21-26
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 21 Rules
Rule and Report Groups
Global Controller and Local Controller Restrictions for Rule and Report Groups
Global Controller and Local Controller rule and report groups have the following restrictions:
•
Rule and report groups created on the Global Controller are pushed to all the Local Controllers.
•
Rule groups created on a Local Controller are local to the Local Controller. They are not copied to
the Global Controller or to other Local Controllers.
•
Local Controller account holders can edit only the Source IP, Destination IP, and Device fields of a
rule group created on a Global Controller.
•
Local Controller account holders cannot edit Global Controller report groups.
•
Local Controller account holders cannot delete Global Controller rule and report groups.
Note
The procedures described in this section are valid for both the Local and Global Controllers, except that
the Case Bar does not appear on the Global Controller HTML interface.
System: COBIT DS9.4: Configuration Control
—
System: COBIT DS9.5: Unauthorized Software
—
System: CS-MARS Distributed Threat Mitigation
(Cisco DTM)
System: CS-MARS Distributed Threat Mitigation
(Cisco DTM)
System: CS-MARS Incident Response
System: CS-MARS Incident Response
System: CS-MARS Issue
System: Client Exploits, Virus, Worm and
Malware
System: Client Exploits, Virus, Worm and
Malware
System: Configuration Changes
—
System: Configuration Issue
System: Configuration Issue
System: Database Server Activity
System: Database Server Activity
System: Host Activity
System: Host Activity
System: Network Attacks and DoS
System: Network Attacks and DoS
System: New Malware Outbreak (Cisco ICS)
System: New Malware Outbreak (Cisco ICS)
System: Operational Issue
System: Operational Issue
System: Reconnaissance
System: Reconnaissance
System: Resource Issue
System: Resource Issue
System: Resource Usage
—
System: Restricted Network Traffic
System: Restricted Network Traffic
System: SOX 302(a)(4)(A)
—
System: SOX 302(a)(4)(D)
—
System: Security Posture Compliance (Cisco
NAC)
System: Security Posture Compliance (Cisco
NAC)
System: Server Exploits
System: Server Exploits
Table 21-2
Predefined Rule and Report Groups (continued)
System Report Groups
Corresponding System Rule Groups