> Source: [sk120256](https://support.checkpoint.com/results/sk/sk120256)

# sk120256 - ATRG: Compliance Blade (R80.10 and higher)

| Property | Value |
|----------|-------|
| Solution ID | sk120256 |
| Date Created | 2017-08-30 |
| Last Modified | 2026-01-21 |
| Technical Level | General |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20, R81.10 (EOS) |
| OS | Gaia |

## Solution

**Table of Contents**

* (1) Overview
* (2) Supported Regulatory Standards
* (3) Configuration
* (4) Troubleshooting
  * (4-1) Initial Installation of the Software
  * (4-2) Licensing
  * (4-3) Post install - Initial Scan
  * (4-4) Resolution issues
  * (4-5) Exclusions - Deactivating a Best Practice, or object within a Best Practice
  * (4-6) Action Items
  * (4-7) Save in Other Blades
  * (4-8) Report Generation
  * (4-9) Excel Export
  * (4-10) Gateway Favorites
  * (4-11) Inactive Objects
  * (4-12) Install Policy
  * (4-13) Help File
  * (4-14) Scoring
  * (4-15) "NA" Best Practices
  * (4-16) Conditional Best Practices
* (5) Debugging
  * (4-1) Rescan issues
* (6) Important Notes

(1) Overview {#Overview}
========================

The Check Point Compliance Blade is a dynamic solution that continuously monitors the Check Point security infrastructure. This unique product examines your Security Gateways, Blades, policies, and configuration settings in real time. It compares them with an extensive database of regulatory standards and security best practices. The Check Point Compliance Blade includes many graphical displays and reports that show compliance with the applicable regulatory standards.

(2) Supported Regulatory Standards {#Key Features}
==================================================

The Check Point Compliance Blade supports these regulatory standards:  
Show / Hide this section  
You can download the XML files from <https://community.checkpoint.com/t5/Compliance/bd-p/Compliance>.

Enter the string to filter this table:

