Skip to main content
Josh Bristow
Veteran
September 24, 2024

Policy Creator - New Option Idea

  • September 24, 2024
  • 14 replies
  • 727 views

I would love to see something like this added to the policy creation section. Think of steps that would be removed by no longer needing to download an existing revision, create a blank policy, and finally importing your revision over the blank. It’s a small thing but when you do it all the time, it’s not so small.

    14 replies

    Guru
    September 26, 2024

    Here is what I use for the function.

    Josh Bristow
    Veteran
    September 26, 2024

    Hey @Josh Bristow - I’m curious, do you use this workflow for creating forked configuration, as well as effectively creating a branch of an existing policy which you then merge back in?

    If you (or any other posters) are forking configuration, I’d be really interested to understand what use-cases usually drive that approach, but also whether you find that it’s the whole configuration which you need, or are you more often cherry picking certain parts of the source configuration (so today you’re having to delete out large chunks to leave the parts you actually want)? 

    We are not cherry picking sections of the policy as we are testing to see how a possible newly added or removed item will effect the policy as a whole.

    Scatts
    BeyondTrust Employee
    BeyondTrust Employee
    September 26, 2024

    Hey @Josh Bristow, what if you were able to simulate a change to policy i.e. add a new application definition and understand if the new rule would hit within the PMC console? 

     

    Preventing the need to deploy the test policy revision to a group of computers and manually replicate the match. By instead, basing the simlulated policy change on audited event data in Analytics.

     

    Woud that help prevent the need to create duplicate policies and use them to test new rules or config changes?

    Josh Bristow
    Veteran
    September 26, 2024

    Hey @Josh Bristow, what if you were able to simulate a change to policy i.e. add a new application definition and understand if the new rule would hit within the PMC console? 

     

    Preventing the need to deploy the test policy revision to a group of computers and manually replicate the match. By instead, basing the simlulated policy change on audited event data in Analytics.

     

    Woud that help prevent the need to create duplicate policies and use them to test new rules or config changes?

    it might help. My issue is that we are required to test all proposed rules with the requester or machines specified by the requester. Even after that initial test is done, we port the change over to the prod policy and apply it to an even larger group of testers from all firms before applying to the entire estate.