
• Example of scoring impact:
A benchmark has 5 rules. An audit is run on a system and 4 rules pass and 1 fail, resulting
in a score of 80%. If the system is granted an exemption waiver, that system does not
appear in the scoring.
Suppression waivers
Suppression waivers allow a rule to be included in an audit, but excludes the result, thus altering
the benchmark score of a system. Suppression waivers have the following characteristics
• Each waiver applies only to a single managed system. Suppression waivers require you to
select a benchmark and a rule.
• The benchmark's rule is included when the system is audited.
• Rule audit results are not included in the score.
• Only benchmarks that are Active can be specified in the waiver.
• Suppression waivers cannot be backdated.
• Rules used in an suppression waiver do not appear in the scoring for a system.
• Rules used in an suppression waiver appear in the audit results.
• Example of scoring impact:
A benchmark has 5 rules. An audit is run and 4 rules pass and 1 fail, resulting in a score of
80%. If the rule that failed is granted a suppression waiver, then the score is 80%.
Waiver status
Waivers can have the following status properties:
DescriptionStatus
A waiver has been requested but approval has not been
granted for it to take effect. Requested waivers do not
Requested
appear on the Waivers tab but appear in the Issue
Catalog (go to Reporting | Issues). Requested waivers
can be deleted.
A waiver has been requested and granted approval but
the waiver is not in effect because the start date has not
yet arrived. Upcoming waivers can be deleted.
Upcoming
The waiver is active and audits involving the system
specified by the waiver will temporarily affect the scoring
of the system. In-effect waivers cannot be deleted.
In-effect
The waiver is no longer in effect, either by user
intervention or because the expires date has arrived.
Expired waivers cannot be deleted.
Expired
Waiver benchmark and rule management
Exception and Suppression waivers require that you assign a benchmark and rule to them.
These types of waivers are both rule-based and system based. Exemption waivers are
Creating and Managing Waivers
Waiver status
McAfee Policy Auditor 5.0 Product Guide48
Comentarios a estos manuales