Tuesday, February 9, 2010

SmartWorkflow

Check Point release R70.2 includes a new software blade called SmartWorkflow that enables both visual change tracking of your security policy, but also the ability to enforce a change control process requiring all changes to be reviewed by a second person before allowing the policy to be installed. Depending on your requirements, there are two ways to deploy the SmartWorkflow software blade.

The first mode is very easy to setup, and once enabled, you can start using it immediately. This mode does not enforce policy approvals, but provides the administrator with visual tracking of all changes made. How many times have you been interrupted at work, only to return and wonder where you left off? No need to wonder, SmartWorkflow provides the tracking you need.

SmartWorkflow for Visual Change Tracking


SmartWorkflow also has the ability to enforce change control, but requires a little more preparation for use. You will need to create two types of administrators, one for building and creating policy change requests, and another with permission to approve those changes. In addition, those with approval permission are not able to make changes to sessions they create or submit. This simple model ensures that no one individual can make a policy change without approval.

SmartWorkflow for Change Control


Notice the mistake that was made when you forget that the admin who creates a session, cannot approve it. Define your roles ahead of time to keep the change procedure flowing.

I hope these examples help you understand the setup and use of the SmartWorkflow feature. Questions, comments and feedback are always welcome. With some planning, hopefully this feature will assist you in creating a change control procedure for your infrastructure.

0 comments: