Rule Bases Only Grow
Every firewall accumulates rules over time: a temporary exception for a project, a rule added during an incident at 2 a.m., a permit that outlived the system it protected. Almost nothing ever gets removed, because removing a rule feels riskier than leaving it. The result is a bloated, poorly understood policy that widens your attack surface and makes every future change harder to reason about.
The Management View
Auditors and frameworks (PCI DSS, ISO 27001, NIST) increasingly expect evidence of periodic firewall rule review. But the real value isn't the checkbox: it's that a disciplined review forces two questions on every rule, does this still serve a legitimate business need, and is it as tight as it should be. Those questions, asked regularly, keep the policy lean and defensible.
Making Reviews Sustainable
The reason reviews fail is that they're treated as one big annual project instead of a routine. A lightweight, tracked process works far better:
- Record a business justification and an owner for every rule, since a rule no one will claim is a rule you can safely retire.
- Assign each rule a review cycle and track the next-due date so overdue rules surface automatically.
- Flag any-any and overly broad rules for tightening rather than blanket removal.
- Keep a decision log (keep / tighten / remove) so the next review starts where this one ended.
The attached template, 02: Firewall Rule Base Review Tracker, is a rule-base register with justification, owner, review cycle and an automatic next-review date, plus a running count of overdue rules and a decision column. It gives you both the working tool and the audit evidence in one place.
