Manage custom posture checks in Strata™ Cloud Manager's Unified Incident Framework to
enforce security policies and maintain compliance.
| Where Can I Use This? | What Do I Need? |
|
|
- Strata Cloud Manager Pro
- Strata Cloud Manager Essentials for predefined check
exceptions
- Panorama® CloudConnector Plugin 3.0.0 or later for
Panorama managed deployments
- Traffic logs in Strata Logging Service
|
Custom posture checks are configurable rules within Strata Cloud Manager's Unified
Incident Framework that evaluate configuration compliance against your defined
security policies. Posture Checks—which include pre-defined best practices—are
global to your tenant. This means they appear in every incident setting and deliver
verdicts regardless of your specific configuration. Incident Settings function as a
filter applied to those verdicts, enabling you to define exceptions or trigger
specific notification profiles. The behavior of these exceptions may vary based on
which feature utilizes the check results.
Posture checks are organized under the Posture product category in your
environment. This hierarchy subdivides into Configuration, which includes
subcategories such as:
- Infrastructure Best Practice & Compliance
- Network Best Practice & Compliance
- Security Best Practice & Compliance
This structure provides a logical framework for categorizing and locating specific
checks.
Posture Check incident codes use the format:
INC_BPA_OBJECT_NAME_POSTURE_CHECK_VIOLATION. For instance,
if you manage checks that assess the Security Policy configuration object,
the incident code you use is: INC_BPA_SECURITY_POLICY_POSTURE_CHECK_VIOLATION. You can quickly find the setting for a specific check by
using the "Incident Code" filter at the top of the page. To
manage the example check, search for "security_policy" in the Incident
Code filter's search box.
Exceptions
Exceptions allow you to bypass specific posture check verdicts under defined
circumstances, providing flexibility in policy enforcement. You can configure
exceptions at two distinct levels: global and scope-based.
Global exceptions apply universally across all scopes within your tenant. You define
them within the default incident code settings for a specific check, providing a
broad mechanism to disable or enable a check's enforcement across your entire
environment.
Scope-based exceptions offer more granular control, allowing you to define exceptions
for specific configuration objects or groups. You configure these within custom
settings, and they follow 'longest match' logic, meaning a custom setting with more
specific match criteria overrides a broader default setting. This allows for
exceptions down to a single configuration object, such as a particular security
policy in your network. See
Incident Setting Resolution.
Here is a video that shows how to manage Custom Posture Checks within the Unified
Incident Framework in Strata Cloud Manager.