True RBAC for management of policies and logs

Question asked by Michael Horne on Oct 15, 2018
I am looking at how best to deploy RBAC to limit access to different parts of the security polices. It appears that the current CheckPoint implementation I have a good granularity controlling what an Admin Role can edit / update / create.


Is there a way to restrict access to read / view some information?


Ideally with RBAC I would like to be able to restrict what administrators can view. Our structure is to have a policy package for site site with security gateways.  The Central / Global IT team will have access to all policy packages and logs. Ideally the Local IT should have an admin role that only allows them to see policy package related to their site. At the moment it appears I cannot prevent them from seeing the policy packages for all sites.


In the ideal, ideal world the Local IT would only be able to access logs, events and reports for security gateways related to theirs site.


Is there any possibility of doing this within the RBAC offered by Checkpoint. Currently we are running R80.10. I do not know if there are nay changes within R80.20.


