Manage continuous monitoring for controls between Configuration Compliance and Policy and Compliance Management
Continuous monitoring for controls is a feature integration between the GRC: Policy and Compliance Management product and the Security Operations Configuration Compliance products. This feature integrates the scan results from third-party applications, like Qualys to determine the compliance status for each associated control.
Continuous monitoring is a pro-active security management approach. Customers monitor and validate compliance and manage risks against authority documents.
Continuous monitoring workflow
- The system admin activates the Configuration Compliance and Policy and Compliance Management plugins.
- The compliance manager maps control objectives or controls to configuration tests, which generate controls, entities, and indicators related to those configuration tests.
- The integration ingests the results of the third-party configuration test scan results at defined intervals.
- If the configuration test scan results of the configuration tests indicate a failure, then the control is non-compliant and an issue is automatically generated.
- If the next scan result of the configuration test indicates that the failure has been remediated, then the control is compliant and the issue is automatically closed.
Map control objective or controls to configuration tests
The compliance manager maps control objectives or controls to the configuration tests, which generate the controls, entities, and indicators associated with configuration compliance.
Before you begin
Role required: compliance manager
The Configuration Compliance plugin must be activated to access this feature and the sn_compliance.auto_create_profile_and_control property must be set to true.
Procedure
Interpret configuration compliance scan results
If the configuration test scan results of the control indicate any failures, the control is marked non-compliant. If the scan results indicate the control passed, all the configuration tests, then the control is marked compliant.
Before you begin
Role required: compliance manager
The Configuration Compliance plugin must be activated to access this feature and the sn_compliance.auto_create_profile_and_control property must be set to true