Skip to main content

Best Practices

Best Practices turns the results of your FireMon Best Practices Assessment into scores you can track over time. Security Manager reports which controls a device is failing today. This page reports whether that has improved or worsened over a period you select, how each category compares with other FireMon customers, and which individual controls moved.

Insights evaluates nothing here. Every number comes from control results your SIP installation produced and Insights collected. See Controls and assessments for what a control is, and how its results arrive.

What the page is scoped to

Best Practices has its own device group and date range controls, and ignores the ones the rest of Insights uses. The device groups available are those your Best Practices assessment is applied to, narrowed to the ones your SIP permissions authorize. The ranges are Last Month, quarter to date, a year, and everything Insights holds.

The range sets three separate figures. A score comes from the most recent result inside the range. A control's change is measured from the oldest result inside it. A score's own change is measured against the last result from before the range began.

The categories

Insights scores your assessment results in six categories. Five are populated by the tags a control carries in Administration > Compliance, so which controls fall into each one depends on how your assessment is written.

CategoryWhat it covers
Overly Permissive AccessAvoidable ways devices grant too much access, widening the attack surface
Risky AccessExposure pathways that could extend reach into sensitive assets
Policy QualityGaps, redundancies and unsafe defaults in rule design
Remote AccessWhether entry points stay least-privilege and hardened
Policy CleanupStale, shadowed and unused rules that should be removed

Vendor Hardening is populated differently. It ignores tags and takes the controls of four CIS benchmark assessments — Juniper, Fortinet FortiGate, Cisco ASA and Check Point — scored as one group. Without those assessments it has no score. Where only some of the four are assigned to a device group, the score covers part of the benchmark.

Reading a category score

The score runs 0 to 10, and lower is better. Zero means no device is failing any control in the category. It is weighted twice: by how many devices a control covers, and by its severity. Scores has the method, and how this differs from SCI.

The change beside it compares periods, not the two ends of the range. It is the difference between the score now and the score at the last result before the range started. A rise is worse.

Each control in the category is failing, passing, or has no data for the range. No data is normal, not a fault — a control has nothing to report about devices it does not apply to. Those controls are excluded from the score on both sides of the calculation, so a category with a few failing controls and many with no data can still score low.

The FireMon Customer Average

Each of the five tagged categories reports an FCA: the average score across FireMon Insights customers for that category. Scoring above it is worse than average, since low is better here. Vendor Hardening has none, because the baseline is built from category tags and Vendor Hardening has no tags.

Two rules scope that average. It is recalculated for the selected range rather than a fixed window. And it is built from every customer's all-devices group, while your own score follows the device group you selected, so narrowing the group leaves the two sides measuring different things. Benchmarking covers who is included, why, and what a missing FCA means.

The average is also scoped to your own assessment: only controls that are in your Best Practices assessment and carry the category's tags count toward it, on your side and everyone else's.

Overall Posture

Overall Posture averages the six categories into a single figure, reported by fiscal quarter against the three quarters before it. Only categories with data enter the average, and each quarter is averaged on its own, so one quarter can rest on fewer categories than the next.

Quarters are cut against your fiscal year start, an account setting that defaults to January. Changing it re-cuts the quarters without moving the results. A quarter is marked improved or regressed against the one before it, and reads "No data" rather than zero where Insights holds no results.

Control-level detail

Every control in the five tagged categories is reported against two dimensions: its severity, and whether its failures rose or fell across the range. The change is expressed as a share of the device group's devices plus security rules, so a heavily weighted control failing more widely stands out from a minor one. Vendor Hardening is excluded.

Opening a category reports its control failures across the range, exportable as CSV, and every control in it with its change and its current Control Failures. That last figure counts failed rules for policy-based controls, and failed devices for device configuration controls. On Vendor Hardening it also names the CIS assessment each control came from. A written insight summarizes what moved.

What else the page counts

For the selected device group: Total Logical Rules (security plus NAT), Security Rules, NAT Rules, Total Objects (network, service and application), and Overall Policy Complexity.

Where Policy Planner is licensed, it also reports change volumes and ticket durations. Change covers those numbers.

Ask AI about this data opens the assistant with everything on this page already in front of it. Ask AI covers what it can and cannot reach.

When the page has nothing to score

Where Insights holds no assessment named Best Practices, or that assessment has no controls, or it is not applied to any device group your account can see, there is nothing to score.

The fix is not in Insights. Assessments and controls are written in Administration > Compliance, and Insights reads what your SIP reports at the next collection. The same applies to a single category with no data on a page that otherwise works: the controls it looks for are not in your assessment, or are not tagged for it.