US · guidance
CMS Pub. 100-17, ch. 117_systems_security, § 3.20
Firewall Ruleset Reviews
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Firewalls are key to preventing unauthorized and unwanted network traffic from entering or exiting
a network and for restricting network access as a means of enforcing least privilege access.
Firewalls accomplish this by using rulesets that determine which traffic is allowed to pass. The
CMS TRA requires firewalls to functionally separate internal network zones.
In accordance with the latest revision of NIST Special Publication 800-41, management shall
develop policies and procedures to periodically review firewall rulesets/configurations (both
internal and external facing) to ensure they remain compliant. Management should use a risk-based
approach for determining the frequency of the review for each firewall, but at a minimum, on a
yearly basis. Areas to address in the policies and procedures include, but are not limited to:
• Validating old or out-of-date rules are prevented from processing by commenting them out
or deleting them. Validating redundant rules are not active.
• Reviewing all rulesets/configurations to identify that change documentation or reference
information that describes the purpose are documented. Management should be able to
provide business justification for each active rule.
• Testing that changes do not break or bypass existing rulesets and function as intended.
• Documenting change management processes to confirm that rule changes were reviewed,
tested, and approved.
• Comparing current rulesets to secured backups to validate that no unauthorized changes
have occurred.
• Verifying known insecure protocols and potentially unnecessary IP addresses are being
restricted.
If MACs decide to automate their Firewall rulesets review, they should ensure the following are
included, at minimum:
- Identification of redundant, duplicate, and conflicting rules.
- Identification of overly permissive rules.
- Identification of insecure ports and protocols.
- Identification of rules that are no longer used.
Firewall ruleset reviews need to be documented and evidence of review maintained. The following
types of information are important to maintain with the evidence of review:
- Evidence of reports and/or documentation reviewed.
- Who reviewed the report and/or documentation, the result of the review, and when the
review was performed.
- Tickets or documentation generated for addressing issues identified.
History
(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
3380c7b8807c0ea053279ba53abfa75a25a5f1aec5b9f38e5ac6e7095ce7252d
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.