and that the rules are reviewed, logged and tested.
You save ₹450
- Full-length timed mocks
- Module-wise practice
- Emerging-tech coverage
One payment, no subscription · Valid for 2 months
Firewall Types Compared
A firewall is a device or software that allows or blocks traffic between networks based on rules.
Packet filtering
What it inspects
Source and destination address, port and protocol of each packet
Strength
Fast, simple
Limitation
No awareness of sessions or content
Stateful inspection
What it inspects
Packets in the context of the connection they belong to
Strength
Blocks packets that don't belong to an established session
Limitation
Still does not read application content
Application-level gateway (proxy)
What it inspects
The application traffic itself, acting as an intermediary
Strength
Fine-grained control and logging per application
Limitation
Slower; one proxy per protocol
Next-generation firewall
What it inspects
Applications, users and content, often with built-in intrusion prevention
Strength
Combines several layers in one device
Limitation
Complex rule sets that drift without review
| Type | What it inspects | Strength | Limitation |
|---|---|---|---|
| Packet filtering | Source and destination address, port and protocol of each packet | Fast, simple | No awareness of sessions or content |
| Stateful inspection | Packets in the context of the connection they belong to | Blocks packets that don't belong to an established session | Still does not read application content |
| Application-level gateway (proxy) | The application traffic itself, acting as an intermediary | Fine-grained control and logging per application | Slower; one proxy per protocol |
| Next-generation firewall | Applications, users and content, often with built-in intrusion prevention | Combines several layers in one device | Complex rule sets that drift without review |
Other Controls in the Module
- DMZ (demilitarised zone)
- A separate network segment for internet-facing servers (website, mail gateway), so a compromise there does not open the internal network.
- Network segmentation
- Splitting the internal network so, for example, branch user machines cannot reach core banking database servers directly.
- IDS
- Intrusion detection system: watches traffic and alerts on suspicious patterns. Detective.
- IPS
- Intrusion prevention system: sits in the traffic path and blocks what it judges malicious. Preventive, and can block legitimate traffic if badly tuned.
- VPN
- Virtual private network: an encrypted tunnel over a public network, used for remote staff and vendor access.
- Vulnerability assessment
- A scan that lists known weaknesses across many systems. Broad, mostly automated.
- Penetration test
- A controlled attempt to exploit weaknesses, showing what an attacker could actually reach. Deeper, narrower, needs written authorisation and rules of engagement.
Quick practice on audit concepts. No signup.
What the Auditor Reviews
- checkAn up-to-date network diagram that matches the devices actually in use
- checkFirewall rule base: each rule has a business owner and justification; no "any to any" rules; rules reviewed periodically and unused ones removed
- checkChanges to firewall and router configuration go through change management
- checkRemote and vendor access via VPN with multi-factor authentication, limited to the systems needed, and disabled when the contract ends
- checkWireless networks use current encryption, guest Wi-Fi is separated from the corporate network
- checkIDS/IPS alerts reach someone who acts on them; logs are retained (CERT-In's Directions require logs of all ICT systems for a rolling 180 days within India)
- checkVAPT done periodically and after major changes, with findings tracked to closure and retested
How the DISA Assessment Test Tests This
Expect definitional MCQs that hinge on one word and scenario MCQs asking for the best control. Classic pairs to keep straight: IDS detects while IPS prevents; vulnerability assessment finds weaknesses while a penetration test exploits them; stateful firewalls track sessions while packet filters don't.
The trap in scenario questions is picking a stronger technology when the stem describes a governance gap. If the firewall exists but rules have never been reviewed, the answer is a periodic rule review with owner sign-off, not buying a next-generation firewall.
FAQs
What is the difference between IDS and IPS?expand_more
An IDS monitors traffic and raises alerts but does not stop it (detective). An IPS sits in the traffic path and blocks traffic it judges malicious (preventive).
What is the difference between vulnerability assessment and penetration testing?expand_more
A vulnerability assessment scans for and lists known weaknesses. A penetration test goes further and tries to exploit them to show real impact. Together they are called VAPT.
What does an IS auditor check in a firewall review?expand_more
That every rule has a documented business reason and owner, overly broad rules are removed, changes follow change management, the rule base is reviewed periodically, and logs are kept and monitored.
Why put servers in a DMZ?expand_more
Internet-facing servers are the most attacked. Isolating them in a DMZ means a compromised web server does not give the attacker a direct path into the internal network.
Next steps
- Logical Accessarrow_forward
- Physical Controlsarrow_forward
- Cryptographyarrow_forward
- Syllabusarrow_forward
Assessment Test format, timed and scored.
