Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

San Francisco public-sector network administrators should base controls on a current inventory and risk assessment, isolate device-management access from ordinary traffic, tightly protect privileged accounts, and make changes and alerts auditable. The City and County of San Francisco’s located Citywide Cybersecurity Policy applies to City information resources and departments—not every business or household in San Francisco—and dates to 2019, so departments should verify whether a newer policy or technical baseline supersedes it.

Who this guidance applies to

The City and County of San Francisco’s Citywide Cybersecurity Policy says its requirements apply to information resources operated by or for the City and County and its departments and commissions. It was approved on November 21, 2019, and lists FY 2020–21 as its next review date. That date has passed; the document is useful local governance context, but should not be described as the current policy without checking for a successor. The policy also says citywide requirements do not supersede applicable state or federal requirements. Read the Citywide Cybersecurity Policy.

The operational controls below draw on recommendations from CISA and NIST. They are general security guidance, not additional San Francisco mandates. A city department should reconcile them with applicable city standards, its service needs, and regulatory obligations.

Start with ownership, inventory, and risk

Security controls are more useful when tied to what a network supports and what a compromise would affect. Build an inventory that records each network asset’s function, owner, data sensitivity, operational or public-safety importance, software and configuration, and vendor-support status. Use it to set priorities rather than applying identical controls to devices with very different roles.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
  • Assign accountability. The City policy directs departments to appoint a Departmental Information Security Officer (DISO); larger departments may appoint a CISO. It also calls for coordination with the City Chief Information Security Officer.
  • Assess risk at least annually. The policy calls for departments to conduct and update risk assessments at least once a year, categorize systems and data by sensitivity and operational criticality, and update cybersecurity requirements at least annually.
  • Use a framework and central services. The policy recommends the NIST Cybersecurity Framework and calls for departments to use citywide standards and services, including access-control and management services. It also directs participation in citywide cybersecurity forums.
  • Track the governing baseline. Record which policy and technical baseline each system follows, its owner, and when it was last reviewed. Confirm the applicable version with the City before treating the 2019 policy as the latest requirement.

The City’s FY 2025–27 COIT application summary describes a proposed identity-governance initiative involving privileged access management, Active Directory consolidation, and integration of identity management with physical-access tools. It is planning context, not evidence that those projects were completed or an audit of live systems. See the FY 25–27 COIT Application Summary.

Separate network-device administration from ordinary traffic

Routers, switches, firewalls, and other infrastructure devices have a management plane: the interfaces and paths administrators use to configure and monitor them. CISA recommends keeping this management activity on an out-of-band network isolated from operational data flow where feasible. That separation makes it harder for a compromise on a user or production network to become a direct route to device control.

  • Place management interfaces in a dedicated, restricted management zone or separate out-of-band network, rather than exposing them to general user or customer traffic.
  • Allow administration only from managed, trusted devices on trusted networks. Do not expose management interfaces directly to the public internet.
  • Prevent management links from becoming a path for device-to-device lateral administration unless that access is explicitly needed and controlled.
  • Use default-deny access-control lists where appropriate, log denied traffic, segment device groups by function, and put externally facing services in suitable isolated zones.
  • Limit VPN features and open ports to what the service actually requires; remove unused management services and interfaces.

Out-of-band access can add infrastructure and operational complexity, while a dedicated logical management zone may be more practical where separate cabling or equipment is not feasible. Either approach should narrowly control routes and permitted administrators; a shared path with broad reach increases the potential blast radius.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Protect privileged identities and sessions

Use individual administrator identities and centralized authentication, authorization, and accounting (AAA) rather than shared routine administrator logins. Apply least privilege: give each account only the access needed for its role, and review accounts and permissions regularly. CISA recommends phishing-resistant multifactor authentication (MFA) for accounts that access systems and networks, including sensitive router administration; prioritize administrator and remote-access accounts where the technology supports it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Use a dedicated administration platform. NIST NCCoE describes hardened administration platforms and unique administrator identities as privileged-access measures. Keep administrative work off general-purpose user devices where practical.
  • Choose MFA with compatibility in mind. CISA identifies physical security keys as a strong MFA option for state, local, tribal, and territorial (SLTT) organizations. A FIDO security key is a possible implementation, not a universal fix: verify support in the organization’s identity provider and the specific network equipment, and plan account recovery and enrollment before rollout. CISA does not endorse a particular model.
  • Constrain emergency access. Keep local break-glass accounts limited and protected. Change or rotate their credentials after emergency use, document that use, and review the account’s access.
  • Record administrative activity. NIST NCCoE describes proxying and logging privileged network-based sessions as an example practice. Use session records to support review and incident reconstruction, with access to those records itself controlled.

