This is one of the many mindmaps from Aman Hardikar:
You can see that it is not only network firewalls and websites that need to be reviewed.
A security architecture needs to be developed from security principles within procedures and goals laid out within business objectives.