Read, measure, prove.
Three things, in that order. TIENOOC reads what runs, measures it against the norm you recorded, and keeps what it found, so you can use it later.
How TIENOOC can be of service
The standard, when you want it
A new network is built to the company standard: the naming convention, the VLANs and the IP plan as designed, the configuration as the baseline prescribes. After a few months, sometimes after weeks, the deviations start. A quick fix, a temporary rule, a name that is just a little different. After a year or two you cannot see the wood for the trees. TIENOOC lays, whenever you want, the standard next to every device and shows where it has drifted: name, VLAN, subnet, configuration. Not as a list of a thousand lines, but per device, with the fix next to it.
Hundreds of devices, one norm
TIENOOC measures hundreds of switches, firewalls, routers, load balancers, wireless controllers and proxies against the same baseline, and lays that baseline itself next to the vendor's best practice. Where your norm is weaker you see the gap, and with one click you adopt the stronger control, fix configuration included.
The firewall, rule by rule
Thousands of rules, objects and service groups, spread over many tabs. TIENOOC goes through the whole set, finds the inconsistencies against your baseline, summarises them, and comes with a proposal for improvement: which rules, what to change, and why.
The periodic report
Do you have to show every quarter, or every six months, that the policies and rules on your firewalls, proxies and other security systems still conform to the standard? TIENOOC tests them against your baseline at the moment you set and delivers the report: what conforms, what deviates, and what changed since the previous report.
The functions, in a row
- Tests configuration of every network system against your baseline and against best practice, line by line.
- Tests your company standards naming of devices, VLANs, hosts and objects, the VRF register, the security matrices and the services allowed per host function.
- Tests design against built the design workbook next to the configuration: what is missing, what is extra, what differs.
- Analyses firewall rules allow-all, shadowed and dead rules, order, disabled rules, logging per rule.
- Analyses and validates the IPAM the content of the IPAM against the company standard and the baseline: every subnet against the site and VLAN registers and the IP plan.
- Tests the CMDB what is recorded against what is there: does the hardware exist, is it online, and does it sit at the recorded location.
- Follows change every run against the previous run of the same system: new, solved, worse, better.
- Gives the fix per finding the configuration that solves it, and an exception register for what you accept.
- Proves it reports in PDF or Word with a digest, each finding tied to IEC 62443-3-3, NIST 800-82r3 and NIS2; on a schedule.
What it reads
Every kind of network system, whatever the brand. Per kind, what TIENOOC reads:
| Kind of system | What is read |
|---|---|
| Firewalls | Management access, crypto, logging, NTP, SNMP, policies, zones, objects, access lists |
| Switches | Hardening, AAA, SNMP, NTP, logging, VLANs, interface hardening, naming |
| Routers | Hardening, AAA, SNMP, NTP, logging, VRFs and leaks, routing, naming |
| Load balancers | Management access, logging, NTP, virtual servers and their rules |
| Wireless controllers | Controller hardening and WLAN security |
| Proxies and cloud security | Filtering rules and their order |
| CMDB | The records against reality: whether the hardware exists, is online and sits at the recorded location, and whether name, model and site match the company standard |
| IPAM | The content of the IPAM, analysed and validated against the company standard and the baseline: every subnet against the site and VLAN registers, the IP plan, naming and what does not belong there |
What it measures against
Your baseline
The Baseline catalog holds your norm: the firewall rule standard, the security matrices for zone, VLAN and VRF, naming for devices, VLANs, hosts and objects, the VRF register, host services per function, and a reference configuration per model and switch function. Imported from your own Word or Excel, or written on the spot.
Best practice
A COONEIT profile per platform, built from vendor guidance and the standards. Where your baseline is weaker, TIENOOC shows the gap. Adopt a control and it enters your baseline at best-practice strength, fix configuration included.
Design versus built
Open the design workbook and the firewall configuration together. TIENOOC lays them side by side: rules in the design that are not on the device, rules on the device that are not in the design, and rules that differ.
Standards
Findings carry the clause they touch in IEC 62443-3-3, NIST 800-82r3 and NIS2, so a report speaks the auditor's language without a second translation.
What you get back
Per device, per line
A score and a band, and under it every check: what was found, why it matters, and the configuration that fixes it. Accept a risk and it moves to the exception register with who and when.
Since the previous run
Every run is compared with the previous run of the same device: new, solved, worse, better. The dashboard shows the estate the same way: compliance, coverage and what needs attention.
Evidence
A report per run and per fleet, in PDF or Word, with a digest that shows it was not edited afterwards. Runs on a schedule, as often as you want.
Guide me
Every screen explains itself: press Guide me, then click a subject on the page. We do not send you into the woods with a map; we walk with you and bring you where you want to be.