Are Your Security Controls Actually Working?

Infographic illustrating the validated East-West risk assessment process in network security, highlighting key components such as ACI Fabric, PBR Redirection, Firewall Inspection, and Governance Intelligence.

A few weeks ago, I was asked by a GRC consultant a simple question:

Is our East-West traffic truly controlled—or are we just assuming it is?

On paper, everything looked correct. ACI was enforcing policy, PBR was redirecting traffic to the firewall, and FortiGate VDOMs were segmenting environments. But I wanted proof—not assumptions.

So I built an end-to-end validation model:

ACI Fabric → PBR → Firewall → Policy Intelligence → GRC Evidence

To make this repeatable and evidence-driven, I developed an automated pipeline that correlates firewall policies with live runtime traffic across all VDOMs. This shifted the approach from static configuration review to continuous validation.

The findings were clear:

✔ Enforcement exists
✔ Traffic is inspected
❗ But policy precision needs refinement

A small number of active policies allow broader-than-intended access—particularly toward identity and infrastructure services like AD, DNS, and PKI.

Most importantly, these are not theoretical risks—they are validated by real session data.

This transformed the conversation:

From “Do we have firewall rules?”
To “Are those rules aligned with least privilege?”

Today, I don’t just see the network—I understand how it behaves.

I turned firewall configuration into governance intelligence.

The real risk isn’t missing controls—it’s believing they’re already working.

-Mohammad Iqbal

Leave a Reply

Discover more from IT Infrastructure

Subscribe now to keep reading and get access to the full archive.

Continue reading