Skip to main content

Glossary

One line each, in alphabetical order. Where there is more to a term than one line holds, the definition links to the page that covers it.

TermWhat it means
AdministrationThe SIP module for system, user and device administration. Users and their device group authorization, device groups, and assessments and controls are all defined here, and Insights is registered under Administration > Settings > Insights. See Connect Your SIP Instance and Users and Access.
application objectA named application an application-aware device recognizes, so a rule can be written against the application rather than a port. See Policy data.
assessmentA named set of controls, assigned to device groups and run together. See Controls and assessments.
complexityA score for how complicated a device's configuration and rules are. Insights collects it per device and as an average per device group, and low is the ideal. See Scores.
controlOne check run against your devices, carrying a severity set by whoever wrote it. For a device group it passes, fails, or returns no data, and no data is common rather than a failure. See Controls and assessments.
deviceA firewall or other device your SIP manages. Insights holds its ID, name, description, group membership and device pack, but not its configuration. See How Insights gets your data.
device groupA named set of devices, defined in SIP under Administration > Device > Device Groups. Almost every figure in Insights is a figure for one group. See Device groups.
duplicate objectTwo object definitions with identical contents under different names. See Policy data.
FireMon Customer Average (FCA)The average of a measurement across every FireMon Insights customer, drawn as a baseline on metric charts and on Best Practices category scores. The same set of customers is named Industry Comparison in the All Metrics column, and Similar Organizations on a KPI carousel card. See Benchmarking.
KPIKey performance indicator, and the name of the Insights landing page: a carousel of generated highlights above a tile for each metric you have checked in All Metrics. See KPI.
MCPModel Context Protocol, the open protocol the FireMon MCP server speaks so your own AI client can query your FireMon environment. See MCP Server.
metricOne number Insights collects per device and per device group on each daily run: a count, a proportion of a total, or a score. See Metrics.
NAT ruleAn address translation on a device, counted alongside security rules. See Policy data.
network objectA named address, subnet or range that rules are written against. See Policy data.
Overall PostureThe Best Practices score out of 10, averaging the six category scores and charted by fiscal quarter. Zero means nothing is failing. See Scores.
percentileThe share of FireMon Insights customers whose value for a metric is lower than yours. See Benchmarking.
Policy ManagerThe name the Insights interface uses for Security Manager, on the Ask Policy Manager AI button, the View in Policy Manager links, and the "Policy Manager is not connected" and "Connect Insights to Policy Manager" messages. The View in Policy Manager links open Security Manager.
Policy PlannerThe separately licensed SIP add-on behind the Change page. Without it, Insights collects no tickets and no workflows. See Policy Planner.
revisionA stored version of a device's configuration in Security Manager. Insights counts revisions, and counts the security rules added, modified and removed. See Revisions.
Risk AnalyzerA separately licensed SIP module for vulnerability assessment and risk prioritization. Insights collects nothing from it.
Security Concern Index (SCI)Security Manager's measure of how much failed control severity a device is carrying, calculated per device. Insights collects it and reports the device group's average as Average Security Concern Index, where low is the ideal. See Scores.
Security ManagerThe SIP module Insights draws almost everything from: rules, objects, revisions, controls, assessments, SCI and complexity. Deep links out of Insights land here. See Insights and Security Manager.
security ruleAn allow or deny decision on a device. Together they make up the rulebase. See Policy data.
service objectA named protocol and port definition that rules are written against. See Policy data.
shadowed ruleA rule that can never match, because a rule above it in the policy always handles the traffic first. See Policy data.
SIPSecurity Intelligence Platform, the on-premise FireMon platform Insights connects to. Its Administration module is where you register Insights. See Connect Your SIP Instance.
SIQLSecurity Intelligence Query Language, FireMon's query language for searching normalized device configurations. See MCP Server.
unreferenced objectAn object that exists but that no rule mentions. See Policy data.
unused ruleA rule that has matched nothing in the last 90 days. Disabled rules, and rules created inside the window, are left out of the count. See Policy data.