Use a built-in or custom control ↗
When using custom standards, you can use built-in controls or create custom controls and then associate them with detection rules.
Add a built-in control to a custom standard
Cortex XSIAM provides built-in controls that cannot be edited or deleted. When you edit or create a custom standard you can add the built-in control.
Create a custom control to use in a custom standard
You can create a new control that is tailored to your own business needs, standards, and organizational policies to use in a custom standard.
- In the Controls catalog, click + Create Control.
- Define control metadata, including:
- A single category
- A single sub category (optional)
- Control name
- Description (optional)
- One or more custom standards to associate the control with
- Click Create.
- Assign a custom detection rule to the control as follows.
Associate a custom control to a detection rule
You can associate custom compliance controls with workload security and cloud security rules. This tailors compliance checks to your organization’s needs. You can associate controls while creating custom rules. You can also associate them when editing custom or built-in rules.
NOTE
Custom rules can only be associated with custom compliance controls.
The following table summarizes supported rule associations.
| Rule type | Built-in rules | Custom rules |
|---|---|---|
| Cloud workload rules | Not applicable. | Associate custom compliance controls while creating or editing custom cloud workload rules. |
| Cloud security rules | Associate custom compliance controls while editing built-in cloud security rules. | Associate custom compliance controls while creating or editing custom cloud security rules. |
NOTE
You can associate custom compliance controls only with ConfigIdentityAI cloud security rules.
To associate a custom compliance control:
- Go to Posture Management → Rules & Policies → Rules → Cloud Workload or Cloud Security.
- Create a custom policy, or edit an existing rule.
- In Overview → Compliance Controls, click Add.
- Select one or more custom compliance controls.
- Click Assign.
- Save your changes.
Edit a custom control
You can edit a copy of a built-in control or edit an existing custom control. You can also delete a custom control.
- In the Controls catalog, click on the built-in control you want to edit and click Save as new.\
To edit a custom control, click on the custom control and click Edit. - Click Next.
- Edit control metadata, including:
- Category: You can reassign the control to a different category.
- Sub category (optional): You can reassign the control to a different sub category.
- Control name: You can update the control name.
- Description (optional): You can update the control description.
- Select custom standards: You can modify the list of custom standards with which the control should be associated.
- Click Save.
If the control does not already contain a rule, assign a custom detection rule to the control.