Firewall expiry-by-default creates a quarterly renewal review nobody will fund, and each un-renewed permit stays an intruder's route in: what do you propose?
answer
- a flat quarterly review deserves to be refused
- rank by what a mistake costs
- borrow governance, do not create it
- friction belongs on whoever wants access
- a signature when there is no budget
basics
~20 sMake renewal rare rather than free. Tier expiry by blast radius so only wide cross-zone permits face human renewal, shrink the population that qualifies, and if even that is unfunded, make a named senior owner sign for the standing exposure.
solid answer
~50 sDo not defend a flat quarterly review; nobody should fund one, because most permits do not deserve it. Tier by blast radius: a permit crossing from a vendor-support zone into a clinical VLAN gets a short expiry and a named human renewal, while a narrow same-zone permit gets a long expiry and a low-friction renewal. That usually turns hundreds of reviews into a few dozen, which a service owner can absorb. Second, attach renewal to something that already has a review — the vendor contract, the project, the support agreement — so no new meeting exists. Third, refuse the false choice: if the directorate will neither fund renewal nor accept an expiry outage, the remaining option is a named executive accepting the standing exposure in writing, with a review date. Security cannot hold that risk on their behalf.
go deeper
Know that removing an old permit is not purely a technical act: someone has to decide the access is no longer needed, and that person is usually not on the network team.
Be able to explain why a flat review of every permit is unaffordable, and how ranking permits by what a mistake would cost reduces the work to something a service owner can carry.
Show how you would fold renewal into reviews that already exist and stage enforcement so the outage risk is bounded, announced and reversible.
Own the funding argument and the escalation. Be ready to say who signs for an exposure nobody will pay to remove, and why security absorbing that decision is the wrong answer.
## Why the flat review is the wrong thing to defend Expiry-by-default is correct as a mechanism and often wrong as a programme, because the version people first propose treats all permits alike: every rule expires quarterly, every rule is renewed by a human, and the resulting workload is charged to whoever owns the network. When the clinical directorate refuses to staff that, they are not being obstructive — they are refusing a badly shaped ask. Winning the argument starts with agreeing that a flat quarterly review of hundreds of permits should not be funded. ## Shrink the population that needs a human The permits differ enormously in what they cost if they are wrong. Rank them by blast radius, which you can derive from the rulebase itself rather than from anyone's memory: | Permit shape | Expiry | Renewal | | --- | --- | --- | | Lower-trust zone into a clinical VLAN, wide service range | Short | Named human, each time | | Cross-zone but narrow, single host and service | Medium | Named human, lightweight | | Same-zone, narrow | Long | Confirm-or-lapse, minimal effort | Done honestly this usually reduces "hundreds of quarterly reviews" to a few dozen decisions a year in the tier that actually matters. That is a number a service owner can carry, and it is the number you should be negotiating over — not the raw permit count. ## Put the renewal where a review already happens A renewal that needs its own meeting will be skipped. A renewal attached to a review that already exists will not. The vendor-support permit renews when the vendor's support contract renews; the project's temporary access renews at the project's stage gate; a clinical system's access is confirmed during its existing change board. You are not creating governance, you are borrowing it, and that argument is far easier to win than a new headcount. ## Make the default cheap in the direction you want The design goal is that doing nothing closes a permit and renewing is a small deliberate act, so the friction falls on whoever wants the access. Two details decide whether that survives contact with a hospital: - **Nothing on a clinical path lapses unannounced.** Enforcement is announced, windowed and rehearsed, or the first patient-visible interruption ends the programme permanently. The cost of that discipline is real and belongs in your proposal, not hidden in it. - **The emergency re-open is itself time-bound.** If re-opening at 02:00 produces another permanent permit, you have funded a treadmill that does not reduce exposure. The re-open path should make an expiry and a named person the easy default. ## Refuse the false choice, and name the third option Sometimes the answer is still no: no renewal effort, no expiry risk. That is not a stalemate, because there is a third position that costs nothing to operate — **a named senior owner accepts the standing exposure in writing, with a stated review date and a stated scope**. The value of this is not paperwork. It is that the risk moves to the person who is actually choosing to keep the permit, and it usually changes their answer: people who will not fund an hour of renewal work are often unwilling to sign a page saying they accept an open path from a vendor zone into a clinical VLAN for another year. What you must not do is let security absorb the decision by quietly renewing everything on the business's behalf. That converts an organisational risk decision into a technical maintenance task, hides the exposure from the people who could reduce it, and leaves the network team accountable for an outcome it does not control. ## What to actually propose in the room 1. Tiered expiry, with the numbers: how many permits fall into the tier that needs a human, and what that costs in hours per quarter. 2. Renewal folded into reviews that already exist, so no new forum is created. 3. A staged enforcement plan with announced windows and a rehearsed re-open, so the outage risk is bounded and visible. 4. For anything the business will not renew and will not let you close, a signed acceptance with an owner and a date. 5. One number reported afterwards: not rules deleted, but how many standing permits have no expiry and no named owner — trending to zero. ## The judgment being tested The interviewer is not looking for enthusiasm about expiry. They are looking for someone who understands that a control with an ongoing human cost is an organisational commitment, that the person who benefits from an exception should carry its cost, and that when funding is genuinely unavailable the professional move is to make the risk owned and visible rather than to quietly hold it yourself.
- Why not let the security team renew the permits on the business's behalf?Because it converts a business risk decision into a maintenance task and hides the exposure from the people who could remove it. Security has no basis to judge whether a clinical flow is still needed, so the renewal becomes rubber-stamping, and the network team ends up accountable for an open path it did not choose to keep.
- What single metric would you report to the board on this?The count of standing permits with no expiry date and no named owner, trended over time. Rules deleted is a vanity number that rewards churn; the unowned count measures whether the default has actually flipped, and it goes up visibly if the next incident recreates the problem.
- The vendor says a short expiry on their support access is unworkable. How do you respond?Tie the expiry to something they already renew — the support contract or the scheduled maintenance visit — so the renewal is not new work for them. If they still refuse, the access is standing third-party reach into a clinical network, and that is a contract conversation with a named owner on our side, not a firewall change.
saying these in an interview costs you the question
- Proposes a flat quarterly review of every permit
- Lets security renew permits on the business's behalf
- Treats refusal to fund as the end of the conversation
- Reports rules deleted as the measure of success
- Ignores that an unannounced expiry on a clinical path is a safety event