User Guide
ICS Dissolvable Agent for SafeGuard Administration Guide
24
Chapter 4: Administering Security Scanner Policies
This chapter contains information about how to administer your policies using the ICS
Administrator Console. