Running a Compliance Job
The component templates provided in Compliance Content libraries were designed specifically as the basis for Compliance Jobs that enable you to analyze your compliance with industry standards.
Before you begin
- Ensure that target components have already been discovered against the appropriate template, as discussed in Running a Component Discovery Job.
- Ensure that the location defined by the STAGING_DIR target property exists on target servers. By default the staging directory is \temp\stage (on Windows) or /var/tmp/stage (on UNIX).
- For the CIS and PCIv2 templates for Windows, ensure that you have set the following properties to the appropriate values:
- IS_DOMAIN_CONTROLLER target-level property to true for all the Domain Controller servers, and false for all the Member Servers.
- IS_SSLF property to true if the server profile is Specialized Security - Limited Functionality (SSLF), and false otherwise.
- PCI Properties/CIS Properties properties to one of the following values, depending upon the server profile:
- ENTERPRISE_MEMBER_SERVER, for a Member Server with Enterprise Client (EC) security
- ENTERPRISE_DOMAIN_CONTROLLER, for a Domain Controller with Enterprise Client (EC) security
- SSLF_MEMBER_SERVER, for a Member Server with Specialized Security — Limited Functionality (SSLF)
- SSLF_DOMAIN_CONTROLLER, for a Domain Controller with SSLF
- If you plan to remediate failed components for a single rule group rather than for all compliance rules in a SOX component template, you mustuncomment the duplicate rules within the rule group before you run the Compliance Job. For more information, see Uncommenting duplicate rules for rule-group remediation.
To create and run a compliance job
- Choose between a regular compliance job and a Batch Job. For more information about each method, and to help you choose between these two methods, see Choosing-between-a-regular-Compliance-Job-and-a-Batch-Job.
- Create and run one of the chosen jobs:
- Create and run a regular Compliance Job based on a Compliance Content component template or component. For instructions, see Creating-Compliance-Jobs.
- Customize and run an out-of-the-box Batch Job that includes a Compliance Job and a Network Shell Script Job, which is especially useful for large-scale environments.
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*