Audit Models

Choose the right audit model

Use this page to compare manual upload, collector-based retrieval, and continuous monitoring, and to see how teams structure review over time.

Common approaches

How firewall audit models differ

Most teams use some combination of these approaches over time.

Capability
ConsistencyHow repeatable the outcome is
SpeedHow fast review can happen
DepthHow much meaningful insight you tend to get
Ad hoc manual review
Low
High
Low
Checklist-based review
Medium
Medium
Medium
Compliance-oriented review
Medium
Medium
Medium
Risk-focused security review
Medium
Medium
High
Repeatable structured analysis
High
High
High

Common models

Five ways teams usually approach FortiGate firewall review

01

Ad hoc manual review

Fast for small changes, but highly dependent on individual experience and easy to make inconsistent.

Useful only in limited situations

02

Checklist-based review

More consistent than ad hoc review, but still often slow and difficult to scale across many configurations.

Better governance, still manual

03

Compliance-oriented review

Strong for audit readiness and control alignment, but can miss broader operational improvement opportunities if used alone.

Good for assurance conversations

04

Risk-focused security review

Useful for hardening and operational risk reduction, but still depends on consistent technical criteria.

Better for real-world exposure analysis

05

Repeatable structured analysis

This is where ConfigSentry adds strong value: more repeatable review, clearer findings, and easier comparison over time.

Best for repeatability and clarity

Why the model matters

The right model helps teams answer the questions that actually matter

Can we repeat this review later and get comparable results? Can we show stakeholders the major risks? Can we tell whether posture is improving?

A stronger audit model reduces dependence on memory, personal habits, and inconsistent review quality.

Choose a path

Start with the right review path, then grow into the right review habit

Many teams begin with standalone audits and move into continuous monitoring once they want more regular visibility and stronger repeatability.