×
×
×
×

Auditing Compliance

This page explains how to group compliance policies, configure audit scans, and interpret compliance results at the target group, computer, and policy levels in Endpoint Central.

Note
This feature is not available in all countries. Reach out to support for further details.

Grouping Policies for Audit

The first step in creating a compliance audit is to group the policies against which you want to audit a specific group of target systems for compliance.

Note
Compliance audits only run on target systems whose OS matches that of the policies. It is recommended to group policies based on OS in order to effectively map them to targets belonging to the same OS.

To create a policy group:

  1. Navigate to Compliance → Policy Groups.
  2. If you are just starting out and have not created a Policy Group yet, click View Compliance Policies. This opens a wizard displaying all available policies along with details such as the category, OS platform, and total number of rules against which targets will be scanned.
    Note
    Once a policy group is created, the View Compliance Policies button changes to Create Policy Group.
  3. Give a meaningful name to the Policy Group.
  4. Select the policies you want to group together for audit. Clicking on a policy reveals a detailed breakdown. Refer to this document to learn more about the policies supported and how they are structured.
  5. Click Create Group.

The created group will be listed under the Policy Groups section. Click the created policy group to view the policies included in it. You can use filters to view policies by Deprecation Status and OS platform. Deprecated policies refer to obsolete policies superseded by their latest upgraded version — they appear greyed-out in the console. Endpoint Central immediately supports the superseded version of all deprecated policies. When you map target system groups to this policy group, they will appear under the Mapped Target Groups section.

Under Built-in Templates, policy group templates built by consolidating policies based on OS and profile levels are readily available. Click a template to view the policies included in it. To use a template policy group for audit, click the Add to Policy Groups button against the desired template. These templates will now be available under Policy Groups and can be used for audits.

Configuring a Compliance Audit

Once you have created a policy group, you need to link it to a target custom group where the compliance scan will run.

Navigate to Compliance → Map and Audit Targets → Create Audit.

A new window will open for creating the audit:

  • Under Target Group, choose the custom group where you want to run the compliance check.
  • Under Map Policy Groups, select the policy group you have created under the Map Policy Groups against which the target should be audited option.
  • Under Schedule Scan, select the scan Frequency (daily is recommended so that any deviations from compliance can be tracked easily) and set the Start at date.
  • If you want to configure notifications regarding this CIS compliance audit, enable the Enable Notifications checkbox.

After configuring these settings, click Create Audit and Scan Now to run the compliance scan immediately, or click Create Audit to run the compliance scan in the subsequent refresh cycle.

Compliance Audit configuration window showing Target Group, Map Policy Groups, Schedule Scan, and Enable Notifications options
Compliance Audit configuration window showing target group, policy group mapping, and scan schedule settings.

Once an audit scan has been scheduled for a target group, it will appear in the table in the Map and Audit Targets view. Systems belonging to the target group will then be periodically assessed for compliance against all rules in the mapped policies based on the schedule. The resulting overall compliance percentage will be displayed for each target group.

The overall compliance percentage indicates the percentage of systems that are secure (systems that achieved a compliance percentage of at least 90%) out of the total systems scanned in the target group.

Overall compliance percentage = Number of secure systems (systems that achieved a compliance percentage of at least 90%) / Total scanned systems × 100

Note
Only scanned systems — not all systems — are considered for overall compliance percentage, because new systems may be added to the custom group in the future. If the audit scan runs before this addition, those new machines will not be audited for compliance until the next scheduled scan. If a system is offline during a scheduled scan, the compliance percentage will reflect only the results of the last scan before this scheduled scan. The compliance scan for this system will occur in the subsequent refresh cycle, after which the compliance percentage will be updated accordingly.

Inside the Target Group

Target group compliance view showing compliance status, breakdown of computers by health, and table of scanned computers
Target group compliance view showing compliance status, health breakdown, and per-computer compliance details.

At the top, you can see the name of the target group, who scheduled the audit, and its scan schedule. You can edit the schedule by clicking Modify Schedule.

Compliance Status

This section indicates the number of computers that need attention (computers whose individual compliance is below 90%) out of total scanned computers. According to Endpoint Central, systems that have achieved a compliance of at least 90% are considered secure. The compliance percentage displayed here is the same as the overall compliance percentage of the target group.

Breakdown of Computers by Health

Computers are classified in this section by health based on their compliance percentage.

