Network Security Policy Management (NSPM) compliance software
See what your firewalls actually permit: multi-vendor rule analysis, path and exposure risk, governed change, and segmentation evidence in one workspace.
- Module typeOperational workspace (product module)
- Policy modelVendor-neutral canonical rules, objects, services and zones
- CollectionSSH with host-key pinning, management stations, API, syslog, uploaded configs, remote site collectors
- AnalysisHygiene, path, exposure, segmentation, attack path, drift, optimisation
- GovernanceChange requests, four-eye approval, scoped RBAC, segregation of duties, tamper-evident audit
- OutputFindings register, remediation register, framework-mapped compliance, CSV/XLSX/HTML/PDF reports
What NSPM requires
Who it applies to
- Network and security operations teams managing multi-vendor firewall estates
- Banks, telcos and regulated enterprises evidencing segmentation for ECC, ISO 27001, PCI DSS or SAMA
- Organisations with geographically dispersed sites the central platform cannot reach directly
- Teams replacing spreadsheet-based firewall rule reviews and recertification
- Enterprises consolidating governance across Fortinet, Palo Alto, Cisco, Huawei, F5 and virtual estates
Network Security Policy Management is GRCLens's operational workspace for firewall and network-policy governance. It collects configurations from a multi-vendor estate, normalises them into one vendor-neutral policy model, and runs every analysis on that model, so a Fortinet rule, a Palo Alto rule and a Cisco ACL are compared on the same terms rather than through four different consoles.
The purpose is visibility and operational efficiency. A rulebase that has accumulated for a decade contains rules nobody can explain, rules shadowed by something above them, temporary exceptions that outlived their ticket, and permissions far wider than the request that created them. NSPM surfaces those with severity and context, traces what a given flow would actually hit device by device, and shows where an internet-facing rule reaches a segment it should not.
Compliance frameworks ask whether network access is restricted and segmented. NSPM answers from the live rulebase rather than from a diagram: per-device checks against ISO 27001, NIST 800-53, PCI DSS and SOC 2, a segmentation matrix and service policy you author yourself, and findings that carry owner, severity and evidence into the same assurance discipline as the rest of the platform.
Change is governed rather than observed after the fact. Requests carry impact analysis before approval, four-eye approval before deployment, validation and a dry run before anything is written, and rollback if it is. Independently, every detected change is correlated against approved requests and classified authorised, unauthorised or unverifiable, the third is never reported as the first.
How GRCLens supports NSPM
NSPM runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Multi-vendor collection
Fortinet FortiGate, Palo Alto PAN-OS, Cisco ASA and IOS/IOS-XE, Huawei VRP, OPNsense, F5 BIG-IP and HAProxy, plus Panorama, FortiManager and Cisco FMC as management stations and VMware NSX and Cisco ISE over their APIs. Collection is read-only, over SSH with the device's host key pinned on first use and a changed key refused rather than healed.
Rule hygiene analysis
Overly permissive, shadowed, duplicate, unused, expired-temporary, undocumented and unlogged rules, each with severity, risk score and the reason it was raised. Hit counts come from live syslog, so an unused rule is one the traffic agrees is unused.
Path and exposure analysis
Trace a source, destination and service through the estate and see which device and which rule decides the verdict. Internet exposure and a trust matrix show where untrusted networks reach internal or restricted segments, and attack-path simulation walks the policy graph for chains that no single rule review would catch.
Your segmentation policy, measured
A zone-pair matrix and an allowed-services policy you author yourself, evaluated against the real rulebase. A zone pair no policy row mentions is reported as ungoverned rather than as compliant, because an empty policy must never score a perfect estate.
Governed change
Change requests with what-if impact analysis, four-eye approval, deployment validation, dry run first, and rollback. Deployment is disabled by default and enabled per device deliberately, a platform that can write to a firewall should make that an explicit decision.
Unauthorised change detection
Every detected change is correlated against approved requests by device, approval window and ticket reference, and classified authorised, unauthorised or unverifiable. Unverifiable, a change that predates the approval record, is never counted as compliant.
