CIS Sophos Firewall Benchmark

Secure configuration guidelines for Sophos Firewall (SFOS)

v1.0.0 December 2024

Overview

▶

This CIS Benchmark provides prescriptive guidance for establishing a secure configuration posture for Sophos Firewall. Recommendations cover system configuration, authentication, firewall rules, VPN configuration, web protection, and logging and monitoring.

~90Recommendations
6Sections
2Profile Levels
SectionAreaFocus
1System ConfigHostname, firmware, zones
2AuthenticationAdmin, RADIUS/LDAP, MFA
3Firewall RulesPolicies, IPS, app control
4VPNIPsec, SSL VPN
5Web ProtectionFiltering, WAF, HTTPS
6LoggingSyslog, alerts, Sophos Central

Profile Definitions

▶
ProfileDescriptionIntended Use
L1Level 1 — StandardEssential security for all Sophos Firewall deployments; minimal performance impact.
L2Level 2 — HardenedAdvanced hardening for PCI-DSS, HIPAA, or high-security environments.

1 — System Configuration

▶

1.1 General Settings

▶
1.1.1 Ensure Hostname Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Hostname Is Configured on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Hostname Is Configured. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Hostname Is Configured. Navigate to the relevant section, apply the setting, and save the configuration.

1.1.2 Ensure Admin Port Is Changed from Default (Automated)
L1 Auto
Description

This recommendation verifies that Admin Port Is Changed from Default on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Admin Port Is Changed from Default. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Admin Port Is Changed from Default. Navigate to the relevant section, apply the setting, and save the configuration.

1.1.3 Ensure Firmware Is Updated to Latest Supported Version (Manual)
L1 Manual
Description

This recommendation verifies that Firmware Is Updated to Latest Supported Version on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Firmware Is Updated to Latest Supported Version. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Firmware Is Updated to Latest Supported Version. Navigate to the relevant section, apply the setting, and save the configuration.

1.1.4 Ensure Device Access Profiles Are Configured (Automated)
L1 Auto
Description

This recommendation verifies that Device Access Profiles Are Configured on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Device Access Profiles Are Configured. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Device Access Profiles Are Configured. Navigate to the relevant section, apply the setting, and save the configuration.

1.1.5 Ensure NTP Is Configured with Authenticated Time Source (Automated)
L1 Auto
Description

This recommendation verifies that NTP Is Configured with Authenticated Time Source on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that NTP Is Configured with Authenticated Time Source. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure NTP Is Configured with Authenticated Time Source. Navigate to the relevant section, apply the setting, and save the configuration.

1.2 Network Interfaces

▶
1.2.1 Ensure Management Interface Is on Dedicated Zone (Automated)
L1 Auto
Description

This recommendation verifies that Management Interface Is on Dedicated Zone on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Management Interface Is on Dedicated Zone. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Management Interface Is on Dedicated Zone. Navigate to the relevant section, apply the setting, and save the configuration.

1.2.2 Ensure Unused Interfaces Are Disabled (Automated)
L1 Auto
Description

This recommendation verifies that Unused Interfaces Are Disabled on the Sophos Firewall network security appliance. Using the recommended component or protocol ensures alignment with security best practices and reduces risk.

Rationale

Using an insecure or legacy component instead of the recommended approach increases the risk of compromise. Ensuring the Sophos Firewall network security appliance uses the correct component aligns with industry best practices and standards.

Audit

Log in to the Sophos web admin console and verify that Unused Interfaces Are Disabled. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Unused Interfaces Are Disabled. Navigate to the relevant section, apply the setting, and save the configuration.

1.2.3 Ensure DNS Settings Use Trusted Resolvers (Automated)
L1 Auto
Description

This recommendation verifies that DNS Settings Use Trusted Resolvers on the Sophos Firewall network security appliance. Using the recommended component or protocol ensures alignment with security best practices and reduces risk.

Rationale

Using an insecure or legacy component instead of the recommended approach increases the risk of compromise. Ensuring the Sophos Firewall network security appliance uses the correct component aligns with industry best practices and standards.

Audit

Log in to the Sophos web admin console and verify that DNS Settings Use Trusted Resolvers. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure DNS Settings Use Trusted Resolvers. Navigate to the relevant section, apply the setting, and save the configuration.

1.2.4 Ensure Zone Isolation Is Properly Configured (Automated)
L1 Auto
Description

This recommendation verifies that Zone Isolation Is Properly Configured on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Zone Isolation Is Properly Configured. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Zone Isolation Is Properly Configured. Navigate to the relevant section, apply the setting, and save the configuration.

2 — Authentication

▶

2.1 Administrator Authentication

▶
2.1.1 Ensure Default Admin Password Is Changed (Manual)
L1 Manual
Description

This recommendation verifies that Default Admin Password Is Changed on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Default Admin Password Is Changed. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Default Admin Password Is Changed. Navigate to the relevant section, apply the setting, and save the configuration.

2.1.2 Ensure Multi-Factor Authentication Is Enabled for Admins (Automated)
L1 Auto
Description

This recommendation verifies that Multi-Factor Authentication Is Enabled for Admins on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Multi-Factor Authentication Is Enabled for Admins. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Multi-Factor Authentication Is Enabled for Admins. Navigate to the relevant section, apply the setting, and save the configuration.

2.1.3 Ensure Admin Session Timeout Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Admin Session Timeout Is Configured on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Admin Session Timeout Is Configured. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Admin Session Timeout Is Configured. Navigate to the relevant section, apply the setting, and save the configuration.

2.1.4 Ensure Login Lockout Policy Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Login Lockout Policy Is Configured on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Login Lockout Policy Is Configured. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Login Lockout Policy Is Configured. Navigate to the relevant section, apply the setting, and save the configuration.

2.2 User Authentication

▶
2.2.1 Ensure RADIUS or LDAP Authentication Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that RADIUS or LDAP Authentication Is Configured on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that RADIUS or LDAP Authentication Is Configured. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure RADIUS or LDAP Authentication Is Configured. Navigate to the relevant section, apply the setting, and save the configuration.

2.2.2 Ensure Captive Portal Authentication Is Configured for Guest Networks (Automated)
L1 Auto
Description

This recommendation verifies that Captive Portal Authentication Is Configured for Guest Networks on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Captive Portal Authentication Is Configured for Guest Networks. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Captive Portal Authentication Is Configured for Guest Networks. Navigate to the relevant section, apply the setting, and save the configuration.

2.2.3 Ensure Password Complexity Requirements Are Enforced (Automated)
L1 Auto
Description

This recommendation ensures that Password Complexity Requirements Are Enforced on the Sophos Firewall network security appliance. Enforcing this requirement establishes a minimum security standard and prevents insecure configurations.

Rationale

Without this enforcement, the Sophos Firewall network security appliance may accept insecure configurations that weaken overall security posture. Mandating this control ensures consistent protection against common attack vectors.

Audit

Log in to the Sophos web admin console and verify that Password Complexity Requirements Are Enforced. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Password Complexity Requirements Are Enforced. Navigate to the relevant section, apply the setting, and save the configuration.

2.2.4 Ensure STAS or AD SSO Is Configured for Internal Users (Automated)
L2 Auto
Description

This recommendation verifies that STAS or AD SSO Is Configured for Internal Users on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that STAS or AD SSO Is Configured for Internal Users. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure STAS or AD SSO Is Configured for Internal Users. Navigate to the relevant section, apply the setting, and save the configuration.

3 — Firewall Rules & Policies

▶

3.1 Rule Configuration

▶
3.1.1 Ensure Default Drop Rule Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Default Drop Rule Is Configured on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Default Drop Rule Is Configured. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Default Drop Rule Is Configured. Navigate to the relevant section, apply the setting, and save the configuration.

