Yes, apply your secy=urity profiles to both. Inbound initiated traffic needs security profiles to protect you from exploits targeting a weakness in your front facing web services. Outbound initiated traffic needs security profiles to protect your browsers or other clients from weaknesses in those browsers or malware download. It also benefits from PanDB URL filtering. You may find in practice that you like different profiles for inbound initiated than outbound initiated traffic, e.g. URL filtering makes a lot more sense Outbound than Inbound. Many people may have more Outbound rules than Inbound rules, so you may want to consider using a Security Profile Group with name "default" for your Outbound traffic, which will then be applied automatically to all new security rules you recreate.