|-----------------------------------------------------|---------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------|
| Standard                                            | Location                                                | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | Supported                                                                                          |
| Australian Privacy Principles (APP)                 | Australia                                               | The Australian Privacy Principles (APPs) replace the National Privacy Principles and Information Privacy Principles and apply to organizations, and Australian, ACT and Norfolk Island Government agencies. The APPs referenced here are taken from Schedule 1 of the Privacy Amendment (Enhancing Privacy Protection) Act 2012, which amends the Privacy Act 1988.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Yes                                                                                                |
| AUISM                                               | Australia                                               | **AUISM** - Australian Government Information Security Manual - The ISM helps organizations use their risk management framework to protect information and systems from cyber threats. The cyber security guidelines within the ISM are based on the experience of the ACSC within ASD.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | Yes                                                                                                |
| Canadian ITSG-33                                    | Canada                                                  | ITSG-33 (Annex 3A: Security Control Catalogue - Family of controls). This Annex is part of a series of guidelines published by the Communications Security Establishment (CSE) under Information Technology Security Guidance Publication 33 (ITSG-33), IT Security Risk Management: A Lifecycle Approach. It contains definitions of security controls that security practitioners can use as a foundation for selecting security controls for the protection of Government of Canada (GC) information systems and managing information technology (IT) security risks. The implementation of a comprehensive set of security controls supports the achievement of GC business activities.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | Yes                                                                                                |
| CIPA                                                | USA                                                     | The Children's Internet Protection Act (CIPA) places restrictions on the use of funding that is available through the Library Services and Technology Act, Title III of the Elementary and Secondary Education Act, and on the Universal Service discount program known as the E-rate (Public Law 106-554). These restrictions take the form of requirements for Internet safety policies and technology which blocks or filters certain material from being accessed through the Internet.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | Yes                                                                                                |
| CIS Benchmarks                                      | International                                           | **CIS Benchmarks** - Center for Internet Security - The Center for Internet Security (CIS) benchmarks are a set of best-practice cybersecurity standards for a range of IT systems and products. CIS Benchmarks provide the baseline configurations to ensure compliance with industry-agreed cybersecurity standards. The benchmarks are developed by CIS alongside communities of cybersecurity experts within industry and research institutes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | Yes                                                                                                |
| CJIS                                                | USA                                                     | CJIS is the Criminal Justice Information Services Security Policy. The essential premise of the CJIS Security Policy is to provide appropriate controls to protect the full lifecycle of CJI, whether at rest or in transit. CJIS is divided into 12 individual policy areas. The controls listed here are referenced in Version 5.2, dated 08/09/2013.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | Yes                                                                                                |
| CMMC                                                | Insurance                                               | **Cyber Security maturity model certification (CMMC), v1.10 (January 2020)** The Cyber security Maturity Model Certification (CMMC) is a unified standard for implementing cyber security across the defense industrial base (DIB), which includes over 300,000 companies in the supply chain. The CMMC is the DoD's response to significant compromises of sensitive defense information located on contractors' information systems.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Yes                                                                                                |
| CobiT 4.1 (IT SOX)                                  | USA                                                     | IT goals for ensuring system security. CobiT is also used as the basis for IT SOX compliance                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Yes                                                                                                |
| Cobit 5.0                                           | International                                           | The requirements listed under CobiT 5.0 are taken from the Deliver, Service and Support IT Domain. Within this, the reference is specifically to DSS05: Manage Security Services. DSS05 is divided into seven requirements: 1) Protect against Malware; 2) Manage network and connectivity security; 3) Manage endpoint security; 4) Manage user identity and logical access; 5) Manage physical access to IT assets; 6) Manage sensitive documents and output devices; and 7) Monitor the infrastructure for security-related events.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Yes                                                                                                |
| Cobit 2019                                          | International                                           | COBIT, or Control Objectives for Information and Related Technologies, is a globally acknowledged framework offering a robust set of principles, practices, and analytical tools for the efficient governance and management of enterprise IT. COBIT 2019 is the latest iteration, specifically crafted to navigate the intricacies of contemporary business landscapes and the swift advancements in technology.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | Yes                                                                                                |
| CSA CCoP 2.0                                        | Singapore                                               | The Cybersecurity Code of Practice (CCoP) issued by the Cyber Security Agency of Singapore (CSA) is a comprehensive set of guidelines and requirements designed to enhance the cybersecurity posture of Critical Information Infrastructure (CII) owners. The CCoP aims to ensure that CII sectors implement robust cybersecurity measures to protect against cyber threats and ensure the resilience of essential services.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Yes                                                                                                |
| Customer Security Programme (CSP) (SWIFT)           |                                                         | While all customers are responsible for protecting their environments, SWIFT has established the Customer Security Programme (CSP) to support customers in the fight against cyber-attacks. SWIFT is a global member-owned cooperative and the world's leading provider of secure financial messaging services.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | Yes                                                                                                |
| Cyber Essentials                                    | UK                                                      | Cyber Essentials Scheme: Requirements for basic technical protection from cyber attacks                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | Not supported                                                                                      |
| Cyber Essentials 3.1                                | UK                                                      | The National Cyber Security Centre (NCSC) in the UK has introduced an update to the Cyber Essentials scheme, a government-backed certification aimed at safeguarding UK organizations from prevalent cyber threats. The new update, version 3.1, includes modifications to malware protection and device management. This update comes after a significant overhaul of the Cyber Essentials scheme in 2022. Starting from April 24, 2023, all new applications for certification must adhere to the latest requirements and question set outlined in version 3.1. These changes will help organizations stay ahead in their defense against cyber risks.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | Yes                                                                                                |
| Deng Bao / ????                                     | China                                                   | ???? - ?????? ??????????????                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | None: The SmartConsole that holds it, is not in Chinese                                            |
| DISA Firewall STIG                                  | USA                                                     | Technical paper detailing guidelines to configure Firewalls                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | Yes                                                                                                |
| DORA 2023                                           | EU - Finance                                            | DORA is a regulation introduced by the European Union (EU) to create a standardized framework for managing cyber risks in the financial sector. It was created due to the increasing number of cyberattacks on financial institutions prompted the EU to take action. DORA aims to ensure financial institutions can withstand and recover from these disruptions.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | Yes                                                                                                |
| DSD                                                 | Australia                                               | Australia's top 35 IT security mitigation strategies.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Yes                                                                                                |
| Essential 8                                         | Australia                                               | The Australian Signals Directorate (ASD) has developed prioritized mitigation strategies to help organizations mitigate cyber security incidents caused by various cyber threats. The Essential Eight is an Australian cybersecurity framework developed by the Australian Cyber Security Centre (ACSC). It offers eight fundamental mitigation strategies to enhance organization's cyber resilience and significantly reduce the impact of cyberattacks.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | Yes                                                                                                |
| FIPS 200                                            | USA                                                     | A requirement under FISMA that requires Federal organizations to comply with the Recommended Security Controls specified in NIST 800-53.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | Yes                                                                                                |
| GDPR                                                | Global                                                  | **General Data Protection Regulation** - Directive 95/46/EC of the European Parliament and of the Council seeks to harmonize the protection of fundamental rights and freedoms of natural persons respecting the processing activities and to ensure the free flow of personal data between Member States.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | Yes                                                                                                |
| GLBA                                                | USA                                                     | US regulation related to Financial Privacy and Safeguards                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | Yes                                                                                                |
| GPG13                                               | UK                                                      | Good Practices Guide defines best practices from the UK government                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | Yes                                                                                                |
| HIPAA Security                                      | USA                                                     | Patient data protection act for Healthcare in the USA                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Yes                                                                                                |
| ICDM                                                | Israel                                                  | The Israeli Cyber Defense Doctrine 1.0 (ICDM) is a methodology for managing cyber risks in organizations in Israel. This document defines a coherent method which guides the corporate responsibility for the construction of a multi-year work plan for the protection of the organization. Using the method presented in this document, the organization will recognize the relevant risks, formulate a defense response and realize a program to reduce the risks accordingly.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | Yes                                                                                                |
| ICDM 2.0                                            | Israel                                                  | The Israeli Cyber Defense Doctrine 2.0 (ICDM 2.0) is a methodology for managing cyber risks in organizations in Israel. It is based on the NIST Cybersecurity Framework and is designed to help organizations identify, assess, and mitigate cyber risks. ICDM 2.0 is a voluntary framework, but it is being adopted by many organizations in Israel.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Yes                                                                                                |
| IDSML                                               | Insurance                                               | **INSURANCE DATA SECURITY MODEL LAW (IDSML)** act establishes standards for data security and standards for the investigation of and notification to the Commissioner of a Cybersecurity Event applicable to Licensees.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | Yes                                                                                                |
| IEC 62443-2-1                                       | International Industrial Automation and Control Systems | **IEC 62443-2-1:2010** defines the elements necessary to establish a cyber security management system (CSMS) for industrial automation and control systems (IACS) and provides guidance on how to develop those elements. This standard uses the broad definition and scope of what constitutes an IACS described in IEC/TS 62443-1-1. The elements of a CSMS described in this standard are mostly policy, procedure, practice, and personnel related, describing what shall or should be included in the final CSMS for the organization. This bilingual version (2012-04) corresponds to the monolingual English version, published in 2010-11.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | Yes                                                                                                |
| ISA TR99                                            | Global/Energy                                           | **ANSI/ISA-TR99.00.02-2004 - Integrating Electronic Security into the Manufacturing and Control Systems Environment Approved 10 October 2004** - To protect Manufacturing and Control Systems environments from potential threats and probability of attacks, each site or corporate entity should be responsible for developing an electronic security program and creating a security plan to protect manufacturing control networks. This ISA Technical Report provides a framework for developing an electronic security program and provides a recommended organization and structure for the security plan. The information provides detailed information about the minimum elements to include. Site or entity-specific information should be included at the appropriate places in the program.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | Yes                                                                                                |
| ISO 27001                                           | International                                           | International framework for the management of Information Security                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | Yes                                                                                                |
| ISO27001:2013                                       | International                                           | **ISO2001** standard was originally published jointly by the International Organization for Standardization (ISO) and the International Electro technical Commission (IEC) in 2005 and then revised in 2013. The standard aim is to help organizations make their information assets more secure, as it offers a risk-based approach to information security.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | Yes                                                                                                |
| ISO27001 2022                                       | International                                           | ISO 27001 is the international standard for information security, published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It provides a framework for organizations of any size or industry to manage their information security risks and protect their information assets.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Yes                                                                                                |
| ISO 27002                                           | Global                                                  | Implementation guidelines for each of the 133 control objectives defined within ISO 27001                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | Yes                                                                                                |
| ISO27002:2022                                       | International                                           | ISO/IEC 27002:2022 is a comprehensive standard designed to help organizations establish, implement, and maintain information security controls. This standard is part of the ISO/IEC 27000 family of standards, which are widely recognized for providing best practices in information security management. Below, we delve into the specifics of ISO/IEC 27002:2022, focusing on its structure, key controls, and attributes. ISO 27002 is an international standard that provides guidelines for organizational information security standards and information security management practices, including the selection, implementation, and management of controls, taking into consideration the organization's information security risk environment. It was revised and formally published in February 2022, replacing the previous version from 2013.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | Yes                                                                                                |
| IT Grundschutz - Security Gateway                   | Germany                                                 | The IT-Grundschutz-Kataloge, ('IT Baseline Protection Manual') is a collection of documents from the German Federal Office for Security in Information Technology (BSI) that provides useful information for detecting weaknesses and combating attacks in the information technology environment. The Compliance Blade looks at Module S3: IT Systems, and specifically at the requirement S.3.301 Security Gateway (Firewall). Check Point has used the 2013 English translation provided by BSI. This is a sample of the overall regulation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | Yes                                                                                                |
| Katakri 3.0                                         | Finland                                                 | Katakri 3.0 refers to the Finnish National Security Authority's National Security Auditing Criteria. Katakri is divided into four subdivisions: Administrative, Personnel, Physical, and Information Assurance. The mapping provided by Check Point has focused on Information Assurance. Katakri provides different levels of security requirements. The Check Point Katakri mapping is based on 'Requirements for the base level (IV)'.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | Yes                                                                                                |
| K-ISMS                                              | Korea                                                   | **Korea-Information Security Management System (K-ISMS)** Under Article 47 in the "Act on Promotion of Information and Communications Network Utilization and Information Protection" (Korean and English), the Korean government introduced the Korea-Information Security Management System (K-ISMS). A country-specific ISMS framework, it defines a stringent set of control requirements designed to help ensure that organizations in Korea consistently and securely protect their information assets. To obtain the certification, a company must undergo an assessment by an independent auditor who covers both information security management and security countermeasures. It covers 104 criteria, including 12 control items in 5 sectors for information security management, and 92 control items in 13 sectors for information security countermeasures. Some of these include examination of the organization's security management responsibilities, security policies, security training, incident response, risk management, and more. A special committee examines the results of the audit and grants the certification. The K-ISMS framework is built on successful information security strategies and policies, as well as security countermeasures and threat response procedures to minimize the impact of any security breaches. These have a significant overlap with ISO/IEC 27001 control objectives, but are not identical. K-ISMS is a more detailed investigation against requirements than it is a general ISO/IEC 27001 assessment. | Yes                                                                                                |
| LGPD (Brazil)                                       | Brazil                                                  | **Brazil's Lei Geral de Prote��o de Dados (or LGPD)** brings sorely needed clarification to the Brazilian legal framework. The LGPD attempts to unify the over 40 different statutes that currently govern personal data, both online and offline, by replacing certain regulations and supplementing others. This unification of previously disparate and oftentimes contradictory regulations is only one similarity it shares with the EU's General Data Protection Regulation, a document from which it clearly takes inspiration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Yes                                                                                                |
| MAAGTIC-SI                                          | Mexico                                                  | MAAGTIC-SI (Manual Administrativo de Aplicaci�n General en las materias de tecnolog�as de la informaci�n, comunicaciones y en la de seguridad de la informaci�n)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | None: The SmartConsole that holds it, is not in Spanish                                            |
| MAS TRM                                             | Singapore                                               | Technology Risk Management guidelines from the Monetary Authority of Singapore                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | Yes                                                                                                |
| Mauritius Data Privacy                              | Mauritius                                               | The Mauritius Data Privacy Act of 2004 is to provide for the protection of the privacy rights of individuals considering the developments in the techniques used to capture, transmit, manipulate, record or store data relating to individuals. The Compliance Blade specifically refers to Section 27 (1) (a) that deals with Data Security.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | Yes                                                                                                |
| N-CIPA                                              | USA                                                     | The Neighborhood Children's Internet Protection Act (NCIPA) places restrictions on the use of funding that is available through the Library Services and Technology Act, Title III of the Elementary and Secondary Education Act, and on the Universal Service discount program known as the E-rate (Public Law 106-554). These restrictions take the form of requirements for Internet safety policies and technology which blocks or filters certain material from being accessed through the Internet.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | Yes                                                                                                |
| NERC CIP                                            | USA                                                     | Cyber security requirements for Utility companies in the USA                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Yes                                                                                                |
| NERC CIP (v.5)                                      | USA                                                     | The NERC CIP (North American Electric Reliability Corporation critical infrastructure protection) plan is a set of requirements designed to secure the assets required for operating North America's bulk electric system. On November 22, 2013, FERC approved Version 5 of the critical infrastructure protection cybersecurity standards (CIP Version 5), which represent significant progress in mitigating cyber risks to the bulk power system. In 2014, NERC initiated a program to help industry transition directly from the currently enforceable CIP Version 3 standards to CIP Version 5. The goal of the transition program is to improve industry's understanding of the technical security requirements for CIP Version 5, as well as the expectations for compliance and enforcement.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |                                                                                                    |
| New York State Cybersecurity Regulation (NYDFS)     | N.Y.                                                    | The NYDFS Cybersecurity Regulation (23 NYCRR 500) is a new set of regulations from the NY Department of Financial Services (NYDFS) that places new cybersecurity requirements on all covered financial institutions. The rules were released on February 16th, 2017 after two rounds of feedback from industry and the public. Covered institutions must adhere to many of the new requirements by as early as August 28, 2017.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | Yes                                                                                                |
| NIS-2                                               | Europe                                                  | NIS-2 is the Network and Information Systems Directive 2, a piece of legislation from the European Union (EU) that aims to improve cybersecurity across the EU. It was adopted in 2022 and came into force in 2023.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Yes                                                                                                |
| NIST 800-41                                         | USA                                                     | Guidelines on Firewalls and Firewall Policy from NIST                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Yes                                                                                                |
| NIST 800-53 Revision 5                              | USA                                                     | The National Institute of Standards and Technology Special Publication 800-53 (NIST 800-53) is a set of guidelines recommending how U.S. government agencies and private sector organizations supporting federal contracts should manage and protect information systems and the data within those systems. NIST 800-53 has been through multiple rounds of revisions since it was first introduced to accommodate changes in technological innovations and data management best practices. The final version of the most recent revision - **NIST 800-53 Revision 5** - was initially introduced in 2020 and was open to public comment through October 1, 2021.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | Yes                                                                                                |
| NIST 800-171                                        | USA                                                     | Protecting Controlled Unclassified Information in Non-federal Information Systems and Organizations: The protection of Controlled Unclassified Information (CUI) while residing in non-federal information systems and organizations is of paramount importance to federal agencies and can directly impact the ability of the federal government to successfully carry out its designated missions and business operations. This NIST 800-171 Special Publication provides federal agencies with recommended requirements for protecting the confidentiality of CUI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Yes                                                                                                |
| NIST SP800-82                                       | Global/Energy                                           | **NIST Special Publication 800-82, revision 2** - Guide to Industrial Control Systems (ICS) Security - The ISM helps organizations use their risk management framework to protect information and systems from cyber threats. The cyber security guidelines within the ISM are based on the experience of the ACSC within ASD.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | Yes                                                                                                |
| NIST 800-82 R3                                      | US Federal Agencies                                     | NIST Special Publication 800-82 Rev3, titled "Guide to Industrial Control Systems (ICS) Security," provides guidance on how to secure Industrial Control Systems (ICS), including Supervisory Control and Data Acquisition (SCADA) systems, Distributed Control Systems (DCS), and other control system configurations such as Programmable Logic Controllers (PLC) used in industrial sectors and critical infrastructures. The primary purpose of NIST SP 800-82 Rev3 is to help improve the security of ICS systems and networks. This document is intended for use by ICS operators, system administrators, system integrators, and others involved in the design, deployment, or maintenance of ICS. It provides practical guidance on securing various types of ICS from cybersecurity threats while considering the performance, reliability, and safety requirements that these systems must meet.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | Yes <br />                                                                                         |
| NORMEN                                              | Norway Healthcare                                       | **Normen overview -** Established on January 1st, 2016, The Norwegian Directorate of eHealth (NDE) is a subordinate institution of our Ministry of Health and Care Services. The former eHealth division of The Norwegian Directorate of Health provided the nucleus from which the new Directorate of eHealth has evolved. The Norwegian Directorate of eHealth will implement the national policy on eHealth, establish the requisite standards, and administrate the use of eHealth methodology nationwide.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | Yes                                                                                                |
| NZISM                                               | New Zealand                                             | **New Zealand Information Security Manual -**The New Zealand Information Security Manual details processes and controls essential for the protection of all New Zealand Government information and systems. Controls and processes representing good practice are also provided to enhance the essential, baseline controls. Baseline controls are minimum acceptable levels of controls. Essential controls are often described as 'systems hygiene'.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Yes                                                                                                |
| PCI DSS                                             | Global                                                  | Global framework for the protection of credit card data (Download 3.1 [here](https://wiki.checkpoint.com/confluence/download/attachments/239337643/PCI-DSS%203.1.xml?version=1&modificationDate=1495702113000&api=v2) / Download 3.2 [here](https://wiki.checkpoint.com/confluence/download/attachments/239337643/PCI-DSS%203.2.xml?version=1&modificationDate=1495702092000&api=v2))                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Yes                                                                                                |
| PCI DSS 2.0                                         | USA                                                     | PCI DSS 2.0 (Payment Card Industry Data Security Standard Version 2.0) is the second version of the Payment Card Industry Data Security Standard (PCI DSS) released in October 2010.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | Yes                                                                                                |
| PCI DSS 3.0                                         | USA                                                     | PCI DSS 3.0 (Payment Card Industry Data Security Standard Version 3.0) is the third version of the Payment Card Industry Data Security Standard (PCI DSS) released in November 2013. (From R80.20, PCI-DSS 3.2)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |                                                                                                    |
| PCI-DSS 3.2.1                                       | International                                           | **PCI-DSS** is a legal obligation mandated not by the government but by the credit card companies. Any company that is involved in the transmission, processing, or storage of credit card data, must be compliant with PCI-DSS. PCI is divided into 12 main requirements, and further broken down into approximately 200 control areas. There are different levels of PCI compliance depending on the number of transactions that are being processed by the company.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Yes                                                                                                |
| PCI-DSS 4.0                                         | International                                           | **The PCI DSS 4.0** provides a baseline of technical and operational requirements designed to protect account data. While specifically designed to focus on environments with payment card account data, PCI DSS can also be used to protect against threats and secure other elements in the payment ecosystem.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | Yes                                                                                                |
| PPG234                                              | Australia                                               | This prudential practice guide (PPG) aims to assist regulated institutions in the management of security risk in information and information technology (IT). It is designed to provide guidance to senior management, risk management and IT security specialists (management and operational).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | Yes                                                                                                |
| Protection of Personal Information Act, 2013 (POPI) | South Africa                                            | The Protection of Personal Information Act, 2013, is an official act of the Republic of South African parliament. This report refers specifically to Chapter 3 (Conditions for Lawful Processing of Personal Information), and more specifically Condition 7.19, Security Safeguards - Security measures on integrity and confidentiality of personal information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | Yes                                                                                                |
| Russian Data Protection 17                          | Russia                                                  | ?????????? ??? ?????? ??????????, ??????????????? ??? ????????? ??????? ???????????? ?????????????? ?????? ? ??????? ???????????? ???????????? ?????? ????????? ????? 2013 ?. ? 17                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | None: The SmartConsole that holds it, is not in Russian. Also should be unified with "section 21". |
| Russian Data 21                                     | Russia                                                  | ?????????? ??? ?????? ??????????, ??????????????? ??? ????????? ??????? ???????????? ?????????????? ?????? ? ??????? ???????????? ???????????? ?????? ????????? ????? 2013 ?. ? 21                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | None: The SmartConsole that holds it, is not in Russian. Also should be unified with "section 17". |
| SAMA                                                | Saudi Arabia                                            | **Saudi Arabian Monetary Authority** established in May 2017 a Framework to facilitate Financial Institutions regulated by SAMA. SAMA established a Cyber Security Framework to enable Financial Institutions regulated by SAMA to effectively identify and address risks related to cyber security. The Framework is based on the SAMA requirements and industry cyber security standards, such as NIST, ISF, ISO, BASEL and PCI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | Yes                                                                                                |
| SANS Top 20 Critical Controls                       | USA                                                     | SANS Top 20 Critical Controls - SANS Institute, working in concert with the Center for Internet Security (CIS), has created a comprehensive security framework-the Critical Security Controls (CSC) for Effective Cyber Defense (often referred to as the SANS Top 20)1 -that provides organizations with a prioritized, highly focused set of actions that are implementable, usable, scalable, and compliant with global industry \& government security requirements. These recommended security controls also serve as the foundation for many regulations \& compliance frameworks, including NIST 800-53, PCI DSS 3.1, ISO 27002, CSA, HIPAA, and many others.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | Yes                                                                                                |
| SOX                                                 | USA                                                     | Refers to the IT controls defined in the CobiT framework. The framework supports governance of IT by defining and aligning business goals with IT goals and IT processes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | Yes                                                                                                |
| Statement of Controls (ISAE 3402)                   | Global                                                  | This report identifies the core control requirements of the Check Point Security Management, Security Gateways and Software Blades. All relevant security best practices have been mapped in line with Check Point recommendations. This report allows Check Point users to verify the status of their Check Point security environment and to ensure that it is in line with Check Point's recommendations.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Yes                                                                                                |
| TISAX                                               | Germany/Automotive                                      | TISAX (Trusted Information Security Assessment Exchange) is a global information security standard for the automotive industry developed by the Association of the German Automotive Industry.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | Yes <br />                                                                                         |
| UK Data Protection Act                              | UK                                                      | UK law that governs the protection of personal data                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Yes                                                                                                |

