Detecting Security Risks in the Security Score Module
During the operations and management of enterprise cloud assets, insufficient security visibility and delayed risk handling are the core pain points that lead to frequent security incidents. SecMaster integrated in COC builds a security scoring system from three core dimensions: compliance check, vulnerability scanning, and threat alarm, providing enterprises with quantitative evaluation of cloud asset security statuses and risk locating capabilities. Enterprises can convert the scores and risk data into security protection capabilities through full-process management, including regular monitoring, in-depth analysis, closed-loop handling, and continuous optimization, to systematically improve the security of cloud assets.
Precautions
If you go to the Secure Score area on the Overview page by creating an IAM 3.0 agency and switching the role, and set the policy authorization scope to global service resources, you need to add the SecMaster ReadOnlyAccess-All resources authorization for the delegation.
Viewing Security Score
- Log in to COC.
- On the COC overview page, access the security score module, and view the security score provided by SecMaster.
The security score shows the overall health status of your workloads on the cloud based on the service version you are using. You can quickly learn about unhandled risks and their threats to your assets.
- The security score is automatically updated at 02:00 every day. You can also click Check Again to update it immediately.
- The score ranges from 0 to 100. A higher score indicates fewer risks and more secure assets. For details about the security score, see Security Overview and Situation Overview.
- Different color blocks in the security score ring chart indicate different severity levels. For example, yellow indicates that your security is medium.
- The security score is updated when you refresh the status of the alert incident after risk handling. After you fix the risks, you can click Check Again so that SecMaster can check and score your system again.
After risks are fixed, manually ignore or handle alert incidents and update the alert incident status in the alert list. The risk severity can be down to a proper level accordingly.
- The security score reflects the security situation of your system last time you let SecMaster check the system. To obtain the latest score, click Check Again.
- Click Go to Process. The SecMaster page is displayed, on which you can view the updated monitoring data.
Figure 1 Checking information in the Security Score area
Helpful Links
The security score data comes from SecMaster. For details, see the following:
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot