Fortify 24x7 stands behind this storefront. Controls presented, worked, and reconciled entry by entry.Open your recordWrite to an engineer
FinShield Tech
Session 02 / Execution approval

Nothing your practice never approved gets an opinion on whether it starts.

Most controls ask what a program is. This one asks whether anybody said yes to it. ThreatLocker holds a list of the software your office genuinely uses and refuses everything outside it at the moment of execution, which closes the gap between a novel piece of malware appearing and somebody producing a signature for it.

ThreatLockerLearning periodElevation handled by us
1 entry / allowlist and ringfencing / elevation on our desk
Entries here1
Carried onThreatLocker
Rate basisEndpoint
DeskAnswered around the clock

Why approval beats recognition

Recognition is a footrace. Somebody must observe the thing, describe it, and deliver that description to your machines before it runs on one of them. Approval is no race at all: the list was settled beforehand, and whatever is missing from it gets refused regardless of whether anybody has ever laid eyes on it.

The cost is real and worth naming. A list has to be built, then kept. An observation stretch watches what the office genuinely runs before any refusal begins, and our desk carries the requests afterwards, so an approval never waits on somebody who is sitting with a client.

A list settled beforehand has no need to recognize anything in order to refuse it.

Ringfencing, the underrated half

Approval is one thing. The run of the machine is quite another. A ringfence governs the reach of an approved program: processes it may launch, directories it may open, addresses it may contact. No spreadsheet needs to start a scripting host, and a rule may say precisely that.

For a practice opening attachments all day, this is where the value actually sits. The document opens the way it always did. What it attempts next is where the line gets drawn.

Entries in this session

Entry specifications

Billing hands over every figure below at page load. Present while you read; a quantity stands until you alter it.

Fortify-ZeroTrustEntry

Execution Control

ThreatLocker refusing by default at the point of execution

Listed software opens client files. Everything else meets a refusal as it attempts to start, and nobody has to identify it first.

  • An observation stretch builds that list out of what the office genuinely runs.
  • Updates from a vendor get followed, so no release locks a preparer out mid filing season.
  • A ringfence governs the reach of a listed program: which files, which processes, which addresses.
Settles onThreatLocker agent, installed once per machine
NetsA single endpoint, list and ringfence on one unit
Value dateOpens when the observation stretch is closed off
Cleared byElevation requests are carried by Fortify 24x7 engineers
Reconciled byA dated trail of approvals, refusals, and edits to policy
Reading the rateper endpoint
settled monthly, in advance
QTY
Unmatched items

What this session does not settle

Execution approval is a strong control with visible edges. Here is where the entry stops.

  • It governs execution, never intent. An approved program used badly by an authorized person remains an approved program. Separation of duties and payment authorization are controls for your practice to design, not for this entry to supply.
  • Documents are not programs. A macro or a scripted attachment is bounded by the ringfence around whichever application opens it. Session 03 is where the message itself gets examined.
  • Servers want separate thought. The same agent runs there, but the list for a line of business host is not the workstation list and should never be copied across from one.
  • An observation stretch is not instantaneous. Enforcement starts once the list has settled. Hurrying it is how an office finishes up refusing its own tax software in February.
  • Your access policy is not ours to write. Who ought to hold which permission inside your practice systems is a decision for the practice. This entry rules only on what may run.
TICK 01

Heads up: card statements show FORTIFY 24X7 - FinShield Tech is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.