Answer yes if management interfaces (used for configuration and management tasks) for firewalls or other edge devices are only accessible through secure channels, and not directly from the public internet. Where remote access is required for a documented business need, it should be only be accessible through a combination of additional security controls such as a VPN, trusted IP addresses, MFA, etc.