Authorize and enable CSPM
Authorize Security Center to access your cloud resources and enable Cloud Security Posture Management (CSPM) for configuration risk checks, baseline checks, and attack path analysis.
Authorize access to cloud resources
Before using configuration risk checks, authorize Security Center to access your cloud resources.
-
Log on to the Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.
-
Click Authorize Now.
If you have already enabled the baseline risk check feature, go to the Cloud Service Configuration Risk tab and click Authorize Now.
NoteAfter authorization, Security Center automatically creates the service-linked role AliyunServiceRoleForSasCspm. This role allows Security Center to access and modify cloud product configurations and provides security best practices for identity authentication, network access control, data security, log auditing, and basic security protection. For more information, see Service-linked roles for Security Center.
-
After authorization, free configuration risk check items become available. If you have not enabled pay-as-you-go or purchased CSPM scans, only free check items are available. On the Cloud Service Configuration Risk tab, items with a Scan button in the Actions column are free.
Authorize the virus scan service
When you use the virus scan feature for the first time, the system displays an authorization page to guide you through the authorization process. If you do not complete the authorization, the virus scan page may not display properly. For example, the Rescan button may be missing.
Authorization trigger conditions:
-
When you access the virus scan page for the first time and have not completed the service authorization, the page automatically redirects to the authorization page.
-
If the authorization status becomes invalid due to network latency or permission changes, the authorization page may also be triggered when you access the virus scan page again.
Authorization procedure:
-
Log on to the Security Center console.
-
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.
-
After you access the virus scan page, if service authorization is required, the page displays the authorization information. Click the blue Authorize Immediately button to complete the authorization.
After the authorization is complete, you can use all virus scan features, including the rescan feature.
If the virus scan page does not work as expected, for example, the Rescan button is missing, check whether you have completed the service authorization. You can try to re-access the page to trigger the authorization process and complete the authorization.
Enable the baseline risk check feature
Baseline risk checks support the following billing methods.
If you purchased Security Center Advanced, Enterprise, or Ultimate Edition, you can only use the baseline check items supported by your edition, even if you also purchased paid CSPM features.
For example, if you purchased Security Center Advanced Edition and paid CSPM features, you can only use the weak password check item.
|
Billing method |
Purchase option |
Edition |
Procedure |
|
The following editions include baseline risk check features at no additional cost.
|
Subscription |
Advanced Edition, Enterprise Edition, or Ultimate Edition |
|
|
Pay-as-you-go |
Enable Container Guard and authorize the Advanced Edition, Enterprise Edition, or Ultimate Edition |
|
|
|
After you purchase paid CSPM features, you can use the baseline risk check feature and all check items. Billing is based on the number of billable cloud product instances for scans, verifications, and remediations respectively. |
Subscription |
Anti-virus Edition or purchasing value-added services only |
See Subscription in Enable paid CSPM features below. |
|
Pay-as-you-go |
Enable Container Guard and authorize the Anti-virus Edition |
See Pay-as-you-go in Enable paid CSPM features below. |
|
|
Do not enable Container Guard |
Enable paid CSPM features
Enable paid CSPM features to access all check items for configuration risk checks and baseline risk checks, plus attack path analysis.
Each Alibaba Cloud account can use only one billing method for CSPM.
Subscription
-
Go to the Security Center purchase page. For Billing Method, select Subscription. For CSPM, select Yes. Set the Quantity and Subscription Duration (in months or years). The elastic protection switch is enabled by default. Purchase other features as needed. For more information, see Purchase Security Center.
Note-
If you already have a subscription instance, go to the Overview page of the Security Center console. In the Subscription section, click to purchase the CSPM feature.
-
After the elastic protection switch is enabled, you are charged based on a hybrid billing method (standard billing + pay-as-you-go billing). For more information, see Billing description. To disable elastic protection, go to and turn off the Burstable Protection switch. The elastic protection switch is automatically turned off if the subscription plan expires without renewal.
-
-
After you enable the feature, go to the section, or the section, to view the Remaining Quota for Cloud Security Posture Management.
Pay-as-you-go
-
Go to the Security Center purchase page. For Billing Method, select Pay-as-you-go. For CSPM, select Yes. Enable other features as needed. For more information, see Purchase Security Center.
NoteIf you already have a pay-as-you-go instance, turn on the CSPM switch in the Enable Pay-as-You-Go Service section on the Overview page of the Security Center console.
-
After you enable the feature, go to the section, or the section, to view the Used Quota for Cloud Security Posture Management.
Unsubscribe from CSPM
If you no longer need CSPM, you can disable it.
-
Subscription:
-
Procedure: Go to the order upgrade or downgrade page. On the Order Downgrade tab, in the CSPM section, set the Purchase or Not to No. For more information, see Downgrade or upgrade configurations.
NoteThe refund amount is shown on the downgrade page. Refund credit routing is covered in Refund rules.
-
Data processing:
-
Cloud product configuration check:
-
Only results for free check items are retained. Results for paid check items are deleted immediately.
-
Periodic scan policies, whitelist policies, and custom check items are not deleted.
-
-
System baseline:
-
Baseline check results cannot be viewed in the console. Backend data is retained for 30 days and then automatically deleted.
NoteIf your Subscription instance (Advanced, Enterprise, or Ultimate) has not expired and you have not unsubscribed from it, the check results for that edition continue to be retained. After the instance expires or you unsubscribe from it, backend data is retained for 30 days and then automatically deleted.
-
Scan policies are deleted immediately. Whitelist policies are not deleted.
-
-
-
-
Pay-as-you-go:
-
Procedure: On the Overview page of the Security Center console, in the Enable Pay-as-You-Go Service section, turn off the CSPM switch.
-
Data processing:
-
Cloud product configuration check:
-
Check results are not deleted after you disable the feature.
-
Periodic scan policies, whitelist policies, and custom check items are not deleted.
-
-
System baseline:
-
Baseline check results cannot be viewed in the console. Backend data is retained for 30 days and then automatically deleted.
NoteIf your Subscription instance (Advanced, Enterprise, or Ultimate) has not expired and you have not unsubscribed from it, the check results for that edition continue to be retained. After the instance expires or you unsubscribe from it, backend data is retained for 30 days and then automatically deleted.
-
Scan policies are deleted immediately. Whitelist policies are not deleted.
-
-
-
What's next
-
Set up Baseline risk checks.
-
To use the attack path analysis feature, see Attack path analysis.