Configure and run check policies

更新时间:
复制 MD 格式

Cloud Security Posture Management (CSPM) in Security Center scans your cloud service configurations to detect misconfigurations before they lead to security vulnerabilities or data breaches.

Configure check items

Security Center includes predefined check items for common configuration risks. Before running a scan, customize these items to align with your security baselines and reduce noise in the results.

Custom check items

Define detection logic based on your internal security standards or risk-specific scenarios.

Supported service providers: Alibaba Cloud, Tencent Cloud, and AWS

Detection scenarios: Compliance Risk, AISPM, and Security Risk. For details, see check rules.

How it works

The following diagram shows the workflow for configuring and using custom check items.

image

Create and publish a custom check item

  1. Go to the creation page. Log in to Security Center console - Risk Governance - CSPM. In the top-left corner, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland. On the Cloud Service Configuration Risk tab, click Create Custom Check Item.

  2. Configure basic information. On the Basic Information Settings tab, configure the following parameters and click Next.

    Parameter

    Description

    Check Item Category Settings

    Assign one or more categories for easier filtering in reports. Click Add to assign multiple categories.

    Use case

    The detection scenario category. Select Compliance Risk, AISPM, or Security Risk.

    AISPM

    Select a predefined option or enter a custom value.

    Check Item Description

    Describe the check item: the service provider, target cloud service, and a brief rule explanation.

    Solution

    Manual remediation steps for users when the check detects a risk.

    Help

    URL of a related help document. Enter None if unavailable.

    Risk Level

    Set the risk level: High, Medium, or Low. For how risk levels are determined, see Assess risk levels.

  3. Define check item rules. On the Check Item Rule Settings tab, configure the following and click Next.

    • Check Item Target: Select the type of cloud service to check under the specified service provider, such as ECS-Instance or OSS-Bucket.

    • Associated Asset Settings (Optional): If the check logic involves related assets, click Add Associated Asset to link an asset type (such as a VPC) to the Check Item Target.

      Note

      If the Service Provider list is empty, the selected Check Item Target does not support asset association. Available options depend on what the console displays.

      Configure the following fields when adding an associated asset:

      Field

      Description

      Associable Attribute

      Property of the Check Item Target used to link to another asset.

      Associated Asset

      Asset type to link.

      Associated Asset Property

      Property of the associated asset that maps to the Associable Attribute.

    • Check Item Settings: Define the detection logic using conditions.

      Conditions follow AND/OR logic:

      Scope

      Rule

      Within a group

      Connect conditions with AND or OR. Each group supports up to 10 conditions.

      Between groups

      Connect groups with AND or OR. Each check item supports up to 5 groups.

      Example: With three groups and the relationship "group1 AND group2 OR group3" — group1 uses AND internally, group2 uses OR, and group3 uses AND:

      Supported operators:

      Operator

      Description

      In / NotIn

      Checks whether a value exists in a specified set.

      Equals / NotEquals

      Checks whether two values are equal.

      Note: Click the image icon next to a parameter to view its data type, examples, and description.

      In the condition configuration area, click Add Condition, then use the multi-level selection panel to navigate the parameter path: first select the resource type (such as ACS_ECS_Instance), then select an attribute (such as PublicIpAddress), expand it, and select the target field under a sub-attribute (such as IpAddress). Set the logical operator to AND and the comparison method to Contains.

      1. Click Add Condition to expand the configuration area.

      2. Click Add Condition or Add Group to build the rule.

  4. Test the rule.

    1. Click Test on the Check Item Rule Settings tab.

    2. In the Test area, select a matching instance from your account (such as an OSS bucket, ECS instance, or Log Service project), then click Test.

    3. If the message "This check item has passed." appears, the configuration parses data correctly. If the result is unexpected, review your conditions and test again.

    4. After the result is as expected, click Save.

    Note

    You can edit, publish, or delete a check item that is saved but not yet published.

  5. Publish the check item. Click Publish on the Check Item Rule Settings tab. Alternatively, go to the custom check item list and click Publish in the Actions column.

    Important

    Only published check items appear in the check item list and are available for scans. Published check items cannot be modified. To edit a published item, deactivate it first.

Manage custom check items

In the Custom Check Item Management section in the upper-right corner of the CSPM Risk page, view, edit, publish, unpublish, or delete custom check items.

Action

Behavior

Edit

Click the check item name to open its edit page. To modify a published check item, first click Deactivate to make it editable. Deactivating preserves all historical scan results. For how to unpublish a check item, see the Unpublish action below.

Unpublish

Removes the check item from active scanning and permanently deletes its associated rules and all historical scan results. To use the item again, you must reconfigure and republish it.

Delete

Permanently removes the check item along with its historical check data and alert information.

Predefined check items

For predefined check items that support customization — such as checks for OSS bucket hotlink protection, idle users, or password expiration — modify their parameters to match your security baselines.

Requirement: A paid edition of CSPM. See Activate a paid edition of CSPM.

