Software Secure Workload
Activity Configure

Segmentation Compliance Score

Segmentation Compliance Score presents a top-level view of policy violations and emphasizes which scopes and workspaces have the most violations.

Segmentation Compliance Score Details
Figure 1: Segmentation Compliance Score Details

 

Escaped/Rejected/Permitted count that is displayed on security dashboard for root scope does not add up to all the counts respectively displayed for all child scopes. Escaped/Rejected/Permitted count is an evaluation on the policy and not just on source or destination.

Lower score indicates:

  • Significant number of escaped flows (policy violations) relative to permitted

  • Score is 0 when more escaped flows than permitted.

Segmentation Compliance Score is computed for scopes with an enforced primary workspace. For scopes without enforced workspaces, the score will be computed as the average of descendant scope scores with enforced policies.

Score is computed by using the ratio between escaped and permitted.

Segmentation Compliance Score Formula
Figure 2: Segmentation Compliance Score Formula

Improve score by reducing number of policy violations

  • Verify policies correctly cover desired behavior.

  • Verify that policies are correctly being enforced.

Help for Segmentation Compliance Score Details
Figure 3: Help for Segmentation Compliance Score Details