nav-img
Advanced

Applying a Policy

You can quickly configure and start server scans by using policy groups. Simply create a group, add policies to it, and apply this group to servers. The agents deployed on your servers will scan everything specified in the policies.

Precautions

  • When you enable the enterprise edition, the default policy group of this edition (including weak password and website shell detection policies) takes effect for all your servers.
  • When you enable the premium or WTP edition, the edition is bound to default_premium_policy_group.

    To create your own policy group, you can copy the default policy group and add or remove policies in the copy.

Accessing the Policies Page

  1. Log in to the management console.
  1. In the upper left corner of the page, select a region, click , and choose Security > Host Security Service.
  2. In the navigation pane, choose Security Operations > Policies.

Creating a Policy Group

  1. In the row where default_premium_policy_group (default policy group of the premium edition) resides, click Copy in the Operation column, as shown in Figure 1.

    Figure 1 Copying a policy group


  2. In the dialog box displayed, enter a policy group name and description, and click OK, as shown in Figure 2.

    Note
    • The name of a policy group must be unique, or the group will fail to be created.
    • The policy group name and its description can contain only letters, digits, underscores (_), hyphens (-), and spaces, and cannot start or end with a space.

    Figure 2 Creating a policy group


  3. Click OK.
  4. Click the name of the policy group you just created. The policies in the group will be displayed, as shown in Figure 3.

    Figure 3 Policies in a group


  5. Click a policy name and modify its settings as required. For details, see Modifying a Policy.
  6. Enable or disable the policy by clicking the corresponding button in the Operation column.

Applying a Policy Group

  1. In the navigation pane, choose Servers. Click the Server tab.
  1. Select one or more servers and click Apply Policy, as shown in Figure 4.

    Figure 4 Applying policies


  2. In the dialog box that is displayed, select a policy group and click OK.

    Figure 5 Selecting a policy group


    Note
    • Old policies applied to a server will become invalid if you apply new policies to the server.
    • Policies are applied to the servers within 1 minute.
    • Policies applied to offline servers will not take effect until the servers are online.
    • In a deployed policy group, you can enable, disable, or modify policies.
    • A policy group that has been deployed cannot be deleted.