  1. Go to Security Center console - Risk Governance - CSPM. In the top-left corner, select the region where your assets are located.

  2. On the Cloud Service Configuration Risk tab, find a check item where the Support Custom Parameters column shows Yes, then click its name.

  3. In the details panel, click Parameter Configuration.

    Note

    If this button does not appear, the check item does not support parameter modification.

  4. In the Parameter Configuration panel, click Add Modifiable Parameter in the Modifiable Parameter column and select the parameter to modify from the drop-down list.

  5. Enter the new value in the Edit Parameter column and click OK.

Note

The modified parameter takes effect during the next scan.

Configure check policies

After configuring check items, set up the scan scope, automatic detection policies, and whitelist rules to control which instances to scan, the scan schedule, and exceptions.

Scan scope

  1. On the Cloud Service Configuration Risk tab, click Policy Management in the upper-right corner, then go to the Cloud Service Scan Policy tab.

  2. Select the existing cloud service instances to scan based on your filter criteria. For new assets added later, the Automatically Scan New Assets option is selected by default. Refine which new assets to auto-scan by product type or asset group. Click Save.

  3. To scan all instances, go to the All Instances tab and click Save.

    Note

    When you select all instances, new instances are automatically included in the scan scope.

After you save the configuration, Security Center scans the selected cloud service instances based on the defined policy. To verify, go to the Cloud Service Configuration Risk tab and check that the scan results reflect your configured scope.

Automatic detection policy

  1. On the Risk Governance > Cloud Service Configuration Risk page, click Policy Management in the upper-right corner, then go to the Cloud Service Scan Policy tab.

  2. Turn on the Automatic CSPM Check switch and configure the following settings:

    Setting

    Description

    Check Cycle

    How frequently the scan runs.

    Check At

    The time to start the scan.

    Check Item Selection

    The predefined or published custom check items to include.

  3. After selecting check items, the Estimated Quota Consumption for a single scan appears above the list.

    Note

    This estimate is for reference only. The actual number of scanned instances may vary.

After you save the configuration, Security Center runs configuration risk scans on your defined schedule. To verify, check the scan history on the Cloud Service Configuration Risk tab after the next scheduled scan time.

Whitelist rules

Exclude specific check items for designated cloud service instances to prevent unnecessary risk alerts. Whitelist rules apply to both scheduled and on-demand scans.

Create a whitelist rule

  1. On the Risk Governance > Cloud Service Configuration Risk page, click Policy Management in the upper-right corner.

  2. On the Whitelist Policy > By Check Item tab, click Create Whitelist Rule.

  3. In the panel, configure the following and click OK:

    Important

    Exempting all instances is a high-risk operation — new security risks on future instances can go undetected. Use Specific Instances for precise whitelisting, and audit your whitelist rules periodically to confirm they are still necessary.

    Parameter

    Description

    Check Item

    The check items to exclude from scans. See check rules.

    Policy Effective Scope

    The scope of the exemption.

    Option

    Behavior

    All Instances

    Exempts all existing and future instances of this cloud service from the check. Related risks are not displayed in the risk list.

    Specific Instances

    Applies the exemption only to the selected instances. New instances are still scanned.

Manage whitelist rules

  • Edit or delete rules: Whitelist rules you create appear in the Cloud Service Check Item Whitelist list. Click Edit to modify the scope, or Delete to remove the exemption.

  • Automatic synchronization: When you manually mark a failed check item as handled or whitelisted while handling risks, the system automatically adds the corresponding rule to this list. For details, see Handle cloud services that fail check items.

Run configuration risk scans

Security Center supports two scan modes:

Mode

Description

Scheduled automatic scans

Runs on the schedule defined in your automatic detection policy.

On-demand scans

Triggered manually at any time.

Run an on-demand scan:

  1. On the Cloud Service Configuration Risk tab, click Full Scan in the Actions area.

  2. Select a scan mode:

    Mode

    What it scans

    Full Scan

    All supported cloud services and check items, including predefined and custom.

    Scan By Policy

    Only the check items selected in Policy Management.

After the scan completes, view all failed check items in the Cloud Service Configuration Risk list and follow each item's Solution to remediate them.

Remediate failed check items

After a scan, go to Risk Governance > CSPM Risk > Cloud Service Configuration Risk to view all failed check items and follow the provided Solution to remediate each risk.

For step-by-step guidance, see View and handle failed check items.

FAQ

What should I do if I find a logic error in a published custom check item?

In the upper-right corner of the CSPM Risk page, click Custom Check Item Management, find the item, and select Deactivate. Then click the item name to open its edit page.

Note

Deactivating a check item makes it editable again without deleting historical scan results. To permanently remove a check item, use Unpublish (deletes all rules and scan results) or Delete (removes the item entirely along with all historical data and alerts).

After modifying and testing the rule, click Publish to make it active again.

How can I find the custom check items I created?

On the Cloud Service Configuration Risk tab of the Risk Governance > CSPM Risk page, your custom check items are grouped under the categories you assigned during creation.