
●
Set severity, remediation, and unsupported behavior to policy items in Quick Settings
Policy editor icons
The following lists the icons used in the policy editor category panel.
The following table lists the icons used in the policy editor.
Policy editor icons Description
(Green padlock)
The selected setting adds more security and is the recommended security option.
(Yellow padlock)
The selected setting provides some security, other choices might provide a more secure policy.
(Red padlock)
The selected setting is less secure.
(Information bubble )
Provides information about a setting. Click the bubble to display the information of a setting.
(Red text box)
Indicates an error. A list of errors displays on an error panel.
(Yellow text box)
Indicates a warning. The information provided for the settings might cause issues on some
devices or in certain situations.
Grayed eld Information is required for this setting.
Set severity, remediation, and unsupported behavior to policy items in Quick Settings
The Quick Settings function allows a user to set the severity, remediation, and unsupported setting on policy
items in the Security Manager Settings located in the main category or sub category policy settings or in the
Quick Settings (Policy) window.
A policy can be set to include or exclude items. The following settings can be set at the top level:
●
Include All Items: This setting at the top level creates a valid policy that includes all the recommended
settings.
●
Exclude All Items: This setting at the top level deselects all the items in the policy.
NOTE: Items can also be included or excluded at the sub category level.
Remediation options are available for each item in the policy and can include the severity level reported during
an assessment, whether to remediate a failure, and how to report an unsupported feature. You can use the
policy's default remediation settings, individually set the options for each item in the policy, or set remediation
options to apply to a specic policy category.
●
Set Severity: Indicates the security risk of the assessed feature when it is not in compliance with the policy.
●
Set Remediation: Indicates whether the item is remediated during an assessment and remediation task.
NOTE: When global remediation is set to Disable device remediation (Report Only), this setting applies to
all policies and takes precedence over a policy's advanced remediation settings. For more information
about the global remediation setting, see Verify device remediation and hostname resolution.
22 Chapter 4 Use Security Manager ENWW
Comentários a estes Manuais