Reply to post: One time for an audit

See that last line in the access list? Yeah, that means you don't have an access list

tip pc Silver badge

One time for an audit

Before our annual audit we where instructed to remove occurrences of ‘any’ in the policy.

There are occasions where you might want an any, I.e you may want all clients to the proxy or to ad, dns, av, ntp etc.

Auditors typically don’t understand the technology and back then just looked for keywords like any.

So I put in an inverse rule, effectively permit any source other than a made up range to dst on specific ports.

The auditor was happy with that despite it effectively being an any.

That’s when I realised management and expensive auditors cared more about ticking boxes than actual intent behind the requirement.

Been the same ever since.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon