- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Those that are having the ongoing or annual audits may know the pain. The auditors want before and after 'pictures' of resolutions to rules that they feel are out of compliance. Of course, some are and some are not. As evidence, many insist on screen shots of the rules they flagged. And a new twist, this year they want before evidence documented too.
Question: Has anyone found or are using a database application that can tie to an incident or finding to a resolution using screen shots. One that is organized and cross references?
Glad you posted this, as I had customer brought this up last year...lets see what others say.
Apparently it is a mythical creature. Sigh.
Have you ever opened an official TAC case to see what they say?
Andy
Perhaps the following options might help:
1) Open the relevant Revision in Read Only - before and after the change.
2) Run the Changes report between the two relevant Revisions
Just go to - SmartConsole > Manage & Settings > Sessions > Revisions
Select the relevant Revision and either apply View to open in Read Only or select - Actions > Changes > Compare selected with previous in list to just see the differences between Revisions.
@Tal_Paz-Fridman ...I think this is how most folks would do it, but I feel like there has to be better way of doing this.
Andy
Hi @the_rock - I think using Changes report between Revisions is an excellent option as it shows the exact change and as an image (picture).
@Tal_Paz-Fridman ...well, one can argue its an excellent option, as it appears to be the ONLY option lol
As I wrote, there is also the option to open the Revision in Read Only mode.
I think the Changes option is excellent because it actually shows the change made and does it visually (unlike using Audit Logs)
Well, we will agree to disagree, as they say 🙂
Part of my process it to work a compliance list from Skybox (or Tufin, or AlgoSec). I investigate the rule and mark it for remediation. When I have done the first pass, I create a Firewall Change Request in Skybox per fw by lines marked for remediation. At this time, I can snapshot the rule. Then the change request is fulfilled. I then go back and validate the rule changes. Here, I clean up the tag for remediation (I don't use tags, but write "Remediate" in the rule name). At this point, I can snapshot the result. All because auditors want pictures as 'proof'. It is much easier to run web_api_show_package before and after and show the comparison, but they won't accept that. You would swear they get a royalty from one of the screen capture companies (I use ScreenPresso (purchased), so they are not getting anything there.)
Edit - this syntax works in R81.10
$MDS_FWDIR/scripts/web_api_show_package.sh -o /var/log/output -k <Policy_Name> -c -d <domain ip or name> --show-membership false
whereas /var/log/output is an existing directory.
Edit # 3 - In the second pass, I also use logs to verify the traffic (Start with Rule UID). With information I get in the log analysis, I see if there can be rule optimization that might 'fix' it by combination or tweak.
While this is an alternate method to get the information of the change, it does not solve the real problem. What to store this change information in that an audit team could find it. Auditors tend to be IROCs (Individuals Right Out of College). You have to spoon feed them. And a year(s) later, you need to point them back to previous evidence. I could have a thousand screen shots, but if they cannot be organized, it is a huge PITA. So it needs to be something that has a marriage of photograph organizer with a audit database.
It is looking like there is a market niche available without any players.
PS - if you are thinking something like ServiceNow, while it supports attachments, replying to a finding to attach 500+ pieces of evidence is a futile exercise.
Agree 100%
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 42 | |
| 21 | |
| 10 | |
| 8 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY