Generate compliance reports

Procedure


Step 1

In the left pane, click Insights & Reports > Compliance Posture.

The Compliance Posture page displays previously generated reports and allows you to create new compliance evaluations.

Step 2

Click Generate Report to begin defining the report.

Step 3

Enter a name and choose the device to evaluate.

  • Currently, PCI DSS 4.0.1 Compliance Template is the only supported template. This template evaluates firewall configurations against requirements for network security, access control, secure configuration, and logging.

  • Only devices that are currently online are available for selection.

Step 4

Review the security zones.

PCI DSS requires the Cardholder Data Environment (CDE) to be accurately defined. The CDE includes systems that store, process, or transmit cardholder data or sensitive authentication data, as well as environments with unrestricted connectivity to systems handling such data. An automated assessment identifies security zones that are likely to be part of the CDE based on the existing configuration. Review the selected security zones and update the selections based on your knowledge of the network before generating the report.

Step 5

In the Security Zones table, select the checkbox in the CDE column for each security zone that is part of the CDE. Clear the checkbox for any zone that is not part of the CDE.

Note

Incorrect security zone selections can result in inaccurate compliance findings, particularly for checks related to segmentation and traffic between network zones.

Step 6

Click Generate Report to begin the compliance evaluation process.

Note
  • Compliance reports are generated manually and are not evaluated automatically.

  • The system analyzes firewall policies and validates them against the selected compliance template. Report generation can fail due to device connectivity issues. Verify that the device is online and reachable.

  • The page confirms that report generation has started. A comprehensive review and analysis of the policies on the selected device will be performed. This process may take some time.

  • Click Return to compliance reports to return to the Compliance Posture page.

Step 7

Find the generated report.

Use the search field to search reports by name, user, or template. You can also click Filters to narrow the results. The Compliance Status column shows the number of checks that passed, need review, or failed.

Step 8

Click the report name to view the detailed compliance results.

  • The report page displays the report name, evaluated device, last update time, compliance score, and compliance summary.

  • The Compliance Score shows the number of compliant checks out of the total number of checks.

  • The Compliance Summary displays total findings, checks that passed, need review, or failed.

  • The report displays a list of Compliance Checks, each representing a specific requirement being evaluated (for example, restricting inbound traffic to the CDE or validating VPN security). Select a compliance check to view its details, which may include:

    • A description

    • References to relevant compliance standards

    • Identified findings associated with the check

    • Recommendations for remediation

The number next to each compliance check indicates how many findings were identified for that check.

Step 9

Click Download Report to export the report in JSON format for audit and offline review.

Step 10

Rerun a report.

After making changes to address compliance findings, rerun the report to evaluate the updated configuration.


You can view compliance findings from the Summary page. Navigate to Insights & Reports > Summary and click Operations to view compliance-related insights for the selected time range.