{#Unique_ID1Table}

(3) Configuration {#Configuration}
==================================

For configuration of the Compliance Blade, see the [Security Management Administration Guide](https://support.checkpoint.com/product/184#f-commonsource=C.%20Documentation) for your version.

(4) Troubleshooting {#Troubleshooting}
======================================

(4-1) Initial Installation of the Software {#Initial Installation of the Software}
----------------------------------------------------------------------------------

**What can go wrong?**

1. *Blade activation issues*   
   * **Symptom:**   
     In SmartConsole:  
     * In the Compliance Blade tab, you see the "`The compliance blade is not activated`" message, and you cannot navigate in the tab's pages
     * In the "**Logs \& Events** " / "**Logs \& Monitor** " view, when you open a new tab, the "**Open Compliance View** " is not displayed.   

   * **Troubleshooting:**   
     1. In SmartConsole, go to the "**Gateways \& Servers**" view.
     2. Double-click the Security Management Server object.
     3. On the "**Management** " tab, make sure the "**Compliance"** checkbox is selected.  
        Example:  
        ![](https://sc1.checkpoint.com/sc/SolutionsStatics//sk120256/Blade_activation_issues_31709050510.png)

   <br />

   <br />

2. *Connectivity to the Security Management Server / Multi-Domain Security Management Server*   
   * **Symptom:**   
     If the Security Management Server IP Address that the customer used to log in to the SmartConsole is not identical to the IP Address set on the Management object, there will be problems with connectivity to the Security Management Server.  
     1. If that is the case, you may still be able to log in and access the "Compliance" tab, but the message "`The compliance blade is not activated`" appears.
     2. This issue might appear when you configure the Security Management Server with two or more interfaces (one for logging in with SmartConsole and one to communicate with the managed Security Gateways).  
        Example:  
        ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120256/Connectivity_21709050316.png)

<br />

(4-2) Licensing {#Licensing}
----------------------------

*No license installed* error message

1. If no license is installed, the user will probably encounter this error message for the first time, when a user tries to access the Compliance Blade tab in SmartConsole.
2. Output of the "`cplic print`" CLI command is useful to troubleshoot such an issue.  
   The output should contain (at least) one of these license strings:  
   * CPSB-COMP-U
   * CPSB-COMP-150
   * CPSB-COMP-50
   * CPSB-COMP-25
   * CPSB-COMP-5

*Additional licensing issues: (conflicts, containers)*

* **Scenario 1: Single Management**   

  * ***You must purchase a Compliance Blade license according to the number of (supported) gateway objects.***   
    * The license is additive.
    * If the Management Server manages 3 Security Gateways, you must buy a 5-Gateway license.
    * If the Management Server manages 10 Security Gateways, you must buy a 25-Gateway license.
    * If you bought a 5-Gateway license, but you have 6 (or more) Security Gateways, the license will not work.
    * If you bought a 5-Gateway license, you already have 5 Security Gateways, and later you add a 6th Security Gateway object, then after the next scan, the license will cease to work.

