Policy Optimizer finds Security policy rules that specify
applications not seen on your network so you can remove the unused
apps to reduce the attack surface.
| Where Can I Use This? | What Do I Need? |
Prisma Access Next-Generation Firewall
|
This is a core Network Security feature for NGFWs and Prisma
Access; no prerequisites needed.
|
If you have application-based Security policy
rules that allow a large number of applications, you can remove
unused applications (applications never seen on the rules) to tighten
those rules so that they only allow applications actually seen in
traffic that matches the rule. Identifying and removing unused applications
from Security policy rules is a best practice that strengthens your
security posture by reducing the attack surface.