To prepare for compliance audits vs. 1 year

Policy visibility across 200+ Palo Alto firewalls
Policies managed across 200+ firewalls
The Challenge
Time-consuming and cumbersome processes with their previous NSPM solution made preparing for audits nearly impossible. Inaccurate reporting and the inability to perform firewall rule recertification and reviews via their existing solution led them to create a proprietary tool to sit on top of their solution to compensate for its lack of necessary features. This untenable process was not only cumbersome, but extremely costly and time consuming.
The company sought to:
- Implement annual firewall rule recertification practices
- Gain 100% visibility of network firewall policies across their entire multi-vendor environment
- Simplify and accelerate their compliance audit preparation process
The Solution
With FireMon, the company gained the ability to perform daily queries for compliance checks and rule reviews, real-time visibility across their entire environment, and a seamless, flexible workflow with state-of-the-art policy change automation capabilities.
- Decreased audit preparation time from 1 year to minutes
- 100% visibility and control to prevent risky and unused or shadowed rules from lurking in their environment
- Proactive compliance checks and auto-denial of changes that violate compliance standards
- Preconfigured and ad-hoc compliance/audit reports, on demand and scheduled risk reports, and on-demand, scheduled, and real-time (on change) compliance reports
We were so frustrated with our previous policy management solution that we ended up using our own resources to get it where it needed to be. FireMon not only did what the others couldn't, but we’re now saving time and effort in other areas as well.”
Results
- Improved process efficiency with automation and workflow, reducing time to implement policy change tasks from weeks to minutes
- Firewall rule review and recertification process reduced from days to minutes
- 100% firewall policy visibility across entire network environment