soc2-ngfw-compliance

Map firewall controls and evidence to SOC 2 Trust Services Criteria for audit readiness.

9|Updated Mar 7, 2026
One-click install
npx skills add https://github.com/fastrevmd-lab/fwskillsshare --skill soc2-ngfw-compliance-fastrevmd-lab
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: soc2-ngfw-compliance
Source: https://github.com/fastrevmd-lab/fwskillsshare/tree/main/skills/soc2-ngfw-compliance
Command: npx skills add https://github.com/fastrevmd-lab/fwskillsshare --skill soc2-ngfw-compliance-fastrevmd-lab

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Auditors and security teams struggle to connect firewall configurations to SOC 2 Trust Services Criteria, often overclaiming compliance or missing Type II operating-effectiveness evidence. This Skill provides a structured control-to-evidence mapping so firewall estates can be assessed accurately for SOC 2 examinations. ## Core Features & Use Cases - Control Mapping: Maps NGFW features and rules to Trust Services Criteria such as CC6.1, CC6.6, CC7.2, and CC8.1, plus Availability, Confidentiality, and Privacy categories. - Assessment Workflow: Guides a five-step process from establishing scope and control matrix through validating Type II operating effectiveness with sampled evidence. - Evidence Markers: Provides safe description/tag patterns for firewall configs that point auditors to control IDs without exposing sensitive data. - Use Case: A SaaS company preparing for a SOC 2 Type II audit uses this Skill to review its Palo Alto rulebase, map each rule to control IDs, identify gaps in change-management evidence, and produce an auditor-ready findings report. ## Quick Start Use the soc2-ngfw-compliance skill to assess this firewall configuration export against SOC 2 Trust Services Criteria and list the evidence gaps.

Frequently Asked Questions about soc2-ngfw-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map firewall rules to SOC 2 Trust Services Criteria?

Map firewall rules to SOC 2 criteria by building a firewall-to-control matrix that links each rule's owner, purpose, and logging to control IDs and criteria like CC6, CC7, and CC8. The Skill's control-mapping reference provides a starting table for logical access, system operations, and change management.

What firewall evidence is needed for a SOC 2 Type II audit?

SOC 2 Type II firewall evidence includes sampled change tickets with approvals and validation, rule review records, admin and VPN access reviews, SIEM log forwarding and alert triage records, and incident tickets spanning the full examination period. Point-in-time screenshots alone are insufficient.

Is a firewall itself SOC 2 compliant?

No, a firewall is not SOC 2 compliant by itself. SOC 2 reports cover an organization's system controls, criteria, and examination period; the firewall only supports those controls when configured, monitored, reviewed, and evidenced consistently.

Should I parse firewall configs before a SOC 2 assessment?

Yes, parse raw configurations first with the matching vendor parsing skill for Cisco, Fortinet, Palo Alto, or Juniper before mapping findings to SOC 2 criteria. This Skill operates on parsed config data, not raw device output.

What is the difference between SOC 2 Type I and Type II for firewalls?

Type I assesses control design at a single point in time, while Type II requires evidence that controls operated effectively across the full report period. For firewalls, Type II demands sampled changes, reviews, and logs from throughout the period.