On This Page
Security Best Practices Report
Overview
The Security Best Practices report provides organizations with the ability to ensure that security controls are based on common security best practices and to detect best practice failures. It lists all the rules that violate each best practice. The Security Best Practices report supports the PCI DSS v4.0 and ISO 27001 standards.
This report enables you to:
-
Identify the locations of risks across your network and which devices are most impacted
-
Prioritize rule optimization and remediation
-
Ensure awareness of the state of your network for audit purposes
Understanding the Security Best Practices report
The image shows an example of a Security Best Practices report created for the PCI DSS framework.
The report has three main sections:
General Information, Scope, Check Overview
-
General Information shows the report ID, name, and the time the report was created.
-
Scope lists the selected when creating the report.
-
Check Overview is the breakdown of the number of passed versus failed checks. Clicking View checks shows a detailed breakdown of each type of check .
Summary
Summary displays the shows the total number of rules and objects with the breakdown by severity.
Compliance Summary per Device
The Compliance Summary sections provides high-level overview of the compliance evaluation results for each device selected for the report. The section shows the overall compliance score and a breakdown of how the device's firewall rules perform against the checks defined in the compliance template (for example, a PCI framework-based template).
Overall compliance score
Percentage (0% to 100%), indicating the proportion of checks passed, with a progress bar showing the compliant/non-compliant split. The non-compliant percentage links directly to the failed checks.
Evaluation summary
The total number of violations, objects, and checks evaluated across the device.
-
Violations: Total number of individual rule or object violations found.
-
Objects: Number of network objects evaluated.
-
Checks: Number of policy checks run, as defined
Check results
The number of failed versus passed checks.
Score breakdown
Shows how the overall compliance percentage is calculated. It breaks down violations by severity level and applies the weighted scoring configuration defined in the report for each severity level to derive the total weighted score and the normalized final score.
The scoring model in use by the report is indicated as either the default or custom.
The weight assigned to each severity level (Critical, High, Medium, Low) reflects its relative impact on the compliance score. The number of violations found at each severity level is multiplied by the corresponding weight to produce a per-severity score. These are then summed into a total weighted score, which is normalized to produce the final compliance percentage displayed in the summary.
Low weight excluded from calculations
Checks with a weight of 0.0 (typically Low severity in the default model) are effectively excluded from the calculation.
Score calculation formula
100 × (1 − weighted violations ÷ weighted total)
where weighted total represents the maximum possible weighted score if all checks had failed. This acts as the normalization baseline.
The weighted total is not displayed in the report but is derived from the total number of items evaluated per check across all severity levels.
Rules
For each rule check defined in the template, shows the number of the device's rules that triggered a violation. The number of rules reflects the total number of rules that triggered at least one violation (not the total number of rules in the device).
-
Severity or Violation Count
You can sort the list by Severity to order checks by their risk level, or by Violation Count to order checks by the number of violations found, highest first in both cases.
Checks with zero violations always appear at the bottom regardless of sort order.
Both severity and violation counts are color-coded (red for high, orange for medium, gray for low). The severity color of each check reflects the severity defined in the compliance template and does not change based on violation count.
-
Rule views
You can either view the results for all rules or only for a specific rule.
All rules: Clicking Expand all on the right, expands to show all the rules
Specific rule: Clicking the arrow next to a rule shows the device's rules with only that violation.
Guardicore devices
For Guardicore devices, the rule card shows the tags and tag groups configured for the device. Hovering over the tag shows both the tag key and tag value.
Objects
For object in the rules, shows the number of empty service groups, network groups, duplicate services and duplicate hosts.
The Severity or Violation Count works similar to rules.
Security Best Practices Report settings
Before creating the Security Best Practices report, review these settings.
Best Practices Report Generation
The list of Best Practices report types that you can select from are based on predefined compliance templates and the All Best Practices report type.
-
Predefined compliance templates: Checks, severity, regulatory citations and remediation instructions, cannot be changed.
-
All Best Practices: Can be customized to suit requirements.
-
Checks: Select the checks to include or exclude.
For checks with values, if the values are not defined, STRE ignores the check during report creation.
STRE only supports the following options for the risky services field:<tcp/udp>:<port>formaticmp
-
Severity: Change as needed. See Severity settings.
-
Citation/Notes: Enter custom citations and remediation instructions as needed.
-
Severity Settings
Severity settings help prioritize the security checks included in the report results.
-
Predefined compliance templates: Severity settings cannot be changed.
-
All Best Practices report: Every check has a default severity setting. If needed change the severity to suit the preferences, risk tolerance, and needs of your organization.
