####Task Summary
- View/Export compliance reports
- Create a Custom Policy Group
- Add Custom Policy Group to Project
- Scan custom policy
Documentation Notes:
- Tenable.cs is used interchangeably with Tenable Cloud Security
- Tenable.io is used interchangeably with Tenable Vulnerability Management
- Tenable Vulnerability Management account
- Skills
- Prior knowledge of networking, and Microsoft Windows and browser
- Completed Labs 1 and 2
- On the Tenable Cloud Security Dashboard, create a new project - custom_policy_project
Select
the provider AWSClick
on the project custom_policy_projectClick
on the Repositories pencil iconSelect
the repository create from the prior labs (eg. tenable-awsjam-demo.git)Save
the configuration
- On Tenable Cloud Security Dashboard left menu,
click
the icon for Reports - Under the Projects filter,
select
the project custom_policy_project Select
FiltersEnable
filter on- Policy Status: Non-Compliant
- Severity: High
Expand
the control Security GroupClick
APPLYExpand
Infrastructure Security
- What is the compliance coverage for Infrastructure Security?
- How many High severity, non-compliant policies were found?
- What is the compliance coverage for the Project we selected?
- On the Tenable Cloud Security dashboard, Create a new Custom Policy
Click
on the left menu (+) and select Custom PolicySelect
Add Policy Group- Filter on the following:
- Severity: High
- Provider: AWS
- Category: Infrastructure Security
Enable
ALL policiesSelect
ContinueType
in the Policy Group Name: custom_Infrastructure_Security_policy_groupSelect
AWSSelect
EnforceSelect
the DONE button to complete group creation.
- On Tenable Cloud Security dashboard,
click
on the project Click
on pencil icon for Active policy groupsDeactive/disable
the current policy group selectionsSearch
for custom_InfrastructureEnable
custom_Infrastructure_Security_policy_groupClick
SAVEVerify
Active policy groups updated with new custom policyClick
on Run scan->IaC scan for the custom_policy_project
- Can custom policy group be created to build a customized policy that contains policies from each Industry Benchmark?
- Create a pull request
- Merge repository
- Validate compliance changes