3.1.2 Ensure Rules Follow Least Privilege Principle (Manual)
L1 Manual
Description

This recommendation verifies that Rules Follow Least Privilege Principle on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Rules Follow Least Privilege Principle. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Rules Follow Least Privilege Principle. Navigate to the relevant section, apply the setting, and save the configuration.

3.1.3 Ensure Source and Destination Zones Are Explicitly Defined (Automated)
L1 Auto
Description

This recommendation verifies that Source and Destination Zones Are Explicitly Defined on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Source and Destination Zones Are Explicitly Defined. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Source and Destination Zones Are Explicitly Defined. Navigate to the relevant section, apply the setting, and save the configuration.

3.1.4 Ensure Unused Rules Are Removed or Disabled (Manual)
L1 Manual
Description

This recommendation verifies that Unused Rules Are Removed or Disabled on the Sophos Firewall network security appliance. Disabling or removing unnecessary components reduces the attack surface and limits potential vectors for exploitation.

Rationale

Running unnecessary components on the Sophos Firewall network security appliance increases the attack surface and the risk of exploitation. Disabling or removing them follows the principle of least functionality and reduces exposure to known vulnerabilities.

Audit

Log in to the Sophos web admin console and verify that Unused Rules Are Removed or Disabled. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Unused Rules Are Removed or Disabled. Navigate to the relevant section, apply the setting, and save the configuration.

3.2 Application Control

▶
3.2.1 Ensure Application Control Is Enabled on WAN Rules (Automated)
L1 Auto
Description

This recommendation verifies that Application Control Is Enabled on WAN Rules on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Application Control Is Enabled on WAN Rules. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Application Control Is Enabled on WAN Rules. Navigate to the relevant section, apply the setting, and save the configuration.

3.2.2 Ensure High-Risk Applications Are Blocked (Automated)
L1 Auto
Description

This setting ensures that High-Risk Applications Are Blocked on the Sophos Firewall network security appliance. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Sophos Firewall network security appliance is essential for defense in depth.

Audit

Log in to the Sophos web admin console and verify that High-Risk Applications Are Blocked. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure High-Risk Applications Are Blocked. Navigate to the relevant section, apply the setting, and save the configuration.

3.2.3 Ensure Intrusion Prevention System Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Intrusion Prevention System Is Enabled on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Intrusion Prevention System Is Enabled. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Intrusion Prevention System Is Enabled. Navigate to the relevant section, apply the setting, and save the configuration.

3.2.4 Ensure IPS Policy Is Set to Recommended or Stricter (Automated)
L1 Auto
Description

This recommendation verifies that IPS Policy Is Set to Recommended or Stricter on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that IPS Policy Is Set to Recommended or Stricter. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure IPS Policy Is Set to Recommended or Stricter. Navigate to the relevant section, apply the setting, and save the configuration.

4 — VPN Configuration

▶

4.1 IPsec VPN

▶
4.1.1 Ensure IPsec Uses Strong Encryption Algorithms (Automated)
L1 Auto
Description

This recommendation verifies that IPsec Uses Strong Encryption Algorithms on the Sophos Firewall network security appliance. Using the recommended component or protocol ensures alignment with security best practices and reduces risk.

Rationale

Using an insecure or legacy component instead of the recommended approach increases the risk of compromise. Ensuring the Sophos Firewall network security appliance uses the correct component aligns with industry best practices and standards.

Audit

Log in to the Sophos web admin console and verify that IPsec Uses Strong Encryption Algorithms. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure IPsec Uses Strong Encryption Algorithms. Navigate to the relevant section, apply the setting, and save the configuration.

4.1.2 Ensure IKEv2 Is Used for IPsec (Automated)
L1 Auto
Description

This recommendation verifies that IKEv2 Is Used for IPsec on the Sophos Firewall network security appliance. Using the recommended component or protocol ensures alignment with security best practices and reduces risk.

Rationale

Using an insecure or legacy component instead of the recommended approach increases the risk of compromise. Ensuring the Sophos Firewall network security appliance uses the correct component aligns with industry best practices and standards.