-
Critical
Failure to comply represents a material violation of widely accepted security best practices that significantly increases the likelihood of unauthorized access, regulatory exposure, or operational disruption. These findings typically reflect high-impact misconfigurations or behaviors that create clear and actionable exposure and should be remediated immediately.
-
High
Indicates a significant deviation from established security best practices that elevates organizational risk. While not necessarily indicative of an imminent compromise, these issues meaningfully weaken the security posture and should be addressed promptly to prevent escalation or downstream exposure.
-
Medium
Reflects conditions that degrade rule governance, visibility, or alignment with security principles. These findings do not usually pose an immediate threat but may increase risk over time, hinder auditability, or complicate investigation and response efforts if left uncorrected.
-
Low
Represents minor configuration inconsistencies, procedural gaps, or optimization opportunities. Addressing these findings improves policy hygiene, reduces "noise" in audits, and supports long-term maintainability, but they generally have minimal direct security impact.
-
Users can change the default scoring configuration of severity settings which impacts the report's scoring model.
Scoring Configuration
You can configure weights for every severity level for any predefined compliance template and the All Best Practices report. The weights are used to calculate and assign the compliance score which reflects how well a device complies with the security best practices checks.
It is calculated based on the number of findings and their severity weights:
-
Higher weights increase the impact of that severity on the final score.
-
A weight of 0 effectively excludes that severity level from the score calculation.
As each finding is weighted by severity, more serious issues have a greater impact on the final score. For example, if you assign a weight of 3 to Critical findings and a weight of 1 to Low findings, a report with two Critical violations will score significantly lower than a report with ten Low violations — reflecting that severity matters, not just volume.
The scoring configuration is displayed in the Scoring breakdown section of the Security Best Practices report.
Create a Security Best Practices Report
Prerequisites
-
Outgoing SMTP server and remote repository configured by admin
Procedure
-
From the sidebar, select Create and then select Security Best Practices.
The settings you can configure for the report are displayed.
-
Define the report settings:
-
General: Report name.
-
Domains and Devices: Select a domain, and one or more devices or device groups.
-
Best Practices
The type of Best Practice report to create based on a predefined compliance template or the All Best Practices custom report.
-
Scoring Configuration:
-
To change the scores for the severity levels, click Customize scoring and enter the required scores for the severity levels.
-
To restore the default scores, click Restore default scoring.
-
-
Export Report:
-
Email: Specify the recipients for notification emails. Press Tab or Enter to separate multiple email addresses.
The email message includes a link to the report in STRE.
Select the format of the report to include in the email as an attachment, as PDF, CSV, or both. Reports larger than 4 MB are compressed as
.zipfiles. -
Remote Repository: STRE can export reports using SFTP. Specify the report format - PDF or CSV.
If the report finished successfully, you can verify that the new files appear in the Reports Folder path, in the remote repository, configured by your administrator (see Send Reports Using SFTP).
-
- Schedule: Configure the following:
- Repeats: The frequency at which the report runs: Daily, Weekly, or Monthly.
- Days of the week: Available for Weekly and Monthly frequencies.
For Weekly, runs the report on each selected day at the specified time. For example, if you select Monday, the report runs every Monday.
For Monthly, this is one of two scheduling options. Runs report on the first occurrence of the selected day of the week in the month at the specified time. For example, if you select Monday, the report runs on the first Monday of the month.
- Calendar Month: Available only for Monthly frequencies. This is the second monthly scheduling option. Runs report on the 1st or 15th of the calendar month. Reports based on calendar months run automatically at midnight.
- Time: The time at which the report should run.
-
-
Click one of the following:
: Saves the report. The Saved menu lists all saved and scheduled reports.
: Runs the report. After a report runs, you can view the results in the Repo menu.
Export Completed Reports from Local Repository
After creating a report, export it to any supported format from the Repo menu.
-
CSV: Use to create your own reports based on the specific data from the report configuration.
-
PDF: Use to export as a ZIP file.
-
If the report exceeds 250 rules, the ZIP file includes multiple PDFs, each including up to 250 rules. The name includes the sequence in the format <num> of <total_reports> to indicate the order. For example, 1 of 3.
-
A single report comprising multiple PDFs can include a total of 6000 rules. To increase the limit, contact Tufin Support.
-
Open Rule in SecureTrack
When viewing the report online, you can go directly from a rule in to the corresponding rule in SecureTrack.
Expand the results, and click the rule ID or rule name to open the rule’s Overview tab in Rule Viewer.








