Reviewing the Web score calculation

Web score measures if the recommended configurations and policies with respect to the SWG capabilities in Forcepoint ONE SSE are implemented.

Each recommended configuration is weighted at 33.33% in the SWG score and approximately 6.66% of the total available web score when all components are enabled.

If you are not leveraging Forcepoint ONE SSE for SWG, then consider disabling the Web score from your overall security index calculation.

When using Forcepoint ONE SSE SWG, then review the recommended configurations and ensure it is applicable for your deployment. If not consider disabling the non-applicable measure.

All HTTP/S Inspection

All HTTP/S Inspection measures whether inspection of Web Traffic has been enabled.

Configure the SmartEdge agent to monitor all HTTP/s traffic. You can do so by selecting the All HTTP/S Traffic mode under Protect > Forward Proxy > SmartEdge Proxy page in Forcepoint ONE SSE.

In the following image, the All HTTPS Traffic mode enabled on a tenant.



To configure SmartEdge Agents on users’ devices, refer to Deploying SmartEdge Agent.

Data Protection

Data Protection measures whether Data Protection policies are applied to your web traffic.

Configure a SWG Content Policy with Secure App Access and select data patterns to act on data exfiltration.

For example, the following images display a SWG Content Policy line with Secure App Access to deny download and upload actions when any data pattern identifying sensitive data was matched.





Threat Protection

Threat Protection measures whether Malware policy is applied to your web traffic.

Configure a SWG Content Policy with Secure App Access and select Malware Data Pattern to block download of Malware.

For example, the following images display a SWG Content Policy line with Secure App Access to deny download and upload actions when a malware data pattern was matched.





To configure SWG Content Policy, refer to Configuring a SWG Content Policy.