Auditing Compliance with Regulations

After you create a regulations profile, SecureTrack runs all of the tests on the target device selected in the profile every time a new revision is received and when the topology changes. When the tests are completed, you can immediately see which tests passed and which failed, including a detailed analysis of the reason according to the test requirements. You can see the critical violations in the Violations browser.

You can also exclude selected rules from the results as exceptions so that rules that you decide are not relevant to the test do no cause it to fail.

The audit results include these features:

  1. An indicator for each device which can be:

    Passed - All tests passed.

    Failed - At least one test failed.

    Calculating - The tests are currently being run on a revision. The results are shown for the previous revision.

    Invalid profile - go to Settings > Configuration> Regulations and complete any parts of the profile that are not marked with a green check mark. The results are shown for the last time the profile was complete.

    Error - Contact Tufin Support for assistance. The results are shown for the last revision before the error occurred.

    You can also recalculate the results based on the last revision.

  2. Filter the profiles by regulations: SOX or PCI DSS
  3. Manually recalculate the results.

    Results are automatically recalculated when there is a new revision or a change in the topology. To see the results after any other changes that impact the tests, click Recalculate.

  4. An indicator for each test to show if it passed or failed, including the number of devices that failed.
  5. Detailed results for each test.
  6. The date that the tests were calculated.
  7. A filter box to filter the results by test name.
  8. Select rules from the results and click Add Exception to exclude them from the regulations test.
  9. Export the results as a report that is saved in: Report > Reports Repository

    You can choose show the list of exceptions in the exported report.