CUI Compliant
0 NIST 800-171 gaps detected. FedRAMP Moderate authorized as part of Prisma Access.
Palo Alto GlobalProtect
by Palo Alto Networks
FedRAMP Status
FedRAMP Authorized
Impact Level
Moderate
Category
VPN & Network Security
Authorized: January 21, 2021
Overview
Palo Alto GlobalProtect provides secure remote access and zero-trust network access as part of the Prisma SASE platform. FedRAMP Moderate authorized. Common in mid-to-large defense contractors for VPN and ZTNA.
CUI Risk Assessment
FedRAMP Moderate authorized as part of Prisma Access.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
Palo Alto GlobalProtect operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO must update System Security Plan Section 9 to document GlobalProtect's role in implementing NIST 800-171 access control requirements (AC-2, AC-3, AC-17).
- 2Network administrator shall configure GlobalProtect portal and gateway within FedRAMP authorized Prisma Access environment to ensure CUI data never traverses unauthorized networks.
- 3ISSO must establish multi-factor authentication integration with existing identity provider to satisfy NIST 800-171 control IA-2(1).
- 4System administrator shall configure endpoint compliance policies requiring disk encryption, updated antivirus, and approved OS versions before VPN access granted.
- 5ISSO must implement split-tunneling policies ensuring CUI-related traffic routes exclusively through authorized network paths per DFARS 252.204-7012.
- 6Security administrator shall enable comprehensive session logging capturing user identity, accessed resources, and session duration to support NIST 800-171 audit requirements (AU-2, AU-3).
- 7ISSO must update authorization boundary diagram to reflect GlobalProtect as external connection point and document security controls at this interface.
- 8Network administrator shall configure traffic inspection policies to detect potential CUI exfiltration while maintaining user privacy compliance.
- 9ISSO must create POA&M entries addressing any temporary deviations from baseline security configurations during deployment.
- 10Contracts officer must verify GlobalProtect licensing agreements include appropriate data location restrictions and government access provisions per DFARS 252.204-7021.
Other FedRAMP Authorized VPN & Network Security Tools
Related Compliance Assessments
Frequently Asked Questions
Is GlobalProtect FedRAMP authorized?
Yes, as part of Palo Alto Prisma Access which holds FedRAMP Moderate authorization. GlobalProtect provides the client-side component for secure remote access.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Palo Alto GlobalProtect CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures