<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PCI Audit Proof of Resolution database? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180626#M30161</link>
    <description>&lt;P&gt;Part of my process it to work a compliance list from Skybox (or Tufin, or AlgoSec).&amp;nbsp; I investigate the rule and mark it for remediation.&amp;nbsp; When I have done the first pass, I create a Firewall Change Request in Skybox per fw by lines marked for remediation.&amp;nbsp; At this time, I can snapshot the rule.&amp;nbsp; Then the change request is fulfilled.&amp;nbsp; I then go back and validate the rule changes.&amp;nbsp; Here, I clean up the tag for remediation (I don't use tags, but write "Remediate" in the rule name).&amp;nbsp; At this point, I can snapshot the result.&amp;nbsp; All because auditors want pictures as 'proof'.&amp;nbsp; It is much easier to run&amp;nbsp;web_api_show_package before and after and show the comparison, but they won't accept that.&amp;nbsp; You would swear they get a royalty from one of the screen capture companies (I use ScreenPresso (purchased), so they are not getting anything there.)&lt;BR /&gt;&lt;BR /&gt;Edit - this syntax works in R81.10&amp;nbsp;&lt;BR /&gt;$MDS_FWDIR/scripts/web_api_show_package.sh -o /var/log/output -k &amp;lt;Policy_Name&amp;gt; -c -d &amp;lt;domain ip or name&amp;gt; --show-membership false&lt;BR /&gt;&lt;BR /&gt;whereas&amp;nbsp;/var/log/output is an existing directory.&lt;BR /&gt;&lt;BR /&gt;Edit # 3 - In the second pass, I also use logs to verify the traffic (Start with Rule UID).&amp;nbsp; With information I get in the log analysis, I see if there can be rule optimization that might 'fix' it by combination or tweak.&lt;/P&gt;</description>
    <pubDate>Thu, 11 May 2023 13:34:30 GMT</pubDate>
    <dc:creator>George_Ellis</dc:creator>
    <dc:date>2023-05-11T13:34:30Z</dc:date>
    <item>
      <title>PCI Audit Proof of Resolution database?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180520#M30125</link>
      <description>&lt;P&gt;Those that are having the ongoing or annual audits may know the pain.&amp;nbsp; The auditors want before and after 'pictures' of resolutions to rules that they feel are out of compliance.&amp;nbsp; Of course, some are and some are not.&amp;nbsp; As evidence, many insist on screen shots of the rules they flagged.&amp;nbsp; And a new twist, this year they want before evidence documented too.&lt;BR /&gt;&lt;BR /&gt;Question:&amp;nbsp; Has anyone found or are using a database application that can tie to an incident or finding to a resolution using screen shots.&amp;nbsp; One that is organized and cross references?&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 12:56:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180520#M30125</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2023-05-10T12:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Audit Proof of Resolution database?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180523#M30126</link>
      <description>&lt;P&gt;Glad you posted this, as I had customer brought this up last year...lets see what others say.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 13:15:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180523#M30126</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-10T13:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Audit Proof of Resolution database?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180612#M30151</link>
      <description>&lt;P&gt;Perhaps the following options might help:&lt;/P&gt;
&lt;P&gt;1) Open the relevant Revision in Read Only - before and after the change.&lt;/P&gt;
&lt;P&gt;2) Run the Changes report between the two relevant Revisions&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just go to - SmartConsole &amp;gt; Manage &amp;amp; Settings &amp;gt; Sessions &amp;gt; Revisions&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Select the relevant Revision and either apply&amp;nbsp;&lt;STRONG&gt;View&lt;/STRONG&gt; to open in Read Only or select - Actions &amp;gt; Changes &amp;gt; &lt;STRONG&gt;Compare selected with previous in list&amp;nbsp;&lt;/STRONG&gt;to just see the differences between Revisions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Revisions.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20871i563BF922E9DAF043/image-size/large?v=v2&amp;amp;px=999" role="button" title="Revisions.png" alt="Revisions.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 10:03:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180612#M30151</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-05-11T10:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Audit Proof of Resolution database?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180614#M30152</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;...I think this is how most folks would do it, but I feel like there has to be better way of doing this.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 11:33:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180614#M30152</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-11T11:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Audit Proof of Resolution database?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180616#M30154</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;- I think using Changes report between Revisions is an excellent option as it shows the exact change and as an image (picture).&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 12:17:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180616#M30154</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-05-11T12:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Audit Proof of Resolution database?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180617#M30155</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;...well, one can argue its an excellent option, as it appears to be the ONLY option lol&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 12:20:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180617#M30155</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-11T12:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Audit Proof of Resolution database?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180622#M30158</link>
      <description>&lt;P&gt;As I wrote, there is also the option to open the Revision in Read Only mode.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think the Changes option is excellent because it actually shows the change made and does it visually (unlike using Audit Logs)&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 12:53:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180622#M30158</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-05-11T12:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Audit Proof of Resolution database?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180623#M30159</link>
      <description>&lt;P&gt;Well, we will agree to disagree, as they say &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 12:56:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180623#M30159</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-11T12:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Audit Proof of Resolution database?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180624#M30160</link>
      <description>&lt;P&gt;While this is an alternate method to get the information of the change, it does not solve the real problem.&amp;nbsp; What to store this change information in that an audit team could find it.&amp;nbsp; Auditors tend to be IROCs (Individuals Right Out of College).&amp;nbsp; You have to spoon feed them.&amp;nbsp; And a year(s) later, you need to point them back to previous evidence.&amp;nbsp; I could have a thousand screen shots, but if they cannot be organized, it is a huge PITA.&amp;nbsp; So it needs to be something that has a marriage of photograph organizer with a audit database.&lt;BR /&gt;&lt;BR /&gt;It is looking like there is a market niche available without any players.&lt;BR /&gt;&lt;BR /&gt;PS - if you are thinking something like ServiceNow, while it supports attachments, replying to a finding to attach 500+ pieces of evidence is a futile exercise.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 13:12:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180624#M30160</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2023-05-11T13:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Audit Proof of Resolution database?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180626#M30161</link>
      <description>&lt;P&gt;Part of my process it to work a compliance list from Skybox (or Tufin, or AlgoSec).&amp;nbsp; I investigate the rule and mark it for remediation.&amp;nbsp; When I have done the first pass, I create a Firewall Change Request in Skybox per fw by lines marked for remediation.&amp;nbsp; At this time, I can snapshot the rule.&amp;nbsp; Then the change request is fulfilled.&amp;nbsp; I then go back and validate the rule changes.&amp;nbsp; Here, I clean up the tag for remediation (I don't use tags, but write "Remediate" in the rule name).&amp;nbsp; At this point, I can snapshot the result.&amp;nbsp; All because auditors want pictures as 'proof'.&amp;nbsp; It is much easier to run&amp;nbsp;web_api_show_package before and after and show the comparison, but they won't accept that.&amp;nbsp; You would swear they get a royalty from one of the screen capture companies (I use ScreenPresso (purchased), so they are not getting anything there.)&lt;BR /&gt;&lt;BR /&gt;Edit - this syntax works in R81.10&amp;nbsp;&lt;BR /&gt;$MDS_FWDIR/scripts/web_api_show_package.sh -o /var/log/output -k &amp;lt;Policy_Name&amp;gt; -c -d &amp;lt;domain ip or name&amp;gt; --show-membership false&lt;BR /&gt;&lt;BR /&gt;whereas&amp;nbsp;/var/log/output is an existing directory.&lt;BR /&gt;&lt;BR /&gt;Edit # 3 - In the second pass, I also use logs to verify the traffic (Start with Rule UID).&amp;nbsp; With information I get in the log analysis, I see if there can be rule optimization that might 'fix' it by combination or tweak.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 13:34:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180626#M30161</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2023-05-11T13:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Audit Proof of Resolution database?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180629#M30162</link>
      <description>&lt;P&gt;Agree 100%&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 13:49:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180629#M30162</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-11T13:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Audit Proof of Resolution database?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180927#M30201</link>
      <description>&lt;P&gt;Apparently it is a mythical creature.&amp;nbsp; Sigh.&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 14:46:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180927#M30201</guid>
      <dc:creator>George_Ellis</dc:creator>
      <dc:date>2023-05-15T14:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: PCI Audit Proof of Resolution database?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180938#M30204</link>
      <description>&lt;P&gt;Have you ever opened an official TAC case to see what they say?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 16:54:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/PCI-Audit-Proof-of-Resolution-database/m-p/180938#M30204</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-15T16:54:06Z</dc:date>
    </item>
  </channel>
</rss>

