Solutions
FortiGate hardening with standards-mapped evidence
Identify configuration weaknesses and see where applicable ConfigSentry rules map to recognised benchmarks, control frameworks, and requirements—including individual references such as CIS FortiGate Benchmark section 2.1. Use the findings to support remediation and review without treating configuration checks as a compliance certification.
Hardening coverage
Review the settings that define the FortiGate security baseline
ConfigSentry evaluates the active configuration rather than relying only on intended design, policy documents, or change records. The applicable checks depend on the device configuration, selected audit template, FortiOS version, and enabled standards.
Administrator authentication
Identify administrator accounts that lack MFA or an approved external authentication path, and review whether default or weak administrative access remains available.
Management access restrictions
Review trusted hosts, management source networks, interface access, and insecure protocols such as HTTP or Telnet.
Password and account controls
Check whether relevant password policies, account protections, and administrative security settings meet the expected baseline.
Logging and audit visibility
Find logging gaps that reduce accountability, investigation capability, and the evidence available during security or compliance review.
Policy and service hardening
Surface overly broad access, unsafe services, weak policy controls, and other configuration choices that undermine least privilege.
Operational security hygiene
Identify issues such as certificate expiry, weak cryptographic settings, backup gaps, and other conditions that weaken the operational baseline.
Standards mapping
See which recognised guidance an applicable rule supports
Where there is a meaningful relationship, a ConfigSentry rule may be tagged with one or more standards and the relevant control, section, or recommendation reference. The mapping supplements the technical finding; it does not replace the evidence or remediation detail.
Benchmarks and vendor guidance
- CIS FortiGate Benchmark
- DISA STIG
- Fortinet Best Practices
Security and control frameworks
- CIS Controls
- ISO 27001
- NIST 800_53
Regulatory and industry requirements
- HIPAA
- PCI DSS
- SOX
Coverage varies by audit. A standard appears only where the selected template contains applicable mapped rules and the rule is relevant to the FortiGate configuration being assessed.
This illustrates the mapping format. The actual rule title, standards, and references depend on the applicable rule.
Reviewable evidence
Keep the technical finding at the centre of the compliance conversation
A standards label is useful only when it remains connected to the configuration state that was actually tested. ConfigSentry findings retain the technical result, affected scope, supporting evidence, and remediation guidance.
Engineer reports provide detailed technical output, while executive reports summarise risk and standards alignment for governance, management, and wider audit preparation.
- Identify mapped checks that passed, failed, or require review
- Trace applicable findings to individual standards references
- Review the observed configuration and affected FortiGate scope
- Use remediation guidance to plan and verify corrective work
- Retain engineer and executive reports as review evidence
Ongoing assurance
Hardening is a state to maintain, not a one-time exercise
Normal firewall administration, upgrades, support changes, exceptions, and policy updates can move a FortiGate away from its approved baseline.
-
01
Establish the current state
Run an audit to identify hardening weaknesses and the applicable standards mappings present in the selected template.
-
02
Verify remediation
Rerun the same deterministic checks to confirm that a weakness was actually corrected rather than relying only on a completed change record.
-
03
Detect regression and drift
Use scheduled or change-triggered audits to identify when later configuration changes cause a previously passing control to fail again.
Important boundary
Standards mapping supports assessment; it does not certify compliance
ConfigSentry shows where an applicable rule supports assessment of a benchmark recommendation, control, or security objective. This can help with technical review, evidence gathering, remediation tracking, and preparation for wider governance or compliance assessments.
Compliance can also depend on organisational scope, policies, procedures, documentation, compensating controls, physical safeguards, and requirements that cannot be determined from a FortiGate configuration alone. ConfigSentry does not certify a firewall, environment, or organisation as compliant and does not replace an independent assessor.
Try the workflow
Run a FortiGate audit and review the findings
The focused free audit demonstrates the ConfigSentry workflow and both report formats. Paid templates provide a broader set of checks and standards-mapped rules.