Bu sayfa henüz yerel dilinizde mevcut değildir. Daha fazla dil seçeneği eklemek için yoğun bir şekilde çalışıyoruz. Desteğiniz için teşekkür ederiz.

Compute
Elastic Cloud Server
Huawei Cloud Flexus
Bare Metal Server
Auto Scaling
Image Management Service
Dedicated Host
FunctionGraph
Cloud Phone Host
Huawei Cloud EulerOS
Networking
Virtual Private Cloud
Elastic IP
Elastic Load Balance
NAT Gateway
Direct Connect
Virtual Private Network
VPC Endpoint
Cloud Connect
Enterprise Router
Enterprise Switch
Global Accelerator
Management & Governance
Cloud Eye
Identity and Access Management
Cloud Trace Service
Resource Formation Service
Tag Management Service
Log Tank Service
Config
OneAccess
Resource Access Manager
Simple Message Notification
Application Performance Management
Application Operations Management
Organizations
Optimization Advisor
IAM Identity Center
Cloud Operations Center
Resource Governance Center
Migration
Server Migration Service
Object Storage Migration Service
Cloud Data Migration
Migration Center
Cloud Ecosystem
KooGallery
Partner Center
User Support
My Account
Billing Center
Cost Center
Resource Center
Enterprise Management
Service Tickets
HUAWEI CLOUD (International) FAQs
ICP Filing
Support Plans
My Credentials
Customer Operation Capabilities
Partner Support Plans
Professional Services
Analytics
MapReduce Service
Data Lake Insight
CloudTable Service
Cloud Search Service
Data Lake Visualization
Data Ingestion Service
GaussDB(DWS)
DataArts Studio
Data Lake Factory
DataArts Lake Formation
IoT
IoT Device Access
Others
Product Pricing Details
System Permissions
Console Quick Start
Common FAQs
Instructions for Associating with a HUAWEI CLOUD Partner
Message Center
Security & Compliance
Security Technologies and Applications
Web Application Firewall
Host Security Service
Cloud Firewall
SecMaster
Anti-DDoS Service
Data Encryption Workshop
Database Security Service
Cloud Bastion Host
Data Security Center
Cloud Certificate Manager
Edge Security
Blockchain
Blockchain Service
Web3 Node Engine Service
Media Services
Media Processing Center
Video On Demand
Live
SparkRTC
MetaStudio
Storage
Object Storage Service
Elastic Volume Service
Cloud Backup and Recovery
Storage Disaster Recovery Service
Scalable File Service Turbo
Scalable File Service
Volume Backup Service
Cloud Server Backup Service
Data Express Service
Dedicated Distributed Storage Service
Containers
Cloud Container Engine
SoftWare Repository for Container
Application Service Mesh
Ubiquitous Cloud Native Service
Cloud Container Instance
Databases
Relational Database Service
Document Database Service
Data Admin Service
Data Replication Service
GeminiDB
GaussDB
Distributed Database Middleware
Database and Application Migration UGO
TaurusDB
Middleware
Distributed Cache Service
API Gateway
Distributed Message Service for Kafka
Distributed Message Service for RabbitMQ
Distributed Message Service for RocketMQ
Cloud Service Engine
Multi-Site High Availability Service
EventGrid
Dedicated Cloud
Dedicated Computing Cluster
Business Applications
Workspace
ROMA Connect
Message & SMS
Domain Name Service
Edge Data Center Management
Meeting
AI
Face Recognition Service
Graph Engine Service
Content Moderation
Image Recognition
Optical Character Recognition
ModelArts
ImageSearch
Conversational Bot Service
Speech Interaction Service
Huawei HiLens
Video Intelligent Analysis Service
Developer Tools
SDK Developer Guide
API Request Signing Guide
Terraform
Koo Command Line Interface
Content Delivery & Edge Computing
Content Delivery Network
Intelligent EdgeFabric
CloudPond
Intelligent EdgeCloud
Solutions
SAP Cloud
High Performance Computing
Developer Services
ServiceStage
CodeArts
CodeArts PerfTest
CodeArts Req
CodeArts Pipeline
CodeArts Build
CodeArts Deploy
CodeArts Artifact
CodeArts TestPlan
CodeArts Check
CodeArts Repo
Cloud Application Engine
MacroVerse aPaaS
KooMessage
KooPhone
KooDrive
Help Center/ Situation Awareness/ User Guide/ Baseline Inspection/ Handling Baseline Inspection Results

Handling Baseline Inspection Results

Updated on 2023-01-13 GMT+08:00

This topic describes how to handle unsafe settings by referring to recommended fixes and how to report manual check results to SA.

