Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The General tab of the Policy Properties window allows you to update the name and description of the selected policy. The policy name appears in the Security Summary view under the Policies tree.

Image RemovedImage Added

Security Checks

Security checks assess the vulnerability of specific Windows OS and SQL Server objects based on your criteria. After security checks are configured and your SQL Server instances are assigned to the policy, you can view the results on the Security Overview window and on the Risk Assessment Report.

Image RemovedImage Added

In addition, you can configure email notifications to be sent out when a particular risk level has been passed. For more information, see Configure Email Settings.

Note

When security checks are setup set up for your policies, it is important that accurate criteria is are entered. For example, a typo in the Windows Operating System Version metric criteria could cause erroneous findings.

...

Some security checks allow you to configure the assessment criteria, such as specific user accounts, stored procedures, or the login audit level. Text entered in this field must use the exact spelling of the object being checked. Use the option Edit and and a new window opens where you can specify multiple criteria items (one per line). To delete any previous previously specified criteria, click the corresponding item, and then Remove. 

...

Tip

Some security check criteria support using the percent wildcard character (%) to specify objects whose names apply a naming convention. For example, to specify all users whose logon starts with sql, enter the following syntax:  domain\sql% .


External Cross-Reference 

Allows you to cross-reference a security vulnerability included in your report to a number or name contained in an external security standard.

...

The Audited SQL Servers tab allows you to change which registered SQL Server instances are assigned to this policy. You can add or remove instances from this policy to better match your auditing needs. Each registered SQL Server instance can belong to multiple policies.

Image RemovedImage Added

The Audited SQL Servers tab is located in the Policy Properties window. 

...

The Internal Review Notes tab allows you to edit the manually-collected data applied to your policy. Manually-collected data is security information that cannot be gathered and assessed through IDERA SQL Secure.

Image RemovedImage Added

You can find the Internal Review Notes tab in the Policy Properties window. 

...