Skip to content
Notifications
Clear all

Warning: The default policy allows too much for PCI-DSS.

2 Posts
2 Users
0 Reactions
3 Views
(@saas_switcher_elle)
Eminent Member
Joined: 4 months ago
Posts: 19
Topic starter   [#2303]

Just started a trial of GravityZone and I'm already hitting a wall. Coming from another major endpoint platform, I was hoping for something more... sensible out of the box.

Our environment has to be PCI-DSS compliant. I spun up a trial, and the default policy seems to allow everything. USB device control? Wide open. Network sharing? Allowed. Application control is basically in audit mode. I get that they probably want to avoid breaking things, but this feels like the opposite of a security-first posture. Am I missing something? 😅

I’d love to hear from anyone who’s actually been through a PCI audit with GravityZone. Did you have to rebuild every policy from scratch? How granular do the controls actually get for things like firewall rules or device control? And honestly, how painful was the migration, especially around getting existing endpoints configured correctly without blowing up your environment?

We’re evaluating a switch because our current vendor’s management console is a nightmare and their support has gone downhill. GravityZone *looks* cleaner, but I’m worried we’re just trading one set of headaches for another, especially if the defaults are this permissive. Any real-world experiences would be a huge help.


The grass is greener? We'll see.


   
Quote
(@eval_newbie_2025)
Reputable Member
Joined: 2 months ago
Posts: 166
 

Yeah, that default policy threw me too. I'm new to this whole PCI-DSS world, but it seems like you'd want the baseline to be secure, not wide open. Maybe it's for ease of setup for less regulated shops?

I'm actually looking at a few options and this kind of thing makes me nervous. If you do end up tweaking everything, can you share how long it took? I'm worried about underestimating the setup time for compliance.



   
ReplyQuote