Support for Palo Alto Networks Strata Cloud Manager is available now. Learn more →

Case Study

FireMon Delivers 100% PCI Compliance and Cleanup

A US homeware retailer serving customers through stores and online channels.

The Results

30%

Target Reduction in Time Spent Preparing Firewall Policy Evidence for PCI Reviews

170+

Fortinet Firewalls in Scope for Analysis and Compliance

1

Platform to Centralise Firewall Policy Analysis, Compliance Reporting and Change History

The Challenge

This US-based retailer’s existing policy management platform was not giving its networking team the visibility or usability it needed. A difficult interface limited adoption, while reporting gaps made it harder to identify rules that needed tightening and to prioritise cleanup. Teams continued to rely on time-consuming, error-prone manual reviews across a complex, multi-vendor environment, adding pressure as PCI compliance requirements grew.

The company set out to:

  • Reduce manual effort in PCI compliance reviews and audit preparation.
  • Identify unused and redundant rules and prioritise overly permissive access for review.
  • Centralise policy analysis and make the platform easier for the networking team to use.
  • Replace a platform that was difficult to use and limited networking team adoption.
  • Improve reporting to pinpoint overly permissive access and prioritise remediation.
  • Gain visibility into distributed firewall policies to support network segmentation and expanding cloud infrastructure.

The Solution

The retailer selected FireMon Security Manager for its usable interface, centralised policy analysis and compliance reporting. It chose the platform to help the networking team identify unused, redundant, shadowed and overly permissive rules, giving reviewers the context to prioritise cleanup and tighten access. Policy assessments, reporting and change history would support PCI reviews and reduce the manual effort involved in gathering audit evidence. The initial focus is firewall rule cleanup and PCI compliance reporting, with broader workflow automation held back for potential future expansion.

FireMon Delivered

  • Assess policies for non-compliance and generate reports to support PCI reviews.
  • Identify inactive, redundant and shadowed rules for analysis before removal.
  • Find overly permissive rules to guide the tightening of access.
  • Record rule changes and configuration history to support investigations and audit reviews.
  • Centralise firewall policy analysis so the networking team can review rule usage, policy issues and change history in one place.

Results

  • Less time spent gathering firewall policy evidence for PCI reviews.
  • More focused cleanup, supported by rule usage and policy analysis.
  • Better visibility into access that needs tightening and changes that need review.
  • Stronger networking team adoption through an interface that makes policy analysis easier to use.
  • More consistent PCI reviews through repeatable policy assessments and reporting.
  • Less manual effort reconstructing rule changes and configuration history during audits and investigations.

“FireMon helps us see which rules need attention and gives our networking team a clearer starting point for cleanup. Having policy analysis and change history in one place means less digging for information when it is time for a PCI review.”

[Principal Security Engineer], managing the selection and deployment of FireMon

FireMon Delivers 100% PCI Compliance and Cleanup