    <br />

    <br />

  * ***Supported Objects: The Compliance Blade currently only supports regular Gateways and Clusters.***   
    * This means that currently, all other objects will not be taken into consideration when counting the licenses.
    * If this is a single Management Server with 50 managed Security Gateways, but only 5 are regular Security Gateways, and the other 45 are UTM-1 Edge devices, then you legitimately attach a 5-Gateway license, and it will work (because Check Point currently only counts "supported" objects).
    * For a Cluster object with two cluster members, the Compliance blade license would be counted for two Gateways.

  <br />

  <br />

* **Scenario 2: Multiple Managements (but not Multi-Domain Management)**   

  * A license must be installed on each Management Server (assuming you want to use the Compliance Blade on each Management Server).  

    * If you have a Management Server "A" with 5 Security Gateways, and a Management Server "B" with 20 Security Gateways, then you need to buy a 5-Gateway license for the Management Server "A", and a license for the Management Server "B" that is equal or greater than the numbers of Security Gateways attached to the Management Server "B".
    * **You cannot buy a 25-Gateway license and split it between the two Management Servers.**

    <br />

    <br />

  * All other comments for a Single Management Server apply.

  <br />

  <br />

* **Scenario 3: Multi-Domain Management**   

  * ***Whatever license is installed on the Multi-Domain Management container, is pushed down to all the connected Domain Management Servers.***   

    * If this a Multi-Domain Security Management Server with three Domain Management Servers "X", "Y", and "Z", and you install a 5-Gateway (or a 25-Gateway) license on the Multi-Domain Security Management Server, then this license is pushed down to each of these three Domain Management Servers.

    <br />

    <br />

  * ***Each Domain Management Server will be checked like a Single Management Server** (see above):*   

    * If a Domain Management Server manages 10 supported Security Gateways, and you install a 5-Gateway license on the Multi-Domain Security Management Server, the license will not work on this Domain Management Server.
    * Example:  
      This is a Multi-Domain Security Management Server with 20 Domain Management Servers. 19 of the Domain Management Servers have 3 Security Gateways each, and 1 Domain Management Server has 20 Security Gateways.
      * If you install a 5-Gateway license on the Multi-Domain Security Management Server, then the license is pushed to all 20 Domain Management Servers, but this license will work only on 19 of them (that have fewer than 5 managed Security Gateways).
      * If you install a 25-Gateway license on the Multi-Domain Security Management Server, then the license is pushed to all 20 Domain Management Servers, and this license will work only all of them.

    <br />

    <br />

(4-3) Post install - Initial Scan {#Post install - Initial Scan}
----------------------------------------------------------------

* The initial full scan begins about 2-3 minutes after the first installation. You will get a notification in the Compliance Blade regarding the need to wait for the full scan to finish.
* **A full scan can take between 2 - 5 minutes.**   
  During this time, the SmartConsole should work as usual.
* **The Compliance tab will not display any information until the scan is finished.**   
  After the Full scan is finished, the user can access the information in the blade, and he should not see a "`Full scan is in progress`" message at the top of the "Overview" page.

<br />

(4-4) Resolution issues {#Resolution issues}
--------------------------------------------

* **On my computer monitor, I cannot see information, data is cut off, etc. when the screen resolution is lower than 1366x768:**   
  The data may be cut off. This is relevant only in the "Overview" page (you can overcome this issue by collapsing the side menu).
* **Supported screen resolutions** :   
  Check Point SmartConsole \> "Compliance" tab supports two different thresholds of screen resolution:
  * 1366x768 (for laptops)  
    On the "Overview" page, the "**Action Items and Messages** " widget shows the actual records. Activate by using 3 buttons.  
    Example:  
    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120256/1366x7681709040121.png)
  * Higher than 1366x768  
    On the "Overview" page, the "**Action Items and Messages** " widget shows all the data with no buttons. The data regarding the "**Compliance Alerts \& Messages** " is a preview (contains short descriptions) and for the full details you need to access the menu items by the link.  
    Example:  
    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120256/Above_1366x7681709040123.png)

<br />

(4-5) Exclusions - Deactivating a Best Practice, or object within a Best Practice {#Exclusions - Deactivating a Best Practice, or object within a Best Practice}
----------------------------------------------------------------------------------------------------------------------------------------------------------------

* **Security Best Practice:**   
  If you have certain constraints that prevent you from configuring a Check Point Software Blade according to the recommendation, we allow you to exclude individual Security Best Practices, by clearing the "**Active** " field, along with the reason it should be excluded and for which period of time.  

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120256/Exclusions1709040125.png)   

  * **What happens behind the scenes when we "deactivate" a Security Best Practice?**   
    Changes will take effect only after a "save" and full scan (either nightly, or manually executed by the user on the "Settings" screen). The effects are: the "Action" Item regarding this Best Practice disappears, statistics in the "Overview" page should change accordingly, compliance of regulations should change as well.
  * **How is the overall score recalculated?**   
    Each Security Best Practice gets a grade (percentage) and is given a status according to the thresholds.  
    If the Security Best Practice is a Gateways / Profiles Best Practice, the grade is calculated as an average of the grades of each of its corresponding objects.   
    If the Security Best Practice is a Global Properties Security Best Practice, the grade is calculated according to the Security Best Practice description - It may be only "true/false". We give "0/100". There can also be levels for deciding the status according to the value tested.  
    Each Security Best Practice is assigned to one or more regulatory requirements.
  * **When is it recalculated?**   
    Next full scan.
  * **Expiration date for deactivation** :   
    Expiration date for deactivation can be set. The status of the Security Best Practice or object in Security Best Practice is not relevant in the calculation until the expiration date has passed. Again, the full scan will check the expiration dates and take this into account for the calculations.

