Policies included with the Security Posture Control application
Summarize
Summary of Policies included with the Security Posture Control application
The Security Posture Control (SPC) application includes a set of predefined policies designed to monitor key security use cases and provide actionable insights via the SPC Workspace dashboard. These policies focus on monitoring security controls coverage, identifying unmanaged devices, detecting risky security configurations, and supporting mitigation controls through API integrations.
Show less
By default, these policies are deactivated and cannot be edited directly but can be cloned to create custom policies tailored to your organization's specific security posture requirements.
Viewing and Managing Policies
- Access included policies by navigating to Workspaces > Security Posture Control > Policies and findings > All.
- Activate policies to begin seeing findings and results; inactive policies do not generate data.
- Policies are read-only but can be cloned to serve as templates for custom policy creation.
- Cloned policies do not appear as built-in key insights on the Home dashboard but can be configured to generate findings and custom insights.
- Custom insights for cloned or newly created policies must be set up in the Custom insight builder module to visualize data on the Custom insights dashboard.
Included Policy Categories
- Security controls coverage monitoring, including endpoint protection and vulnerability scanning.
- Identification of unmanaged devices within the environment.
- Detection of toxic or critical security combinations such as missing controls or internet exposure.
- Mitigation controls monitoring through SPC API integrations.
Asset Profiles and Tool Integration
Activate included asset profiles and policies to evaluate configuration and coverage gaps across key security tools such as:
- CrowdStrike
- Microsoft Intune, Defender, and SCCM
- HCL BigFix
- Qualys
- Rapid7
This enables a comprehensive view of your security posture and helps identify areas requiring remediation.
Creating Custom Policies
Customers can create custom policies from scratch or by cloning existing policies to tailor security monitoring to internal requirements. Custom policies support more granular control and can be integrated into your remediation workflows.
For detailed guidance on creating and activating custom policies, refer to the Security Posture Control documentation covering policy creation, examples of base, child, and cloned policies, and mitigation controls policies.
There are a few policies that are included with the Security Posture Control application that are tied to important use cases and are ultimately shown as key insights on the dashboard on the landing page (Home module) in the SPC Workspace.
Viewing policies
To view these policies, navigate to .
These policies are deactivated by default. You must activate them before you can view returned results (Findings). You cannot edit these policies, but you can use them to help you create other policies by cloning their conditions as a starting point. See Clone a policy or create a child policy in Security Posture Control for more information.
You can clone these policies to create your own custom policies but note that any policies you clone are not reflected as key insights on the dashboard on the Home landing page with the key insights that are included with the application. However, you can configure findings for these cloned policies and see the returned results from these policies.
You can configure custom insights or reports for the cloned policies, or, alternatively configure findings for these cloned policies to manage remediation. You can also create your own custom policies from scratch to monitor security controls coverage as per your internal requirements.
- Policies that monitor security controls coverage (endpoint protection and vulnerability scanner).
- Policies that identify unmanaged devices.
- Policies that monitor toxic combinations that involve critical combinations such as missing security controls, internet exposure, and so on.
- Policies for SPC API Integrations for Mitigation Controls Monitoring.
After you clone and activate any policies you create, you must create your own custom insight record on the Custom insight builder module in the workspace (the last module in the navigator panel). Only then can you view the data from your policies on the Custom insights dashboard (the second icon from the top in the workspace).
Policies and asset profiles included with the application
Get insights into your overall security posture and configuration gaps in your security tools using the policies and asset profiles that are included with the application. Activate these asset profiles and policies in the Security Posture Control workspace so that you can identify gaps in configuration or coverage of the following tools:
- CrowdStrike
- Microsoft Intune, Defender, and SCCM
- HCL Big Fix
- Qualys
- Rapid7
Creating your own policies
See Creating your own policies in the Security Posture Control application for more information about how to create your own policies.
For example policies, see Examples of base, child, and cloned policies for Security Posture Control.
See Create and activate custom policies for Security Posture Control for more information about the steps required to create a policy.
See Mitigation controls policies for more information for more information about policies used for mitigation controls monitoring.