Internal testing of firewall effectiveness is performed by firewall administrators an at least a weekly basis.
Internal testing is performed before and after each significant change in firewall configuration.
The firewall is periodically tested from both sides using automated tools provided by outside providers on a regular basis.
Select critical functions of the firewall are tested on a nearly continuous basis.
Internal auditors do a thorough test of the firewall on every internal audit.
External auditors do spot checks on every audit.
Random, blind, and periodic outside testing of the firewall and the entire incident response system dealing with the firewall is done on an ongoing basis.
Guest testers are periodically invited in to do firewall testing.
The coverage of some of the tests is known and select firewall functions are fully tested by some of the tests.
