- What's New
- Function Overview
- Service Overview
- Billing
- Getting Started
-
User Guide
- Buying SecMaster
- Authorizing SecMaster
- Viewing Security Overview
- Workspaces
- Viewing Purchased Resources
- Security Situation
- Resource Manager
- Risk Prevention
- Threat Operations
- Security Orchestration
-
Playbook Overview
- Ransomware Incident Response Solution
- Attack Link Analysis Alert Notification
- HSS Isolation and Killing of Malware
- Automatic Renaming of Alert Names
- Auto High-Risk Vulnerability Notification
- Automatic Notification of High-Risk Alerts
- Auto Blocking for High-risk Alerts
- Real-time Notification of Critical Organization and Management Operations
-
Settings
- Data Integration
-
Log Data Collection
- Data Collection Overview
- Adding a Node
- Configuring a Component
- Adding a Connection
- Creating and Editing a Parser
- Adding and Editing a Collection Channel
- Managing Connections
- Managing Parsers
- Managing Collection Channels
- Viewing Collection Nodes
- Managing Nodes and Components
- Partitioning a Disk
- Logstash Configuration Description
- Connector Rules
- Parser Rules
- Upgrading the Component Controller
- Customizing Directories
- Permissions Management
- Key Operations Recorded by CTS
-
Best Practices
-
Log Access and Transfer Operation Guide
- Solution Overview
- Resource Planning
- Process Flow
-
Procedure
- (Optional) Step 1: Buy an ECS
- (Optional) Step 2: Buy a Data Disk
- (Optional) Step 3: Attach a Data Disk
- Step 4: Create a Non-administrator IAM User
- Step 5: Configure Network Connection
- Step 6: Install the Component Controller (isap-agent)
- Step 7: Install the Log Collection Component (Logstash)
- (Optional) Step 8: Creating a Log Storage Pipeline
- Step 9: Configure a Connector
- (Optional) Step 10: Configure a Log Parser
- Step 11: Configure a Log Collection Channel
- Step 12: Verify Log Access and Transfer
- Credential Leakage Response Solution
-
Log Access and Transfer Operation Guide
-
API Reference
- Before You Start
- API Overview
- Calling APIs
-
API
- Alert Management
- Incident Management
- Indicator Management
- Playbook Management
- Alert Rule Management
- Playbook Version Management
- Playbook Rule Management
- Playbook Instance Management
- Playbook Approval Management
- Playbook Action Management
- Incident Relationship Management
- Data Class Management
- Workflow Management
- Data Space Management
- Pipelines
- Workspace Management
- Metering and Billing
- Metric Query
- Baseline Inspection
- Appendix
- FAQs
Performing a Scheduled Baseline Check
Scenarios
SecMaster can check whether your assets have risks based on baseline check plans. By default, every three days SecMaster automatically performs a baseline check on all assets in the current region under your account from 00:00 to 06:00 in accordance with compliance pack Cloud Security Compliance Check 1.0. This function is enabled by default. So there are no manual actions required.
You can customize the automatic inspection period, time, and scope to create custom check plans.
This document describes how to create a custom baseline check plan.
Limitations and Constraints
- A compliance pack can be added to only one check plan.
- SecMaster cannot execute check plans that include manual check items. So do not add compliance packs that include manual check items to a check plan. There are manual check items in DJCP 2.0 Level 3 Requirements.
- The default check plan can be enabled or disabled only. No changes on its compliance packs or execution time can be made.
Procedure
- Log in to the management console.
- Click
in the upper left corner of the management console and select a region or project.
- Click
in the upper left corner of the page and choose Security & Compliance > SecMaster.
- In the navigation pane on the left, choose Workspaces > Management. In the workspace list, click the name of the target workspace.
Figure 1 Workspace management page
- In the navigation pane on the left, choose Risk Prevention > Baseline Inspection. On the displayed page, click the Security Standards tab. Then, click the Check Plan tab.
- On the Check Plan tab, click Create Plan. The pane for creating a plan is displayed on the right.
- Configure the check plan.
Table 1 Parameters for creating a check plan Parameter
Description
Basic Information
Name
Custom plan name.
Schedule
Select how often and when the check plan is executed.
- Schedule: every day, every 3 days, every 7 days, every 15 days, or every 30 days
- Check start time: 00:00-06:00, 06:00-12:00, 12:00-18:00, or 18:00-24:00
Select Compliance Pack
Select the compliance pack you want to use.
- Click OK.
After the check plan is created, SecMaster performs cloud service baseline scanning at the specified time. You can choose Risk Prevention > Baseline Inspection to view the scan result.
Related Operations
You can view, edit, enable, disable, or delete a custom check plan.
- Viewing a check plan
- In the navigation pane on the left, choose Risk Prevention > Baseline Inspection. On the Baseline Inspection page, click the Security Standards tab. Then, click the Check Plan tab.
- On the Check Plan page, view what check plans you already have.
- Editing a custom check plan
Only custom check plans can be edited.
- In the navigation pane on the left, choose Risk Prevention > Baseline Inspection. On the Baseline Inspection page, click the Security Standards tab. Then, click the Check Plan tab.
- In the upper right corner of the check plan box, click Edit. The pane for editing the check plan is displayed on the right.
- Edit settings and click OK.
- Deleting a custom check plan
Only custom check plans can be deleted.
- In the navigation pane on the left, choose Risk Prevention > Baseline Inspection. On the Baseline Inspection page, click the Security Standards tab. Then, click the Check Plan tab.
- In the upper right corner of the check plan box, click Delete.
- In the displayed dialog box, click OK.
- Disabling or enabling a check plan
- In the navigation pane on the left, choose Risk Prevention > Baseline Inspection. On the Baseline Inspection page, click the Security Standards tab. Then, click the Check Plan tab.
- Toggle on or off the status button in the box where the target plan is located.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.