Prerequisites

  • Your professional edition SA is available.
  • The cloud service baseline has been scanned.

Handling Unsafe Settings

The following describes how to fix unsafe settings discovered by check item IAM user login protection.

  1. Log in to the management console.
  2. Click in the upper left corner of the page and choose Security & Compliance > Situation Awareness.
  3. In the navigation pane on the left, choose Baseline Inspection.
  4. Select the region where the check result to be viewed is located.
  5. On the Security Standards tab, choose Cloud Security Compliance Standard 1.0, and view the risk status of check items.

    Figure 1 Check item status
    • If the icon of a check item status is green, the configuration is correct and no unsafe settings found.
    • If the icon of a check item status is red, there may be inappropriate configurations and the assets may have potential risks.

  6. In the row containing the IAM user login protection check, click View Details in the Operation column.
  7. View the risk details and fix the unsafe settings by referring to Result and Reference.

    Table 1 Check item description

    Parameter

    Description

    Status

    Displays the check status of the current check item.

    • If the result is Passed, the configuration corresponding to the check item is appropriate.
    • If the result is Failed, the configuration corresponding to the check item is inappropriate. The check results will be listed.

    Latest Check

    Last time when the current check item was performed.

    Check Method

    Method used by the current check item.

    Severity

    Severity of the unsafe settings discovered against the current check item.

    Impact

    Security impact caused by unsafe settings discovered against the current check item.

    Standard and Category

    Security standard and category of the current check item.

    Description

    Check content of the current check items.

    Check Process

    Check process of the current check item.

    Reference

    Links of documentation related to the check item.

    Click the reference link to go to the detailed page.

    Resource

    Resource to which the current check item belongs.

    The check result can be Passed or Failed.

    • If the result is Passed, the configuration corresponding to the check item is appropriate.
    • If unsafe settings are found, the detailed information is listed. You can click the button in the Operation column to go to page and fix the configuration.

  8. After all unsafe configurations are rectified, click Check to verify that all risky items have been rectified.

Reporting Manual Check Results to SA

For manual check items, after you finish each check, report the check results to SA. The pass rate is calculated based on results from both manual and automatic checks.

  1. Log in to the management console.
  2. Click in the upper left corner of the page and choose Security & Compliance > Situation Awareness.
  3. In the navigation pane on the left, choose Baseline Inspection.
  4. Select the region where the check result to be viewed is located.
  5. In the Operation column of the target manual check item, click Manual Check.
  6. In the displayed dialog box, select a result and click OK.

    Figure 2 Manually Check
    NOTE:

    Report manual check results every 7 days as your feedback is valid only for 7 days.

Ignoring a Check Item

If you have custom requirements for a check item, ignore the check item. For example, SA checks whether the session timeout duration is set to 15 minutes, while you need to set it to 20 minutes. In this situation, ignore this check item so that SA no longer executes this check.

An ignored check item will be no longer executed. It will not be counted when the Pass Rate is calculated.

  1. Log in to the management console.
  2. Click in the upper left corner of the page and choose Security & Compliance > Situation Awareness.
  3. In the navigation pane on the left, choose Baseline Inspection.
  4. Select the region where the check result to be viewed is located.
  5. On the Security Standards tab, locate the row containing the check item you want to ignore, click Ignore in the Operation column.

    To ignore more than one check item at a time, select all the check items you want to ignore, and click Ignore in the upper left corner of the check item list.

  6. In the displayed dialog box, click OK.

    Figure 3 Ignore the following check items?
    NOTE:
    • Ignored check items will be not executed. They will not be counted when the Pass Rate is calculated.
    • To resume an ignored check item, locate the row containing the ignored check item, and click Unignore in the Operation column. Then, in the displayed dialog box, click OK.

Sitemizi ve deneyiminizi iyileştirmek için çerezleri kullanırız. Sitemizde tarama yapmaya devam ederek çerez politikamızı kabul etmiş olursunuz. Daha fazla bilgi edinin

Feedback

Feedback

Feedback

0/500

Selected Content

Submit selected content with the feedback