Applies To:
-
BIG-IQ Centralized Management
8.0.0
Analyzing Security Policies
-
Overview of security policy audit
The security policy audit allows you to evaluate and edit a security policy based on system-provided recommendation. In addition, you can use the audit to analyze policy changes, deploy changes, ignore recommendations, and export the audit results. The image below provides an overview of the information and available actions within the Policy Analyzer audit. For more information about the system-provided recommendations, see section Security Policy Analyzer recommendations. -
Policy security score
In the Security Analyzer screen, the policy’s security score indicates the number of outstanding system recommendations to improve application protection. Each score is based on the number of pending recommendations in each severity. If a policy surpasses the threshold for the number of outstanding recommendations of any severity, the system updates the security score.
-
Security Policy Analyzer recommendations
The following is a list of policy tuning recommendations to improve your Web Application Security policy’s protection. These suggestions are based on rule violations detected by policy learning. Recommendations are based on current policy configuration and traffic analysis. You can either approve or ignore these suggestions based on your application protection requirements.