health check assessment and recommendations - heartland … · 2018-02-14 · heartland business...

28
1 | Confidential. Heartland Business Systems, LLC. All Rights Reserved. Health Check Assessment and Recommendations 1. General Device Configuration 1.1 Best-Practice System Configuration Item Comments 1.1.3 Observation Certificate expiration check not enabled. Security Priority N/A Remediation Service Impact Risk None. Recommendation Enable option for “certificate expiration check”. Justification Certificates loaded on the Palo Alto firewall are commonly used for purposes such as SSL decryption, device administration, user identification, VPN, etc. HBS recommends enabling the certificate expiration check so certificates nearing expiration warn the administrator. Take appropriate action to renew the certificate before a service impact occurs. A valid e-mail profile that generates a notification for critical severity events is required. References: Palo Alto Device Help Pages Device à Setup à Management Remediation Impact Notes None. Item Comments 1.1.4 Observation Log storage quota not optimized. Security Priority N/A Remediation Service Impact Risk None. Recommendation Customize the default storage quotas to better utilize available log space for desired firewall logs. Justification All log storage categories come with a predetermined amount of capacity reserved. Customize the default settings to maximize the storage space for

Upload: others

Post on 11-Jul-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service

1 | Confidential. Heartland Business Systems, LLC. All Rights Reserved.

Health Check Assessment and Recommendations

1. General Device Configuration

1.1 Best-Practice System Configuration Item Comments 1.1.3

Observation Certificate expiration check not enabled.

Security Priority N/A

Remediation Service Impact Risk

None.

Recommendation Enable option for “certificate expiration check”.

Justification Certificates loaded on the Palo Alto firewall are commonly used for purposes such as SSL decryption, device administration, user identification, VPN, etc. HBS recommends enabling the certificate expiration check so certificates nearing expiration warn the administrator. Take appropriate action to renew the certificate before a service impact occurs. A valid e-mail profile that generates a notification for critical severity events is required.

References:

Palo Alto Device Help Pages

Device à Setup à Management

Remediation Impact Notes

None.

Item Comments 1.1.4

Observation Log storage quota not optimized.

Security Priority N/A

Remediation Service Impact Risk

None.

Recommendation Customize the default storage quotas to better utilize available log space for desired firewall logs.

Justification All log storage categories come with a predetermined amount of capacity reserved. Customize the default settings to maximize the storage space for

Page 2: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 3: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 4: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 5: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 6: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 7: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 8: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 9: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 10: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 11: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 12: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 13: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 14: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 15: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 16: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 17: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 18: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 19: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 20: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 21: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 22: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 23: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 24: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 25: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 26: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 27: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service
Page 28: Health Check Assessment and Recommendations - Heartland … · 2018-02-14 · HEARTLAND BUSINESS SYSTEMS Remediation Impact Notes Item Observation Security Priority Remediation Service