Workflows
SegAudit is used two ways. A consultant runs it once per client engagement and hands over a pack of deliverables. A plant or corporate firewall team runs it on its own plants every quarter and tracks progress. Both start from the same two exported files and the same analysis.
For consultants
Section titled “For consultants”- Scope and request. Set up your firm profile once, then send the client the generated evidence request for their Panorama, firewall, FortiGate, FortiAnalyzer, Cisco ASA, Cisco FTD (FMC) or Check Point.
- Load and check. Check the hashes of the files that come back, load them, and confirm the zone model with the client.
- Review. Work the findings queue, triage each finding, and add what you saw on site that the evidence cannot show.
- Plan the change. Agree which flows production keeps, and turn the plans into the change package the client’s engineer implements.
- Deliver. Hand over the executive brief, audit report, roadmap, proposal and the rest as one pack, in Word and markdown.
- Follow on. Verify the change against the next traffic log, and record a checkpoint at each re-assessment.
For plant teams
Section titled “For plant teams”- Set up once. Install on a jump host, confirm the zone model and target security levels, and save the engagement.
- Export each quarter. Your engineer exports the configuration and the traffic log for the quarter.
- Review. See what crosses the Purdue model, what changed since last quarter, and run the periodic rule review.
- Change through your CAB. Take the change windows through your own change process, pilot plant first.
- Prove it. Load the next traffic log to verify each plan, and record the quarter as a checkpoint for management.
The full step-by-step workflows, with what to check at each step, are in the customer guides for licensed customers. To see every screen first, open the built-in sample in your first audit.