Lookout Product Documentation

Find answers about using and optimizing Lookout products.

Add New Assessment

  1. From the Management Console, select Protect > Cloud Security Posture Management.
  2. From the Cloud Security Posture Management page, click New.

    You will view these fields initially. Depending on the cloud account you select for the assessment, you will view additional fields.

  3. Enter this information for the new assessment as indicated for the type of cloud account to be used for the assessment.
    Field

    IaaS cloud

    applications (AWS, Azure)

    SaaS cloud

    applications (Salesforce, Office 365)

    Assessment Name

    Enter a name for the assessment. The name can include only numbers and letters - no spaces or special characters.

    RequiredRequired

    Description

    Enter a description of the assessment.

    OptionalOptional

    Cloud Account

    Select the cloud account for the assessment. All information for the assessment will pertain to this cloud.

    The list of cloud applications includes only those for which you have specified Cloud Security Posture as a protection model when you onboarded the cloud.

    RequiredRequired

    Assessment Template

    Select a template for the assessment. The template option shown pertains to the cloud account you select.

    RequiredRequired

    Filter by Region

    Select the region or regions to be included in the assessment.

    OptionalN/A

    Filter by Tag

    To provide an additional level of filtering, select a resource tag.

    OptionalN/A

    Frequency

    Select how often to run the assessment - daily, weekly, monthly, quarterly, or on demand.

    RequiredRequired

    Notification Template

    Select a template for email notifications regarding assessment results.

    OptionalOptional

    Resource Tag

    You can create tags to identify and track failed resources. Enter text for a tag.

    OptionalN/A
  4. Click Next to display the Compliance Rules page, where you can select rule enablement, rule weighting, and actions for the assessment.

    This page lists the compliance rules available for this assessment. The list is grouped by type (for example, rules pertaining to monitoring). To show the list for a type, click the arrow icon to the left of the rule type. To hide the list for that type, click the arrow icon again.

    To display details for a rule, click anywhere on its name.

  5. Configure the rules as follows:
    • Enabled -- Click the toggle that indicates whether the rule will be enabled for the assessment. If it is not enabled, it will not be included when the assessment is run.
    • Weight - The weight is a number from 0 to 5 that indicates the relative importance of the rule. The higher the number, the greater the weight. Select a number from the prompt or accept the default weight shown.
    • Comments - Enter any comments that pertain to the rule. A comment can be helpful if (for example) the rule weight or action is changed.
    • Action - Three options are available, depending on the cloud you selected for this assessment.
      • Audit -- The default action.
      • Tag (AWS and Azure cloud applications) -- If you selected Resource Tags when you created the assessment, you can choose Tag from the prompt. This action will apply a tag to the rule if the assessment finds failed resources.
      • Remediate (Salesforce cloud applications) -- When you select this action, Secure Cloud Access will attempt to resolve issues for failed resources when the assessment is run.
      • Click Next to review a summary of the assessment information.

    Then, click Previous to make any corrections, or Save to save the assessment.

    The new assessment is added to the list. It will run on the schedule you selected. You can also run the assessment any time by clicking the arrow icon in the Actions column.