This document describes how to use the baseline management feature to help you manage baseline security in your server.
Background Information
The Cloud Workload Protection Platform (CWPP) supports periodic and one-click detection of baseline detection items, detection of specified baseline items on designated hosts, understanding baseline pass rates and risk situations through detection policies. It provides risk levels and repair suggestions for baselines and detection items, and provides default baseline policies, helping you better manage baseline security in your server.
Operation Guide
- Log in to the tenant-side console of CWPP. In the left sidebar, select Baseline Management > Security Baseline to go to the Security Baseline page.
- The Security Baseline page enables one to set baseline policies, detect periodically, and detect specified policies with one click. It supports viewing the pass rate and risk status of the baseline policy, as well as the list of baseline detection results. It also supports viewing the baseline and detection item details and repair plans and can ignore the detection items of specified servers.
Baseline Policy
The baseline policy is a collection of baseline detection items based on user-defined settings. It understands the pass rate and risk situation of the baseline based on the policy dimension.
- Cloud platform default baseline policy: Cloud platform host security provides you with a default baseline detection policy based on the mainstream baseline detection content of network security, including: International Standard Baseline, weak password, unauthorized access, level-2 cybersecurity classified protection, level-3 cybersecurity classified protection, and cloud security standard policy. You can add detection items to the default baseline policy and servers to be detected. This policy, by default, detects all Ultimate Edition or flagship edition servers at 00:00 on the 7th day every 7 days.
- Adding Baseline Policy
- In the upper-right corner of the Security Baseline page, click Baseline Detection Setting.
- In Detection Policy Settings, click Add Policy.
- In the pop-up window for adding a policy, enter a policy name (cannot be the same as an existing policy name), select a detection period, baseline options, and application assets, click Save and update.
Note:
CWP supports creating a maximum of 20 baseline policies. After the number of baseline policies reaches 20, you are not allowed to create more. However, you can delete the existing baseline and create another one.
Baseline Detection
CWPP supports periodic detection and one-click detection of baseline detection items, and supports the detection of specified baseline items on specified CVMs.
- One-Click Detection
1.Click One-click Detection, select the baseline policy to detect and issue detection (the detection usually lasts 2 - 5 minutes). After the detection is completed, the detection results will be displayed at the bottom of the Security Baseline page. - Periodic Detection
- In the upper-right corner of the Security Baseline page, click Baseline Detection Setting.
- In Detection Policy Settings, you can set periodic detection.
List of Baseline Detection Results
Below the Security Baseline page, you can view the list of baseline detection results, view baseline detection details, fuzzily search and filter the status of a single baseline, and download all tables.
- Detection rule name: Baseline detection rule name, containing several detection items of the same category. - Specific detection item: Total number of detection items under this detection rule. - Number of detected servers: The number of servers detected by this detection rule. - Last detection time: The time when this detection rule was last detected. - Processing status: failed, approved. - Perform operations - Recheck: You can re-detect this detection rule. - View detail: server inspection results and associated detection items are viewable.