Access control policy analysis summaries

An access control policy analysis summary is a dashboard that

  • provides insights on rule health, usage, and anomalies through visual representations

  • displays right-pane summary information when you select a policy, and

  • enables access to detailed analysis and optimization options.

Policy analysis summary components

When analysis completes, select an access control policy to review the right-pane summary and click View analysis details and optimize.

Alternatively, you can click the ellipse button associated with a policy and select View details to see the right-pane summary.

The right-pane summary displays key insights about the selected access control policy, including the status of rules categorized as healthy, disabled, expired, and anomalous.

The analysis summary includes these components:

  • Overall summary: Provides insights on how many rules are healthy, disabled, expired, and contain anomalies, using a pie chart for the selected access control policy. You can also hover over the part of the pie to view the percentage of rules.

The analysis summary for the access control policy displays a pie chart illustrating the health status of rules, including counts of healthy, disabled, expired, and anomalous rules. Users can hover over the pie sections to view the percentage of each rule category.
  • Rule usage history: Shows how recently rules were used, with time periods.

The pie chart illustrates the distribution of healthy, disabled, expired, and anomalous rules within the selected access control policy, allowing users to hover over sections for percentage details.
  • Rules with Anomalies: Provides insights on how many rules have anomalies.

The image illustrates a summary of access control policy analysis, highlighting rule usage history, rules with anomalies, and insights on hit counts for various rule types, including allow, block, monitor, and trust.
  • Hits rules & dead rules: Provides insights on hitcount of expired rules, for rule types including allow, block, monitor, and trust.

The image illustrates a summary of access control policy analysis, highlighting rules with anomalies, hit counts for expired rules, and application insights regarding detected traffic without restrictions.

In remediation tabs such as Duplicate rules, Expired rules, Mergeable rules, Overlapping objects, and Policy insights you can select the check box next to a category to stage all observations in that category, or expand the category and select specific observations or rules. Available actions depend on the anomaly type.