Bindinglaw

US · guidance

CMS Pub. 100-17, ch. 117_systems_security, § 3.20

Firewall Ruleset Reviews

activein force · 2026-08-25 – presentas-observed

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Firewalls are key to preventing unauthorized and unwanted network traffic from entering or exiting

a network and for restricting network access as a means of enforcing least privilege access.

Firewalls accomplish this by using rulesets that determine which traffic is allowed to pass. The

CMS TRA requires firewalls to functionally separate internal network zones.

In accordance with the latest revision of NIST Special Publication 800-41, management shall

develop policies and procedures to periodically review firewall rulesets/configurations (both

internal and external facing) to ensure they remain compliant. Management should use a risk-based

approach for determining the frequency of the review for each firewall, but at a minimum, on a

yearly basis. Areas to address in the policies and procedures include, but are not limited to:

• Validating old or out-of-date rules are prevented from processing by commenting them out

or deleting them. Validating redundant rules are not active.

• Reviewing all rulesets/configurations to identify that change documentation or reference

information that describes the purpose are documented. Management should be able to

provide business justification for each active rule.

• Testing that changes do not break or bypass existing rulesets and function as intended.

• Documenting change management processes to confirm that rule changes were reviewed,

tested, and approved.

• Comparing current rulesets to secured backups to validate that no unauthorized changes

have occurred.

• Verifying known insecure protocols and potentially unnecessary IP addresses are being

restricted.

If MACs decide to automate their Firewall rulesets review, they should ensure the following are

included, at minimum:

- Identification of redundant, duplicate, and conflicting rules.

- Identification of overly permissive rules.

- Identification of insecure ports and protocols.

- Identification of rules that are no longer used.

Firewall ruleset reviews need to be documented and evidence of review maintained. The following

types of information are important to maintain with the evidence of review:

- Evidence of reports and/or documentation reviewed.

- Who reviewed the report and/or documentation, the result of the review, and when the

review was performed.

- Tickets or documentation generated for addressing issues identified.

History

(Rev. 15.1; Issued: 07-17-25; Effective: 02-28-25; Implementation: 08-18-25)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
3380c7b8807c0ea053279ba53abfa75a25a5f1aec5b9f38e5ac6e7095ce7252d
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.