Compliance Percentage of the SystemsHealth Status
Below 10%Vulnerable — indicates vulnerable computers
10% — 50%Poor Compliance — indicates systems with poor compliance
50% — 90%Moderate Compliance — indicates systems whose compliance can be improved
Above 90%Secure — indicates secure computers

The Table View

The table below lists all computers belonging to this target group. Details such as OS platform, scanned and yet-to-scan policies, and compliance percentage for each computer are available here. If the audit is modified after a scan to map a new policy group, these policies will remain unscanned until the next scheduled scan and will be counted as Yet-to-scan policies.

The compliance percentage of each system indicates the percentage of rules the computer has passed out of the total scanned rules (excluding unscored rules) from all the mapped policies.

Compliance percentage = Rules passed / (Total scanned rules − unscored rules) × 100

Note
Not all rules from the mapped policies factor into your compliance percentage. Rules are excluded in three cases:
  • The rules belong to policies that are yet to be scanned.
  • The rules belong to policies that are not applicable to the system — this can happen if the policy is designed for a particular OS that does not match the system's OS.
  • The rules are labelled as unscored. While these rules are still counted towards the total rule count of a policy, their outcome will not be factored into the compliance percentage.
Also, if a policy group mapped to the target is modified after an audit scan to add or remove policies, those changes will not influence the compliance percentage until the subsequent scan.

You can also view the compliance status and percentage of a computer on a per-policy basis by clicking on a computer.

Individual Computer View

Individual computer compliance view showing compliance status, breakdown of rules by compliance status, and per-policy table
Individual computer compliance view showing rule-level compliance status and per-policy breakdown.

Compliance Status

This section indicates the number of rules the computer has failed to comply with out of the total scanned rules from all the mapped policies. The compliance percentage displayed here indicates the percentage of rules the computer has passed out of the total scanned rules (excluding unscored rules) from all the mapped policies.

Compliance percentage = Rules passed / (Total scanned rules − unscored rules) × 100

Breakdown of Rules by Compliance Status

All rules applicable to the computer are classified in this section based on compliance status:

  • Failed — Rules that the computer configurations failed to comply with.
  • Error — Rules that failed to be processed while scanning.
  • Unscored — These rules are counted towards the total rule count of a policy, but their outcome will not be factored into the compliance percentage. According to CIS, rules are either "scored" or "not scored". Scored recommendations are mandatory to achieve CIS compliance, and if not met will lower the total benchmark compliance percentage. Recommendations that are not scored have no impact on the compliance percentage.
  • Passed — Rules that the computer configurations successfully comply with.

The Table View

The table below lists all policies mapped to this computer along with the number of rules passed in each policy and the compliance percentage per policy. The compliance percentage for each policy indicates the percentage of rules the computer has passed out of the total scanned rules from that policy. You can use the filter option to view rules based on compliance status. For instance, selecting Failed in the compliance status filter displays all failed rules from every policy. Click View Resolution next to a failed rule to view the detailed steps to implement the recommended value.

You can also view the compliance status of a computer on a per-rule basis by clicking on a policy.

Individual Policy View

Individual policy compliance view showing compliance status and breakdown of rules by compliance status for a specific policy
Individual policy compliance view showing rule-level compliance status for the selected policy.

Compliance Status

This section indicates the number of rules the computer has failed to comply with out of the total scanned rules from this particular policy. The compliance percentage displayed here indicates the percentage of rules the computer has passed out of the total scanned rules from the policy.

Breakdown of Rules by Compliance Status

All rules from the policy are classified in this section based on the computer's compliance status:

  • Failed — Rules that the computer configurations failed to comply with.
  • Error — Rules that failed to be processed while scanning.
  • Unscored — These rules are counted towards the total rule count of a policy, but their outcome will not be factored into the compliance percentage. According to CIS, rules are either "scored" or "not scored". Scored recommendations are mandatory to achieve CIS compliance, and if not met will lower the total benchmark compliance percentage. Recommendations that are not scored have no impact on the compliance percentage.
  • Passed — Rules that the computer configurations successfully comply with.

The Policy Breakdown Table View

Refer to this page to learn more about how the policy is structured and for a detailed explanation of the terminologies used. For each title, you can view the number of rules the computer has passed. Click on a title to expand and reveal the rules pertaining to it. You can view the compliance status next to each rule. If you click on a rule, the detailed summary, rationale, and How to Fix columns will be visible. The How to Fix column offers detailed steps to implement the recommended value for each failed rule.

You can also create customized CIS Compliance Reports. Navigate to Reports → Executive Reports and choose CIS Compliance Reports. Refer to this page to learn more about creating one.

Related