Category Archives: Cybersecurity
Wired 802.1X with Cisco Identity Services Engine (ISE) is an identity-based access-control system spanning endpoint supplicants, Catalyst switch authenticators, RADIUS policy, certificates or credentials, authorization results, and network enforcement. The design challenge is not getting one managed laptop to authenticate in a lab; it is supporting phones, printers, headless devices, pre-login machine access, certificate renewal, […]
Cisco TrustSec Scalable Group Tags (SGTs) let the network carry a role or security-group classification independently from IP subnet. Cisco Identity Services Engine can assign and distribute security-group policy, network devices can propagate SGT context inline or through mechanisms such as SXP, and enforcement points can apply Security Group ACLs (SGACLs) based on source/destination group […]
Runtime Application Self-Protection (RASP) places defensive logic inside or immediately around an application runtime so the application can detect and respond to suspicious execution as it happens. OWASP’s mobile security guidance describes common RASP-style capabilities including environment detection, code-integrity verification, anti-tampering, anti-debugging, and detection of hooking frameworks. Within Security Engineering, RASP should be understood as […]
FortiAnalyzer log forwarding lets an organization keep FortiAnalyzer as a local log-management and analytics platform while sending selected security telemetry to another FortiAnalyzer, a syslog server, a CEF destination, or supported cloud services through output plugins. In the default forwarding model, FortiAnalyzer retains a local copy, so forwarding creates a second distribution path rather than […]
Secrets rotation automation is the process of changing a credential on a schedule or in response to an event, updating the service that validates it, testing the new value, promoting it to current, and ensuring every consumer can continue working without relying on the old secret indefinitely. Rotation is successful only when both sides of […]
FortiCNAPP risk prioritization is designed to answer a question generic vulnerability severity cannot: which vulnerable assets and vulnerabilities matter most in this specific environment? Current FortiCNAPP documentation calculates proprietary risk scores for hosts, container images, packages, and CVEs using factors such as vulnerability prevalence, CVE/CVSS data, internet exposure, known or active exploits, package status, and […]
Shadow AI is the use of generative AI applications, browser extensions, coding assistants, embedded SaaS features, or model APIs outside the organization’s approved governance path. The risk is not simply that an employee found an unsanctioned website. The organization may not know which data users upload, how the provider retains it, whether it trains on […]
FortiGate ZTNA tags—called security posture tags in current FortiOS documentation—are dynamic endpoint attributes synchronized from FortiClient EMS to FortiGate. EMS evaluates zero-trust tagging rules against endpoint posture and identity context, then FortiGate receives the resulting IP/MAC mappings as read-only dynamic address objects that can be referenced in ZTNA rules, firewall policies, and NAC policies. Within […]
SLSA—Supply-chain Levels for Software Artifacts—is a specification for improving software supply-chain security through verifiable provenance and stronger controls around source and build systems. The current approved specification is version 1.2. A key current-state detail is that SLSA no longer has one universal “level” for everything: it has separate tracks, including a Build track and a […]
FortiManager Administrative Domains (ADOMs) partition devices, policy packages, objects, administrators, and version-specific management data into separate logical management areas. They are useful for managed service providers, large enterprises, multi-team environments, mixed device families, and firmware-lifecycle separation, but Fortinet best practices explicitly caution against creating more ADOMs than the business needs because each ADOM adds configuration […]
Palo Alto security operations sits at the intersection of network enforcement, routing, centralized configuration, SASE connectivity, device health, and user experience. PAN-OS firewalls no longer operate as isolated security appliances: Panorama can layer and push shared configuration, AIOps and Strata Cloud Manager can analyze health and security posture, Prisma Access extends policy to remote networks […]
FortiManager revision control is the combination of configuration history, change isolation, comparison, approval, and install discipline that lets teams make centralized firewall changes without losing the ability to explain or reverse them. Current FortiManager supports ADOM revisions for policy packages, objects, and VPN-console settings, policy-level revision history, and workspace/workflow modes that control how multiple administrators […]
PAN-OS Advanced Routing Engine turns the firewall into a more capable standards-oriented routing platform without separating routing from security enforcement. It uses logical routers instead of the legacy virtual-router model and supports BGP, MP-BGP, OSPFv2, OSPFv3, RIPv2, static routes, BFD, IPv4 multicast routing, redistribution, route maps, prefix lists, access lists, and RIB filtering. Within Palo […]
FortiSOAR playbooks automate security workflows across Fortinet and third-party systems through triggers, decisions, connectors, records, blocks, variables, and human interaction. Current FortiSOAR 8.0 design guidance emphasizes starting with a trigger, gating execution through decisions, grouping related logic in blocks, using reference blocks for reusable workflows, and choosing logging levels that support production operations without filling […]
Palo Alto AIOps for NGFW uses firewall telemetry to analyze device health, security posture, software behavior, and feature adoption. Current Strata Cloud Manager and AIOps capabilities include health alerts, security posture alerts, best-practice insights, feature-adoption visibility, predictive analysis, and software-upgrade recommendations for supported firewalls. Within Palo Alto Security Operations, AIOps is useful because it can […]