cis-controls-ngfw-compliance

Map firewall configurations and evidence to CIS Controls v8 safeguards.

9|Updated Mar 7, 2026
One-click install
npx skills add https://github.com/fastrevmd-lab/fwskillsshare --skill cis-controls-ngfw-compliance-fastrevmd-lab
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cis-controls-ngfw-compliance
Source: https://github.com/fastrevmd-lab/fwskillsshare/tree/main/skills/cis-controls-ngfw-compliance
Command: npx skills add https://github.com/fastrevmd-lab/fwskillsshare --skill cis-controls-ngfw-compliance-fastrevmd-lab

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Security teams struggle to demonstrate how their firewall estate supports CIS Controls v8/v8.1 safeguards during audits, often overclaiming that a firewall is "CIS compliant" without evidence. This Skill maps firewall controls, configurations, and operational evidence to specific CIS safeguards and Implementation Groups, producing defensible gap assessments. ## Core Features & Use Cases - Control Mapping: Maps NGFW features and firewall rules to CIS Controls 1-18 with a control-by-control matrix covering inventory, secure configuration, access control, logging, and incident response. - Assessment Workflow: Guides an eight-step assessment from scope and Implementation Group selection through rulebase review, evidence markers, and vulnerability/incident-response validation. - Evidence Markers: Recommends concise CIS:/CTRL: description and tag markers for policies, NAT rules, zones, and VPNs so exports carry auditable control references. - Use Case: Given a Palo Alto or Fortinet policy export, produce a firewall-to-CIS matrix identifying that a broad server egress rule maps to Controls 3, 4, 6, 8, 12, and 13, with risk explanation and remediation steps tailored to IG2. ## Quick Start Use the cis-controls-ngfw-compliance skill to assess this firewall configuration export against CIS Controls v8.1 at IG2 and produce a gap matrix with remediation priorities.

Frequently Asked Questions about cis-controls-ngfw-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map firewall rules to CIS Controls v8?

Map each firewall rule to CIS Controls by identifying its role in inventory, secure configuration, access control, logging, or network defense, then reference the control-by-control matrix in the mapping reference. Capture rule owner, business purpose, ticket reference, and evidence markers for each mapping.

Is a firewall CIS compliant by itself?

No, a firewall is not CIS compliant as a standalone product. CIS Controls alignment is assessed across the organization's implemented safeguards, processes, assets, and evidence; the firewall estate only supports specific safeguards when configured and operated correctly.

What is the difference between CIS Controls and CIS Benchmarks?

CIS Controls are prioritized organizational security practices organized into Implementation Groups, while CIS Benchmarks are product-specific hardening guides. This Skill covers CIS Controls v8/v8.1 safeguard mapping and explicitly excludes product-specific CIS Benchmarks.

Which CIS Implementation Group should my firewall assessment target?

Choose based on organizational risk and maturity: IG1 covers essential cyber hygiene, IG2 adds governance and monitoring for typical enterprises, and IG3 adds advanced detection and testing. When unspecified, the Skill provides a baseline labeled for tailoring by Implementation Group.

What evidence is needed for a CIS firewall assessment?

Required evidence includes asset inventory, network diagrams, policy and NAT exports, admin account and MFA records, change tickets, rule review history, SIEM forwarding configuration, vulnerability scan results, backup evidence, and incident response runbooks. The Skill provides a full evidence request checklist.

Can I put CIS control markers in firewall rule descriptions?

Yes, use short markers like CIS:BOUNDARY CTRL:12 OWNER:NetSec REF:FWSTD-001 in descriptions or tags where the platform supports them. Never include secrets, customer data, vulnerability details, or sensitive architecture in these fields.