
Assess and remediate
After devices are added and policies are created, view or create a task to run an assessment for a selected device
group in the Tasks page. An assessment can be scheduled to run immediately or to run in the future. The
assessment identies devices in the network that do not comply with the security policy. If you choose to
remediate, devices with non-compliant settings are corrected.
NOTE: For email conrmation of a task, congure the email server.
For instructions, see Congure the email server settings
Run or Schedule an assessment or remediation
Security Manager can run unattended scheduled tasks. These tasks are scheduled by a user to occur periodically.
When the task is complete, you will receive an email notication if the Automation Output feature in the Settings
page is congured for email.
Requirements before creating a new task
●
Enable Allow Automatic Remediation option in Instant-On Security setting to automatically enable device
remediation.
For more information, see Set up Instant On Security.
●
Verify the global remediation setting before running the rst assessment.
For more information, see Verify device remediation and hostname resolution.
●
Check the Quick Settings (Policy) remediation options set in the Policies page.
For more information, see Set severity, remediation, and unsupported behavior to policy items in Quick
Settings.
●
A valid policy to perform an Assess and Remediate task.
NOTE: When scheduling an assessment, the Assess Only option provides a report, but does not change any
device settings. The Assess and Remediate option remediates out-of-compliance devices.
1. Log into Security Manager, and then select the Tasks tab.
2.
Hover on the left navigation pane, and then select the New Task icon ( ).
You can also create a new task from the following pages:
●
Devices: Select the New Task icon from the Devices toolbar.
●
Policies: Select the New Task icon from the Policies toolbar.
3. On the New Task window, select a group or groups from the Selected Group drop-down list.
4. Type a name for a task in the Task Name text box.
5. On the Task Type section, select a task.
●
Assess only: This is the default selected option.
●
Assess and Remediate: A valid Security Manager license is required.
ENWW Assess and remediate 35
Comentarios a estos manuales