  <br />

  <br />

* **Gateway**   

  * **After excluding a Security Gateway, do we need to actively perform a scan or is it automatic?**   
    You need to perform a scan. The Security Gateway's status is calculated as the average of all the Security Best Practices running on this Security Gateway. Meaning, Global Properties Security Best Practices are not included in the calculation. Security Best Practices that have been deactivated on a certain Security Gateway are not included in the calculation as well.

  <br />

  <br />

* **Regulation**   

  * **Status of a requirement:**   
    Each Security Best Practice is assigned to one or more regulatory requirements. The status of a requirement is calculated as the average score of all the Security Best Practices assigned to this requirement. The score is a percentage and translated into a status according to the same threshold's logic.
  * **How is the Regulation score impacted after a Security Best Practice is excluded? When does it change?**   
    After a Security Best Practice is deactivated (and full scan performed), the grade of the Regulation should be based on only the activated assigned Security Best Practices.
  * **After excluding a Security Gateway, do we need to actively perform a scan or is it automatic?**   
    After deactivating a Security Gateway, a "save" and full scan are needed to recalculate all the Security Best Practice results. After this is done, the Regulation results will change as well.
  * **Are any processes being generated in the background?**   
    No processes are being generated. The system waits for the full scan.

<br />

(4-6) Action Items {#Action Items}
----------------------------------

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120256/Action_Items1709040128.png)

* **When setting a date, is there a process being run in the background?**   
  No process is being run. The only effect of the due date is the distribution of the statistics in the "**Overview** " \> "**Action Item**".
* **Date format errors: where is the date format taken from?**   
  The dates/time is checked and compared with the Management Server's time.
* **Overdue: At what point is it considered overdue? End of day? Beginning of day?**   
  Date and time are entered. It is overdue based on the time set. This is server-based time.  
  * **How do the Action Items interact with the daily scan?**Once a Security Best Practice becomes 100% secure, its corresponding Action Item should disappear from the Action Items screen (in the menu).
  * **And the mini-scan?**   
    Once a Security Best Practice becomes 100% secure, its corresponding Action Item should disappear from the Action Items screen.

<br />

(4-7) Save in Other Blades {#Save in Other Blades}
--------------------------------------------------

* **When pressing Save, a mini-scan takes place. What is the process? How long should it take? What is normal, and what is abnormal (in terms of time range)?**   
  A mini-scan recalculates the relevant Security Best Practice (relevant to the objects changed in the last save). This process should take up to 30 seconds. At the end of the process, the user is notified if any Security Best Practice statuses have gotten worse with Security alerts.  
  **Some actions will require a full scan (no mini scan will be executed after the save):** Adding/removing Security Gateway objects, adding/removing blades in Security Gateway objects, deactivating Security Best Practice or Security Best Practice objects, IP Address changes in Profiles or Protections.
* **When is "post-save" information updated in the Overview and Security Best Practice windows?**   
  After the mini-scan is finished (or full scan, as well), the GUI and data is updated automatically.
* **Generation of Compliance Alerts - process involved?**   
  Part of the mini-scan (see above).
* **How the Save adds and removes Action Items based on the results** ?   
  See the section "Action Items".

<br />

(4-8) Report Generation {#Report Generation}
--------------------------------------------

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120256/Report_Generation1709040131.png)

* **How is the data generated?**   
  Based on the results in the last scan (what is viewed in the system at that moment).
* **Format issues?**   
  No export to Microsoft Word. Permissions issue may cause the generation of the report to fail.
* **Export to PDF issues?**   
  Some paging issues persist.
* **Export to email client?**   
  No issues.

<br />

(4-9) Excel Export {#Excel Export}
----------------------------------

* **What happens when I export data to Excel? Process involved?**   
  The Excel Export is based on the results in the last scan (what is viewed in the system at that moment).

<br />

(4-10) Gateway Favorites {#Gateway Favorites}
---------------------------------------------

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120256/Gateway_Favorites1709040133.png)

* **Process when I select / choose my favorites?**   
  The favorite Security Gateways are saved as part of SmartConsole configuration on the SmartConsole client computer for each logged in user.

<br />

(4-11) Inactive Objects {#Inactive Objects}
-------------------------------------------

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120256/Inactive_Objects1709040134.png)

* **When editing a comment / timeframe of an Exclusion, is there a process in the background that updates somewhere?**   
  Requires a full scan to take effect.
* **How does the software know when to cancel the exclusion (reached the due date)?**   
  Requires a full scan to take effect.
* **Deleting an Exclusion**   
  Requires a full scan to take effect. See the section "Exclusions - Deactivating a Best Practice, or object within a Best Practice".

<br />

(4-12) Install Policy {#Install Policy}
---------------------------------------

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk120256/Install_Policy1709040135.png)

* **When performing Install Policy, are there any GRC processes running that impact performance?**   
  No process is running.
* **Cancelling the Security Alerts post-install policy: What is the process here?**   
  Upon policy installation, the user can decide to view the compliance report/view current Security alerts / delete the current Security alerts. If delete Security alerts is chosen, the alerts are deleted from the database. No special process.

<br />

(4-13) Help File {#Help File}
-----------------------------

* **If the help text is not loading, what is it being linked to?**   
  Standard SmartConsole help. Not specific to Compliance Blade.

<br />

(4-14) Scoring {#Scoring}
-------------------------

* **Scoring errors**   
  Should not be any.

<br />

(4-15) "NA" Best Practices {#NA Best Practices}
-----------------------------------------------

* **When a Best Practice is displayed as "`NA`"**   
  **NA score:**   
  Security Best Practice / Security Best Practice object may receive an "`NA`" status in these situations:  
  * The security product is not enabled in the specific Security Gateway object.
  * Security Best Practices of type "OS" (Operating System) can only run on Check Point devices running the Gaia operating system, except for Scalable Chassis appliances 40000 / 60000 and Maestro Security Groups.  
    For example, Quantum Spark devices run the Gaia Embedded operating system, and therefore all OS best practices show "`N/A`" for each Quantum Spark Gateway object.

