Home/Questions/Network, logging and monitoring
Question library

Network, logging and monitoring: what cyber insurance applications ask

Firewalls, segmentation, remote access exposure, DNS and web filtering, log centralization, retention, and testing regimes.

29 questions in this section

partialDoes the Applicant employ external/perimeter and internal firewalls? verifiedIs RDP enabled, and if so, accessible internally only or externally? partialHas the Applicant applied network segmentation within its environment? partialAre development, testing, and production conducted in separate environments? partialDoes the Applicant employ intrusion detection/prevention? partialIs IP filtering used to prevent connections from known-malicious addresses? verifiedCan network ports only be opened with a legitimate business need? Port accessibility regularly verified? partialWhat is the firewall policy: deny all by default, permit by exception? partialHow frequently is firewall configuration reviewed and firmware updated? partialDoes the Applicant employ SIEM, log centralization, and audit logging across firewalls + IDS? partialHow long are audit logs maintained (30 / 90 / 1 year)? attestedDoes the Applicant conduct regular penetration testing? In-house or outsourced? partialDoes the Applicant conduct regular vulnerability scans? attestedAre independent security audits or assessments performed? attestedDoes the Applicant have a Security Operations Center (SOC) monitored 24/7? partialDoes local logging happen per-host? partialWhat percentage of hardware/software connected to network is inventoried? partialAre administrative/management login portals restricted from the public internet (closed or limited to specific IP addresses)? attestedHow is the Applicant's VPN infrastructure hosted (exclusively cloud-based, exclusively on-premises, or hybrid)? attestedWhich VPN provider/product does the Applicant use for remote connectivity? verifiedCan unauthorized devices be blocked from remotely accessing the network (e.g. MDM, allow-lists)? partialAre protective DNS or DNS filtering services in use? partialIs web gateway technology used to monitor and filter malicious or suspicious URLs? partialIs administrative access to servers restricted to a jump host or a limited number of endpoints? attestedIs workstation-to-workstation communication restricted (e.g. RDP between user workstations)? partialIs inbound and outbound traffic to critical servers restricted using an allow-list approach? attestedIs port-level network access control (e.g. 802.1X) used to admit only approved devices? attestedIs command-line activity in command shells (e.g. PowerShell, bash) logged and monitored? verifiedAre unsuccessful logins to administrative accounts logged and alerted on?

Back to the full question index

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture