NIS2 EU directive
Network and Information Security 2
Risk management, incident reporting, supply-chain security. Article 21(2) covers ten measures, all surfaced.
example finding
NIS2 Art. 21(2)(b) Incident handling
Logs are kept on the device, not shipped off.
SOC 2 AICPA
Trust Services Criteria
Security (CC), availability (A), processing integrity (PI), confidentiality (C), privacy (P).
example finding
SOC 2 CC7.2 Anomaly monitoring
No off-box destination for security logs.
PCI-DSS v4 PCI SSC
Payment Card Industry Data Security Standard
CDE scope wizard. Segmentation analysis. Logging requirements 10.x covered end to end.
example finding
PCI-DSS 1.4.2 Inbound traffic to CDE
Rule allows untrusted network into CDE.
ISO 27001 2022
ISO/IEC 27001 Annex A
The 93 controls in the 2022 update. We map the ones the firewall config can actually evidence.
example finding
ISO 27001 A.8.16 Monitoring activities
Continuous monitoring not in place.
CIS Controls v8 CIS
Center for Internet Security
Implementation Groups 1 through 3, with the firewall-related safeguards from each.
example finding
CIS 8.10 Retain audit logs
Retention period not enforced.
NIST CSF 2.0
Cybersecurity Framework
Identify, Protect, Detect, Respond, Recover. Plus Govern in the 2.0 update.
example finding
NIST CSF DE.CM-1 Continuous monitoring
Logs are local only.