<br />

(4-16) Conditional Best Practices {#Conditional Best Practices}
---------------------------------------------------------------

**Dependent Best Practice:**   
A Security Best Practice can be dependent on another Security Best Practice status. The current Security Best Practice will be tested only if the dependent Security Best Practice is above a specified threshold. If it is not above that threshold, the current Security Best Practice will be "`NA`".

<br />

(5) Debugging {#Debugging}
==========================

(5-1) Rescan issues {#Rescan issues}
------------------------------------

* **Symptom:**   
  When trying to run rescan (SmartConsole \> "Manage \& Settings" \> "Blades" \> "Compliance" section \> "Settings" \> "Rescan"), the status changes to "`pending ...`" and rescan does not start after more than 20 seconds.   

* **Troubleshooting and Debug:**   
  1. Close all SmartConsole windows connected to the Security Management Server / Domain Management Server.
  2. On the Security Management Server, make sure that there are no processes named "`interpreter`".
     1. Connect to the command line on the Management Server.
     2. Log in to the Expert mode.
     3. Run:  
        `ps -auxw | grep interpreter`
     4. If such a process is running, kill it with this command:  
        `killall interpreter`
  3. In the [Database Tool (GuiDBedit Tool](https://support.checkpoint.com/results/sk/sk13009):  
     1. Connect with the Database Tool (GuiDBedit Tool) to the Security Management Server / Domain Management Server.
     2. In the top left panel, go to **Other** \> **grc_test_elements**.
     3. In the top right panel, sort the table by the **Object Name** column.
     4. Look for an object named "**grc_interpreter**" (there should be only one) and click it one time (to select it).
     5. In the bottom panel, look for the object "**status**".
     6. Right-click that field and click **Reset** .  
        The value should change to "**Finished** ".  
        Example:  
        ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk92861/image005.png)
     7. Save the changes: go to the **File** menu \> click **Save All**.
     8. Close the GuiDBedit Tool.
  4. Enable debug:  
     In R82.10:  
     run mgmt_cli set compliance-settings "debug-mode" true  

     In R77 and higher:  
     Modify the "*grc.conf* " file to enable debug:
     1. On the Management Server, stop all Check Point services:
        * On a Security Management Server:  
          `cpstop`
        * On a Multi-Domain Security Management Server:  
          `mdsstop_customer <IP Address or Name of Domain Management Server>`
     2. On a Multi-Domain Security Management Server, go to the content of the relevant Domain Management Server:  
        `mdsenv <IP Address or Name of Domain Management Server>`
     3. Back up the current "*grc.conf* " file:  
        `cp -v $FWDIR/conf/grc.conf{,_BKP}`
     4. Edit the current "*grc.conf* " file:   
        `vi $FWDIR/conf/grc.conf`
     5. Set the value of the parameter `debugMode` to "1":  
        `debugMode=1`
     6. Save the changes in the file and exit Vi editor.
     7. On the Management Server, start all Check Point services:
        * On a Security Management Server:  
          `cpstart`
        * On a Multi-Domain Security Management Server:  
          `mdsstart_customer <IP Address or Name of Domain Management Server>`
  5. Connect with SmartConsole to the Security Management Server / Domain Management Server.
  6. Navigate to the **Manage \& Settings** view \> **Blades** \> **Compliance** section \> click **Settings** \> click **Rescan**.
  7. Wait for the scan to finish.
  8. Disable debug  
     In R82.10:  
     run mgmt_cli set compliance-settings "debug-mode" false  

     In R77 and higher:  
     Modify the "*grc.conf* " file to disable debug:
     1. On the Management Server, stop all Check Point services:
        * On a Security Management Server:  
          `cpstop`
        * On a Multi-Domain Security Management Server:  
          `mdsstop_customer <IP Address or Name of Domain Management Server>`
     2. On a Multi-Domain Security Management Server, go to the content of the relevant Domain Management Server:  
        `mdsenv <IP Address or Name of Domain Management Server>`
     3. Edit the current "*grc.conf* " file:  
        `vi $FWDIR/conf/grc.conf`
     4. Set the value of the parameter `debugMode` to "0":  
        `debugMode=0`
     5. Save the changes in the file and exit Vi editor.
     6. On the Management Server, start all Check Point services:
        * On a Security Management Server:  
          `cpstart`
        * On a Multi-Domain Security Management Server:  
          `mdsstart_customer <IP Address or Name of Domain Management Server>`
  9. Get the relevant log files from the Management Server:
     * On a Security Management Server
       * `$FWDIR/log/fwm.elg.*`
       * `$FWDIR/log/grc_interpreter.elg*`
     * On a Multi-Domain Security Management Server (enter the correct values):
       * `/opt/CPmds-<YOUR_VERSION>/customers/<YOUR_DOMAIN>/CPsuite-<YOUR_VERSION>/fw1/log/fwm.elg.*`
       * `/opt/CPmds-<YOUR_VERSION>/customers/<YOUR_DOMAIN>/CPsuite-<YOUR_VERSION>/fw1/log/grc_interpreter.elg*`
  10. Connect with SmartConsole to the Security Management Server / Domain Management Server.
  11. In the `fwm.elg` log files, look for this string:  
      `interpreter was requested to rerun`  
      * If this string appears in the file, it is necessary to look for additional information about the cause of the problem in this log file.
      * If this string does not appear in the file, or if this the string "`no pending requests found`" appears, then [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/).

<br />

(6) Important Notes {#Important Notes}
======================================

* The Compliance blade supports VSX Gateways / VSX Clusters.  
  By design, the "Security Best Practices" for "Gaia OS" are **not** checked on VSX Gateways / VSX Clusters.
* The relevant object for Application Control and URL Filtering practices are the Policies, because you need to handle them per policy (and not per Policy Layer).  
  As for Inline Layers, the parent rule of Inline Layers is usually not "`Src = 'Any' Dst ='Any' or 'Internet'`". Hence, even though the rule in the Inline Layer states "`Src = 'Any' Dst ='Any' or 'Internet'`", the traffic that reaches the Inline layer for matching may be skipped because of the parent definition.

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
