Sys Maintenance: Policies View

Document created by RSA Information Design and Development on Jul 28, 2016
Version 1Show Document
  • View in full screen mode
 

Policies view 

This figure depicts the Policies view.

AddPolicyCompleted.png

How to Access

The required permission to access this view is Manage services.

  1. In the Security Analytics menu, select Administration > Health & Wellness.
  2. Click the Policies tab.

Policies Panel

In the Policies panel, you can add or delete policies for hosts and services in this panel.

                                       
FeatureDescription
addlList.PNG Displays available service types to create a new policy . Select one so that you can define a policy or policies for it.
Icon_Delete_sm.png Deletes the selected policy from the Policies panel. You can only delete one policy at a time.
icon-edit.png Allows you to change the name of the policy.
CopyPolicyBtn.PNG Creates a copy of the selected policy. For example, if you select First Policy and click CopyPolicyBtn.PNG, Security Analytics creates a copy of this policy and names it First Policy (1).
ExpPolBtn.PNG Expands the list of policies under the services and hosts in the Policies panel.
CntrctPolBtn.PNG Contracts the list of policies under the services and hosts in the Policies panel.
 

List of:

  • services and hosts for which you have defined policies.
  • RSA standard policies that you can apply to hosts and services.

Policy Detail Panel

The Policy Detail panel displays the policy selected from the Policies panel.

                                                                                                                   
FeatureDescription
SaveSaves any changes you made in this panel.
Policy TypeDisplays the type of policy you selected.
Modified DateDisplays the last date this policy was modified.
Checkbox.png EnableSelect and deselect this checkbox to enable and disable the policy.
Services
addlList.PNG

Displays GrpsSvcsDrpDwnMnu.PNG menu.  Select:

  • Groups to display the Groups dialog from which you select service groups to this policy.
  • Service/Host to display the Services/Hosts dialog from which you select services to add to this policy. If policy type is Host, the menu will have Host not Service. You can select services based on policy type.
Icon_Delete_sm.png Deletes the selected service or group from this policy.
Rules
Icon-Add.png Displays the Add Rule dialog in which you define a rule for this policy.
Icon_Delete_sm.png Deletes the selected rule from this policy.
icon-edit.png Displays the Edit Rule dialog for the selected rule.
Policy Suppression
Icon-Add.png Adds a policy suppression timeframe row. 
Icon_Delete_sm.png Deletes the selected policy suppression timeframe row.
Time ZoneSelect the time zone for the Policy from the drop-down list.  This time zone applies to both Policy Suppression and Rule Suppression.
Checkbox.png Select the checkbox to select a policy suppression timeframe row.
DaysDays of the week that you want to suppress the policy according to the time range specified. Click on the day of the week that you want to suppress the policy.  You can select any combination of days including all days.
Time RangeTime range during which the policy is suppressed for the days selected.
Notifications
Icon-Add.png Adds a EMAIL notification row. 
Icon_Delete_sm.png Deletes the selected policy suppression timeframe row.
Notification SettingsOpens the Notification Servers view in which you can define the Email notification settings.
Checkbox.png Select the checkbox to select a policy suppression timeframe row.
TypeDisplay EMAIL.  EMAIL is the only type of notification available in this release.
NotificationSelect the type of EMAIL notification.  See Configure Notification Types in the System Configuration Guide for the source of the values in this drop-down list.
Notification ServerSelect the EMAIL notification server. See Configure Notification Servers in the System Configuration Guide for the source of the values in this drop-down list.
Template

Select the Template for this EMAIL notification. RSA provides the Health & Wellness Default SMTP Template and the alarms template. See Configure Notification Templatesin the System Configuration Guide for the source of the other values in this drop-down list.

Note: Please refer to Include the Default Email Subject Line if you want to include the default Email subject line from the Health & Wellness template in your Health & Wellness Email notifications for specified recipients.

Groups dialog

                                 
FeatureDescription
Groups panel
Name

Displays the service groups you have define. Select:

  • All to display all your services in the Services panel.
  • A group to display the services in comprise that group in the Services panel.
Services panel
NameDisplays the name of the service.
HostDisplays the host on which the service is running.
TypeDisplays the type of service.

Rules Dialog

                                                                
FeatureDescription
Checkbox.png EnableSelect and deselect this checkbox to enable and disable the rule for this policy.
NameEnter the name of the rule.
Description

Added this field in Security Analytics 10.5.0.1.

Enter the description of the rule. RSA suggests that you include the following information in this field.

  • Informational description - purpose of the rule and what problem it monitors.

  • Remediation - steps to take to resolve the condition that triggers the alarm for this rule.

Severity

Select the severity of the rule. Valid values are:

  • Critical
  • High
  • Medium
  • Low
Statistic

Select the statistics you want to check with this rule. Select a:

  • statistical category from the left drop-down list.
  • statistic from the right drop-down list.

Note: For Public Key Infrastructure (PKI) policy, select PKI in the category and statistics as any one of the following:
- SA Server PKI Certificate Expiration - Displays the time left before the certificate expires.
- SA Server PKI CRL Expiration - Displays the time left before the Certificate Revocation List (CRL) expires.
- SA Server PKI CRL Status - Displays the current status of the CRL.

SA Server PKI Certificate Expiration - Displays the time left before the certificate expires.

SA Server PKI CRL Expiration - Displays the time left before the Certificate Revocation List (CRL) expires.

SA Server PKI CRL Status - Displays the current status of the CRL.

Please refer to the System Stats Browser View for examples of the statistics you may want to check with a rule. 

Alarm Threshold

Define the threshold of the rule that will trigger the policy alarm:

  • operator:

    • For Security Analytics 10.5 (=, !=, <, <=>, or  >=
    • For Security Analytics 10.5.0.1 and later (See Threshold Operators below)
  • amount

Note: For CRL expiry the supported format is ddddhhmm, for example:
- 10000 represent 1 day
- 2359 represent 23 hours and 59 minutes
- 10023 represent 1 day and 23 minutes
- 3650100 represent 365 days and 1 hour

  • time in minutes
Recovery

Define the when to clear the threshold of the rule:

  • operator:

    • For Security Analytics 10.5 (=, !=, <, <=>, or  >=
    • For Security Analytics 10.5.0.1 and later (See Threshold Operators below)
  • amount
  • time in minutes
Rule Suppression
Icon-Add.png Adds a rule suppression timeframe row. 
Icon_Delete_sm.png Deletes the selected rule suppression timeframe row.
Checkbox.png Select the checkbox to select a rule suppression timeframe row.
Time Zone: time-zoneDisplays the Policy time zone.  You select the time zone for a policy in the Policy Suppression panel.
DaysDays of the week that you want to suppress the rule according to the time range specified. Click on the day of the week that you want to suppress the rule.  You can select any combination of days including all days.
Time RangeTime range during which the rule is suppressed for the days selected.

In Security Analytics 10.5.0.1, RSA added threshold operator support as described in the following Threshold Operators section.

Threshold Operators

The Alarm Threshold and Recovery Threshold fields in the Rules dialog prompt you for either numeric or string operators based on the statistic criteria you specify.

       
Numeric operators drown-down menu: Operators.PNGString operators drop-down menu: RegExOperators.PNG
You are here: References > Health and Wellness > Sys Maintenance: Policies View

Attachments

    Outcomes