Formal policies govern which network traffic is permitted and how firewall rules are created and reviewed
Sekit's Firewall management policy, one of A.5.1's topic-specific policies, states the default-deny stance and who may request and approve rule changes.
An approved firewall standard defining default-deny and who may approve rule changes is the policy basis A.8.20's network controls depend on.