Professional-Grade Network Security Evaluation
| Component | Status | Notes |
|---|---|---|
| Network diagram up to date? | ☐ Yes ☐ No ☐ N/A | _______________ |
| Network segmentation (VLANs)? | ☐ Yes ☐ No ☐ N/A | _______________ |
| Guest network isolated from internal? | ☐ Yes ☐ No ☐ N/A | _______________ |
| IoT devices on separate VLAN? | ☐ Yes ☐ No ☐ N/A | _______________ |
| DMZ for public-facing servers? | ☐ Yes ☐ No ☐ N/A | _______________ |
| Redundant internet connections? | ☐ Yes ☐ No ☐ N/A | _______________ |
| Item | Compliant? | Remediation Needed |
|---|---|---|
| Default deny all policy | ☐ Yes ☐ No | _______________ |
| Outbound filtering enabled | ☐ Yes ☐ No | _______________ |
| Unused ports/services blocked | ☐ Yes ☐ No | _______________ |
| Firmware up to date (within 30 days) | ☐ Yes ☐ No | _______________ |
| Admin access restricted to management VLAN | ☐ Yes ☐ No | _______________ |
| MFA enabled for firewall admin login | ☐ Yes ☐ No | _______________ |
| Logging enabled and reviewed weekly | ☐ Yes ☐ No | _______________ |
| Intrusion prevention (IPS) active | ☐ Yes ☐ No | _______________ |
| Geo-blocking for high-risk countries | ☐ Yes ☐ No | _______________ |
| DDoS protection configured | ☐ Yes ☐ No | _______________ |
| Item | Status | Finding |
|---|---|---|
| WPA3 encryption (or WPA2 minimum) | ☐ Yes ☐ No | _______________ |
| Strong WiFi password (20+ characters) | ☐ Yes ☐ No | _______________ |
| SSID broadcast disabled (optional) | ☐ Yes ☐ No | _______________ |
| Guest WiFi isolated from internal | ☐ Yes ☐ No | _______________ |
| 802.1X authentication for internal WiFi | ☐ Yes ☐ No | _______________ |
| Rogue access point detection | ☐ Yes ☐ No | _______________ |
| WiFi coverage mapping completed | ☐ Yes ☐ No | _______________ |
| Component | Compliant? | Notes |
|---|---|---|
| VPN required for all remote access | ☐ Yes ☐ No | _______________ |
| Modern encryption (AES-256, no PPTP) | ☐ Yes ☐ No | _______________ |
| Split tunneling disabled | ☐ Yes ☐ No | _______________ |
| MFA required for VPN login | ☐ Yes ☐ No | _______________ |
| VPN client auto-update enabled | ☐ Yes ☐ No | _______________ |
| Session timeout configured (30 min) | ☐ Yes ☐ No | _______________ |
| VPN access logs reviewed monthly | ☐ Yes ☐ No | _______________ |
| Tool/Capability | Implemented? | Platform/Tool |
|---|---|---|
| SIEM (Security Information and Event Management) | ☐ Yes ☐ No | _______________ |
| Network traffic analysis | ☐ Yes ☐ No | _______________ |
| Bandwidth monitoring | ☐ Yes ☐ No | _______________ |
| Intrusion detection system (IDS) | ☐ Yes ☐ No | _______________ |
| Endpoint detection and response (EDR) | ☐ Yes ☐ No | _______________ |
| Email security gateway | ☐ Yes ☐ No | _______________ |
| DNS filtering/monitoring | ☐ Yes ☐ No | _______________ |
| Automated alerting configured | ☐ Yes ☐ No | _______________ |
Last Scan Date: ___/___/___ | Next Scheduled: ___/___/___
| Severity | Count | Avg Time to Remediate |
|---|---|---|
| Critical | ___ | Target: 7 days |
| High | ___ | Target: 30 days |
| Medium | ___ | Target: 90 days |
| Low | ___ | Target: Next maintenance window |
CVE Scores (CVSS):
Common False Positives:
| Risk Level | Business Impact | Priority | Action |
|---|---|---|---|
| Critical | High | P0 | Emergency patch (24 hours) |
| Critical | Medium/Low | P1 | Urgent patch (7 days) |
| High | High | P1 | Urgent patch (7 days) |
| High | Medium/Low | P2 | Standard patch (30 days) |
| Medium | Any | P3 | Next maintenance window |
| Low | Any | P4 | Quarterly review |
| Control | Implemented? | Notes |
|---|---|---|
| Device registration required | ☐ Yes ☐ No | _______________ |
| Antivirus/patch level checks | ☐ Yes ☐ No | _______________ |
| Quarantine VLAN for non-compliant devices | ☐ Yes ☐ No | _______________ |
| BYOD policy enforced via NAC | ☐ Yes ☐ No | _______________ |
| MAC address filtering | ☐ Yes ☐ No | _______________ |
Assessed by: _________________________________
Date: ___/___/___
Overall Security Posture: ☐ Strong ☐ Adequate ☐ Needs Improvement ☐ Critical Issues
Total Findings: Critical: ___ | High: ___ | Medium: ___ | Low: ___
Estimated Remediation Cost: $_______________
Estimated Remediation Time: ___ weeks
Next Assessment Date: ___/___/___