Rule documentation and recertification
Twelve fields per rule: business justification, owner, business unit, environment, classification, risk, change number, expiry and review dates. Expiring and expired rules surface as findings, so recertification is a worklist rather than an annual spreadsheet.
Topology and observed traffic
A live map built from three distinct sources kept distinct: what the customer declares, what SNMP, LLDP and CDP discover, and what syslog shows actually flowing. Policy-permitted and observed flows are overlaid, so a rule permitting traffic nobody sends is visible as exactly that.
Continuous improvement
A ranked cleanup plan with the safest wins first, golden baselines with drift reporting against an approved standard, and a remediation register that tracks a finding from raised to closed with evidence, the assurance loop applied to network policy.
Distributed sites
For sites the platform cannot reach directly, a collector runs inside the site and submits over outbound HTTPS only, nothing connects inward. Results are queued locally through a WAN outage and replayed with their original collection time, and a collector that stops checking in takes its devices to Not reporting rather than leaving a pre-outage configuration on screen as the live estate.
Framework mapping and evidence
Per-device rulebase checks against ISO 27001, NIST 800-53, PCI DSS and SOC 2, with manual attestation and evidence upload where a control needs human judgement. Findings and posture attach to the ECC, IEC 62443, OTCC and PCI assessments that ask about segmentation.
Integration and alerting
CEF syslog to a SIEM, signed SOAR webhooks, email, SNMP traps with a published MIB, and SMS for critical findings. A finding can be raised as a ServiceNow incident or a Jira issue, de-duplicated so the same problem never files a second ticket.
Governance of the platform itself
Scoped role grants with segregation-of-duties conflict detection, so the person who requests a change cannot be the one who approves it. The audit log is hash-chained and independently verifiable, retention is configurable per tenant, and every credential is encrypted at rest.
NSPM frequently asked questions
Is NSPM a compliance framework?
No: it is an operational module. It provides the network-policy evidence that framework assessments such as NCA-ECC, ISO 27001, PCI DSS and IEC 62443 rely on, and its findings attach to the controls that ask about network segmentation and access restriction.
Which firewalls and devices are supported?
Fortinet FortiGate, Palo Alto PAN-OS, Cisco ASA, Cisco IOS and IOS-XE, Huawei VRP, OPNsense, F5 BIG-IP and HAProxy are parsed into the canonical model. Panorama, FortiManager and Cisco FMC are supported as management stations, and VMware NSX and Cisco ISE are onboarded over their APIs. Configurations can also be uploaded directly.
Does NSPM replace our firewall manager?
No. Day-to-day administration stays in your management tools. NSPM governs and evidences policy quality, risk and compliance across all of them at once, and can push an approved change with validation and rollback where you choose to enable it.
Can it collect from branch sites we cannot reach from the data centre?
Yes. A collector runs inside the site and connects outbound to the platform over HTTPS; nothing connects into the site and no inbound firewall rule is needed. It queues results locally if the site loses connectivity and replays them on reconnection, and the platform reports a site that stops reporting rather than presenting its last-known configuration as current.
How does it tell an approved change from an unauthorised one?
Each detected change is correlated against approved change requests by device, approval window, the rules named in the request and the ticket reference in the rule comment. The result is authorised, unauthorised or unverifiable, the last meaning the change predates the approval record, which is reported as its own state rather than counted as compliant.
Can it push rule changes to a firewall?
Yes, where you enable it. Deployment is disabled by default and turned on per device, runs a validation and a dry run before anything is written, and supports rollback. The platform is read-only until that decision is made deliberately.
How do findings reach the auditors?
Findings carry owner, severity, status and evidence, flow into a remediation register, and can be referenced from control assessments. Reports export to CSV, XLSX, HTML and PDF, and the audit log behind them is hash-chained so its integrity can be verified independently.
Does it work on premise?
Yes. The platform deploys on premise as a self-contained bundle with no dependency on a public cloud service, which is how it is delivered for banks and critical-infrastructure operators that cannot place policy data outside their own estate.

Talk to us about NSPM
Security Solution Consultants provides Network security advisory services alongside the platform, so you can combine tooling with hands-on expertise.