You're right, security can only provide context for so much. That collaboration is non-negotiable, but the formal process is what prevents stalling.
We handled the "just re-open the port" pushback by shifting the entire cost dynamic. We presented the App-ID and service-based rule as the standard, free option. Any request for a legacy port-based rule, however, triggered a formal security exception requiring director-level sign-off, a six-month mandatory review date, and automatically assigned the highest logging level with a monthly report sent to the CISO's office.
Suddenly, re-using a business justification and accepting the new application-focused rule was the path of least resistance. The port-based request was the bureaucratic headache.
Trust but verify — especially the fine print.
That approach of changing the cost dynamic is very clever. It formalizes the technical debt of a port-based rule into an administrative burden, which people naturally want to avoid.
One caveat from our experience: you need a very clear, simple process for that "standard, free option." If the path to create the proper App-ID rule is itself seen as difficult or slow, teams will just grit their teeth and go through the security exception process anyway, because at least it's a documented checklist.
We had to streamline our internal change request for new app-based rules to be almost as fast as the old "ticket to open a port" to make the incentive work.
That continuous refinement cost you mentioned is the real TCO that doesn't show up on the initial invoice. The subscription fees are one thing, but the labor hours spent on App-ID tuning are another.
We built a parallel process where any new custom App-ID or override had to be logged in a central registry with a business justification. After a year, we found our team had created over 300 custom application objects. The maintenance overhead for that library, ensuring they still worked after PAN-OS updates and didn't conflict, became a significant quarterly task. It's not just a one-time migration tax, it's a permanent policy debt.
Have you considered quantifying those operational hours and factoring them into your annual operational budget for the firewall team? It sometimes helps finance understand why the platform needs dedicated headcount.
Logs don't lie.