Short answer
Yes. FirstNet sets up reports and dashboards that support audits and checks by regulators. Compliance reporting is part of the managed service FirstNet wraps around its Sophos deployments.
In detail
Reports you can get across FirstNet's security services:
- Sophos NG-SIEM: telemetry intake, compliance reports and log retention. The Enhanced and Premium support tiers add more reports and executive reports.
- FortiAnalyzer as a Service: built-in compliance reports for Fortinet estates. You can check them against FortiManager policy changes.
- FortiManager: monthly reports on policy changes, firmware drift and licence use.
- Mimecast: monthly reports on incident trends, policy changes and DMARC progress, depending on scope.
- SendMarc: your published DMARC policy, enforcement status and a monthly report as evidence.
- Netskope Advanced Analytics: dashboards, KPI reports and visuals ready for the board.
These reports give auditors and boards evidence that controls are in place and working. They support your compliance goals but do not guarantee them. Compliance is shared, and it depends on your own settings and governance.
FirstNet's product and legal teams review formal security questionnaires and audit evidence packs. They review contract wording too. None of these are signed informally.
Source: FirstNet Managed Cybersecurity Services service page →
Didn’t answer your question?
