Creating and installing a policy and policy rules
Use the Policy Builder for Data to manage policies and policy rules.
About this task
The Policy Builder for Data provides a single solution for creating and modifying policies, policy rules, and policy rule actions. This procedure describes an end-to-end workflow for creating and installing a policy.
Note: After you update a policy (such as changes to group members, policy rules, or actions), you
must reinstall the policy. You can either reinstall the policy on a managed unit, or select
Policy installation schedule from the configuration profile. Use the
Policy installation schedule to schedule a distribution that pushes the policy
from the central manager to specified managed units. For more information, see Distributing configuration profiles from central managers.
Important: Policies that are installed from the central manager to an
aggregator might appear in the aggregator UI as not installed because you cannot install policies on
an aggregator. To determine whether a policy is installed, run the list_installed_policies API or check in
the Policy Builder for Data page for each aggregator.
Procedure
- Navigate to .
-
Create a policy or clone an existing policy or policy template.
- To create a new policy, click the
icon. - To clone an existing policy, select an existing policy or policy template from the
Security Policies window and click the
icon.Tip: Guardium provides templates of predefined policies that you can use to build similar policies. Clone the [template] version and customize it as needed.
- To create a new policy, click the
-
Click the Rules ribbon to begin working with policy rules.
- To create a new rule, click the
icon. - To clone a rule, select an existing rule and click the
icon. - To edit a rule, select an existing rule and click the
icon.
- To create a new rule, click the
- When you finish defining the policy and its rules, click OK to save the policy and return to the Security Policies table.
What to do next
You can also install policies by using . For more information, see Using the Policy Installation tool.