Security keys generally offer stronger resistance to phishing than less-resistant MFA methods, but may require compatible services, enrollment, spare-key procedures, and a recovery path. The right choice depends on the systems being protected and whether administrators can use the chosen method consistently.

Control changes, patching, and unsupported devices

Maintain accurate hardware, software, and configuration records, and track approved changes. Compare observed device configurations with an approved baseline so unexpected changes can be investigated. CISA and NIST guidance treats patching as a managed process: prioritize based on exposure, exploitation status, operational impact, and support status, then test and deploy through change management.

Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
  1. Identify affected assets and determine their criticality, exposure, vendor support status, and whether exploitation is known or suspected.
  2. Rank remediation by the risk of leaving the flaw in place and the operational cost of downtime. Do not use a vulnerability score alone as a substitute for service-impact assessment.
  3. Test updates in a representative environment when possible, schedule deployment through change control, and prepare a rollback or recovery path appropriate to the device.
  4. Record the approved change and verify afterward that the intended version or configuration is active.
  5. Track end-of-life or unsupported equipment for replacement; where immediate replacement is not possible, reduce exposure and isolate it as far as operations allow.

Testing and staged changes can reduce the chance that an update disrupts a critical service, but they take time and do not eliminate risk. An exposed, actively exploited vulnerability may require faster mitigation than a routine maintenance window permits.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Centralize logs and prepare for incidents

Local-only logs can be difficult to correlate and may be lost or altered if a device is compromised. Forward AAA and security-event logs to protected central systems, restrict who can alter or read them, and monitor them for suspicious access or configuration changes. Capture enough context to reconstruct privileged logins, administrative actions, relevant network activity, and the timing of changes. Set retention to meet operational, legal, and incident-response needs.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Alert on unexpected changes to device configurations, administrator accounts, access policies, and logging settings.
  • Correlate network and identity events centrally, while ensuring the monitoring workload can be reviewed by assigned staff.
  • Define incident roles and escalation routes, and exercise response and recovery procedures.
  • Maintain recoverable backups of critical configurations and systems, and verify that restoration works.

The City policy assigns a centralized incident-response role to the City CISO and calls for incident exercises. NIST NCCoE guidance likewise recommends ongoing monitoring and recoverable backups for critical platforms. No single logging or backup arrangement replaces a tested response plan.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

What San Francisco’s public documents do—and do not—establish

The City policy describes a citywide program intended to protect critical infrastructure and sensitive information, manage risk, improve detection, contain and eradicate compromises, and restore information resources. Its annual assessment and requirements cycles are governance requirements, not evidence of a measured reduction in incidents or proof that every department has implemented a particular control.

The FY 2025–27 COIT application summary describes identity-governance work as a proposal and discusses risks associated with privileged accounts and multiple directory instances. It does not establish project completion, independently audit a department’s systems, or show that a particular vulnerability is exploitable. The public documents cited here do not establish the current security posture of every municipal network or the compliance status of any named department.

Administrator implementation checklist

  • Confirm applicable city policy, technical baselines, and other legal requirements with the responsible security office.
  • Name the security owner; inventory assets, owners, functions, sensitivity, criticality, configurations, and support status.
  • Complete and update the department risk assessment at least annually, using service impact to set priorities.
  • Isolate the management plane; restrict it to trusted devices and networks, and remove unnecessary exposed services.
  • Use unique administrator identities, centralized AAA, least privilege, and phishing-resistant MFA where supported.
  • Harden administration platforms and log privileged sessions; tightly control emergency accounts.
  • Track configuration baselines and approved changes; test and prioritize patches through change management.
  • Send protected logs to central monitoring, alert on unauthorized changes, and exercise incident recovery.

For broader technical detail, consult CISA’s Enhanced Visibility and Hardening Guidance for Communications Infrastructure, NIST NCCoE’s SP 1800-31 Appendix A Patch Management System Security Practices, CISA’s Four Cybersecurity Essentials for SLTTs, and the joint CISA and NSA Top 10 Cybersecurity Misconfigurations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.