Cloud Workload Rules page ↗
The Cloud Workload Rules page allows users to manage rules. Users can create, edit, filter, and manage rules.
Note
Keep the following caveats in mind when working with Rules:
- Instance Administrators can view all facets of Rules without restrictions, even when Scope-Based Access Control (SBAC) roles are in effect.
- If you’ve been assigned a custom role with View/Edit permissions limited by SBAC, you may not be able to view specific Rules.
- You can further narrow your search in a Rules table by using SBAC to limit the scope of the findings, issues, and case counts.
The Widget section enables users to get 'at-a-glance' information based on Platform, Rule type, and Scanner type.
The Cloud Workload Rules page displays both the default rules and user-configured rules, with the following fields.
Rules table columns
| Column Name | Description |
| Rule ID | A unique identifier assigned to each rule. |
| Rule Name | The name of the rule, typically defined by the user or system. |
| Description | A brief summary of the rule's purpose and functionality. |
| Policies | Lists the policies in which the rule is included. |
| Controls | Compliance controls associated with the rule for regulatory adherence. |
| Platform | Specifies the platform or environment the rule applies to. For example: Linux, Windows or Kubernetes. |
| Scanner | The tool or method used to evaluate findings, such as Inventory Scanner, Agentless Disk Scan, Host Scanner, Kubernetes Connector or Kubernetes File System Scanner . |
| Severity | Defines the severity of the rule. |
| Data Type | The type of data the rule evaluates. For example: Hosts or Kubernetes Resources |
| Created By | The user who created the rule. |
| Last Modified | The date and time the rule was last updated. |
| Rule Type | Indicates whether the rule is a Built-in or Custom rule. |
| Remediation | Defines the remediation steps to address the detected misconfiguration. |
| Applicable assets | Supported applicable asset types. |
| Available actions | Indicates whether the available action is Prevent and Create an Issue or Create an Issue |
| Standards | Associated compliance standards or controls |
| Open issue | No. of open issue related to this rule. |
Filter page results
You can use Show filter Panel button in the upper-right corner of the Rules page to filter the existing rules based on different filter criteria, as described below:
Table 6. Rule Filter table
| Filter | Allowed Values |
| Rule Name | Rule names and empty values |
| Description | Rule description and empty values |
| Policies | No. of policies |
| Controls | No. of controls |
| Platform | Linux, Windows and Kubernetes |
| Scanner | Agentless Disk Scan, Host Scanner, Kubernetes Connector, Kubernetes File System Scanner and Inventory Scanner |
| Data type | Hosts, Kubernetes Resources |
| Severity | Informational, Low, Medium, High and Critical |
| Created by | System or specific username |
| Last modified | Selected date and time |
| Rule type | Built-in and Custom |
| Remediation | Remediation values |
| Applicable assets | Supported applicable asset types |
| Available actions | Prevent and Create an Issue and Create an Issue |
| Standards | Associated compliance standards or controls |
| Open Issues | No. of open issue |
| Rule ID | Unique Id of a rule |
Change the layout of the rules table
- Navigate to Posture Management > Rules > Cloud Workload.
- In the Cloud Workload Rules page, click the More Options icon (⋮).
- In the Layout tab, do the following:
- To add or remove columns, search for a specific column and:
- Click + to add it to the table.
- Click - to remove it from the table.
- To reorder columns, go to the In View section and click and drag columns up or down.
- To add new columns, go to the Add Columns section and click + to include them in the table.
- To add or remove columns, search for a specific column and:
- The table layout updates automatically based on your selections.
Rule details panel
The rule panel displays the following details related to the selected rule:
- Details of the rule like scanner details, remediation details, and more.
- Compliance Controls for the rule.
This panel enables you to:
- Edit the rule
- Save as new
- Delete the rule