Cisco ASA show running-config (paste show access-list below it for hit counts), a Palo Alto XML configuration, a FortiGate backup, an FMC export, or a rules CSV.
The last approved config, in the same format. Adds drift: rules and objects added, removed, changed or moved.
Findings use the same engine and wording as the fwaudit command-line tool, which also
collects live from FMC and cdFMC, applies accepted-risk exceptions, and writes the printable auditor report.
Control references point reviewers to related requirements; they are not a statement of compliance.