Audit

Log in to the Sophos web admin console and verify that IKEv2 Is Used for IPsec. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure IKEv2 Is Used for IPsec. Navigate to the relevant section, apply the setting, and save the configuration.

4.1.3 Ensure Perfect Forward Secrecy Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Perfect Forward Secrecy Is Enabled on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Perfect Forward Secrecy Is Enabled. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Perfect Forward Secrecy Is Enabled. Navigate to the relevant section, apply the setting, and save the configuration.

4.1.4 Ensure Dead Peer Detection Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Dead Peer Detection Is Configured on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Dead Peer Detection Is Configured. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Dead Peer Detection Is Configured. Navigate to the relevant section, apply the setting, and save the configuration.

4.2 SSL VPN

▶
4.2.1 Ensure SSL VPN Uses TLS 1.2 or Higher (Automated)
L1 Auto
Description

This recommendation verifies that SSL VPN Uses TLS 1.2 or Higher on the Sophos Firewall network security appliance. Using the recommended component or protocol ensures alignment with security best practices and reduces risk.

Rationale

Using an insecure or legacy component instead of the recommended approach increases the risk of compromise. Ensuring the Sophos Firewall network security appliance uses the correct component aligns with industry best practices and standards.

Audit

Log in to the Sophos web admin console and verify that SSL VPN Uses TLS 1.2 or Higher. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure SSL VPN Uses TLS 1.2 or Higher. Navigate to the relevant section, apply the setting, and save the configuration.

4.2.2 Ensure SSL VPN Portal Is Restricted by Source (Automated)
L2 Auto
Description

This setting ensures that SSL VPN Portal Is Restricted by Source on the Sophos Firewall network security appliance. Restricting this capability limits potential abuse and enforces the principle of least privilege across the environment.

Rationale

Unrestricted access to this capability could allow unauthorized users or processes to perform actions beyond their intended scope. Applying least-privilege principles to the Sophos Firewall network security appliance is essential for defense in depth.

Audit

Log in to the Sophos web admin console and verify that SSL VPN Portal Is Restricted by Source. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure SSL VPN Portal Is Restricted by Source. Navigate to the relevant section, apply the setting, and save the configuration.

4.2.3 Ensure SSL VPN Authentication Uses MFA (Automated)
L1 Auto
Description

This recommendation verifies that SSL VPN Authentication Uses MFA on the Sophos Firewall network security appliance. Using the recommended component or protocol ensures alignment with security best practices and reduces risk.

Rationale

Using an insecure or legacy component instead of the recommended approach increases the risk of compromise. Ensuring the Sophos Firewall network security appliance uses the correct component aligns with industry best practices and standards.

Audit

Log in to the Sophos web admin console and verify that SSL VPN Authentication Uses MFA. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure SSL VPN Authentication Uses MFA. Navigate to the relevant section, apply the setting, and save the configuration.

5 — Web Protection

▶

5.1 Web Filtering

▶
5.1.1 Ensure Web Filtering Policy Is Applied to All Outbound Rules (Automated)
L1 Auto
Description

This recommendation verifies that Web Filtering Policy Is Applied to All Outbound Rules on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Web Filtering Policy Is Applied to All Outbound Rules. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Web Filtering Policy Is Applied to All Outbound Rules. Navigate to the relevant section, apply the setting, and save the configuration.

5.1.2 Ensure HTTPS Scanning Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that HTTPS Scanning Is Enabled on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that HTTPS Scanning Is Enabled. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure HTTPS Scanning Is Enabled. Navigate to the relevant section, apply the setting, and save the configuration.

5.1.3 Ensure Malware Scanning Is Enabled for Web Traffic (Automated)
L1 Auto
Description

This recommendation verifies that Malware Scanning Is Enabled for Web Traffic on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Malware Scanning Is Enabled for Web Traffic. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Malware Scanning Is Enabled for Web Traffic. Navigate to the relevant section, apply the setting, and save the configuration.

5.1.4 Ensure Pharming Protection Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Pharming Protection Is Enabled on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Pharming Protection Is Enabled. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Pharming Protection Is Enabled. Navigate to the relevant section, apply the setting, and save the configuration.

5.2 Web Application Firewall

▶
5.2.1 Ensure WAF Is Enabled for Published Web Servers (Automated)
L1 Auto
Description

This recommendation verifies that WAF Is Enabled for Published Web Servers on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that WAF Is Enabled for Published Web Servers. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure WAF Is Enabled for Published Web Servers. Navigate to the relevant section, apply the setting, and save the configuration.

5.2.2 Ensure WAF Protection Mode Is Set to Reject (Automated)
L1 Auto
Description

This recommendation verifies that WAF Protection Mode Is Set to Reject on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that WAF Protection Mode Is Set to Reject. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure WAF Protection Mode Is Set to Reject. Navigate to the relevant section, apply the setting, and save the configuration.

5.2.3 Ensure WAF Cookie Signing Is Enabled (Automated)
L2 Auto
Description

This recommendation verifies that WAF Cookie Signing Is Enabled on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that WAF Cookie Signing Is Enabled. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure WAF Cookie Signing Is Enabled. Navigate to the relevant section, apply the setting, and save the configuration.

6 — Logging & Monitoring

▶

6.1 Log Configuration

▶
6.1.1 Ensure Syslog Server Is Configured (Automated)
L1 Auto
Description

This recommendation verifies that Syslog Server Is Configured on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Syslog Server Is Configured. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Syslog Server Is Configured. Navigate to the relevant section, apply the setting, and save the configuration.

6.1.2 Ensure Firewall Rule Logging Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Firewall Rule Logging Is Enabled on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Firewall Rule Logging Is Enabled. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Firewall Rule Logging Is Enabled. Navigate to the relevant section, apply the setting, and save the configuration.

6.1.3 Ensure Admin Activity Logging Is Enabled (Automated)
L1 Auto
Description

This recommendation verifies that Admin Activity Logging Is Enabled on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Admin Activity Logging Is Enabled. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Admin Activity Logging Is Enabled. Navigate to the relevant section, apply the setting, and save the configuration.

6.1.4 Ensure Log Retention Period Is Set to 90 Days or More (Automated)
L1 Auto
Description

This recommendation verifies that Log Retention Period Is Set to 90 Days or More on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Log Retention Period Is Set to 90 Days or More. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Log Retention Period Is Set to 90 Days or More. Navigate to the relevant section, apply the setting, and save the configuration.

6.2 Alerting & Notifications

▶
6.2.1 Ensure Email Notifications Are Configured for Critical Events (Automated)
L1 Auto
Description

This recommendation verifies that Email Notifications Are Configured for Critical Events on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Email Notifications Are Configured for Critical Events. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Email Notifications Are Configured for Critical Events. Navigate to the relevant section, apply the setting, and save the configuration.

6.2.2 Ensure SNMP Is Configured with SNMPv3 (Automated)
L1 Auto
Description

This recommendation verifies that SNMP Is Configured with SNMPv3 on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to properly configure this setting may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that SNMP Is Configured with SNMPv3. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure SNMP Is Configured with SNMPv3. Navigate to the relevant section, apply the setting, and save the configuration.

6.2.3 Ensure Sophos Central Management Is Connected (Automated)
L2 Auto
Description

This recommendation verifies that Sophos Central Management Is Connected on the Sophos Firewall network security appliance. Implementing this control strengthens the overall security configuration and reduces exposure to potential threats.

Rationale

Failure to implement this control may leave the Sophos Firewall network security appliance vulnerable to attack or non-compliant with organizational security policies. This control helps establish a consistent, hardened configuration baseline.

Audit

Log in to the Sophos web admin console and verify that Sophos Central Management Is Connected. Navigate to the relevant configuration page and review the current settings.

Remediation

In the Sophos web admin console, configure Sophos Central Management Is Connected. Navigate to the relevant section, apply the setting, and save the configuration.