McAfee QUICKCLEAN 3.0 Technical Information Page 103

  • Download
  • Add to my manuals
  • Print
  • Page
    / 212
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 102
Comodo Endpoint Security Manager - SME - Administrator Guide
View All Policies - Allows administrators to view, add, reconfigure and export ESM polices
Create Policy - A step-by-step wizard that takes admins through the policy import, specification and deployment
process
Before proceeding with creating a policy, read the 'Key Concepts' section below to gain a baseline understanding first.
Policies - Key concepts
Policies are security settings for the installed components of CIS configured and tested on a local machines via the
standard CIS interface.
Policies can be imported from an endpoint into the ESM console then applied to target computers or groups of
computers. The machine chosen for this purpose can be considered a template of sorts for other equivalently
configured machines in the organization (i.e. having the same hardware/software – a computer used to image other
endpoints in the organization is ideal for this purpose). This allows admins to create a 'model' configuration on one
machine that can be rolled out to other computers.
Policies can also be created by:
Importing CIS configuration from a previously saved .xml file or image.
Importing an existing policy to use as the starting point for a new policy.
Policies can be named according to criteria deemed suitable by the administrator. For example, policies based on
security levels could be named 'Highly Secure', 'Medium Security' and 'Low Security'.
At the administrator's discretion, a policy can cover settings for all or only some of the three CIS components that may
be installed on an endpoint:- Antivirus, Firewall, and Defense + settings. A policy which excludes settings for one of the
CIS components installed on the endpoint receiving policy is considered as locally configured (see below) for the
settings of that component.
The ESM agent installed at each endpoint is responsible for connecting the target machine to the respective ESM
server and the remote management of the CIS installation. Only the agent applies the security policy settings to
different components of the CIS application and checks whether the application is compliant to policy.
Each endpoint has two types of policy assigned to it:directly, or via the group that an endpoint is a member, 'Local
Policy' and 'Internet Policy':
A 'local policy' which describes the CIS security settings that will apply when the endpoint is within the local
network.
An 'Internet policy' which is automatically applied when the endpoint connects to ESM from an IP address
outside the local network.
Policy and CIS Mode are independent of each other. 'CIS Mode' can be either 'Local' or 'Remote' and this determines
whether or not ESM will enforce policy compliance on an endpoint:
Remote Mode - The policy of an endpoint in remote management mode will be determined by the ESM
console. If the endpoint falls out of compliance (because CIS settings have been altered) then the console
will automatically re-apply the assigned policy to the endpoint. This is the ideal situation for ongoing
management.
Endpoint Security Manager - SME Administrator Guide | © 2013 Comodo Security Solutions Inc. | All rights reserved 103
Page view 102
1 2 ... 98 99 100 101 102 103 104 105 106 107 108 ... 211 212

Comments to this Manuals

No comments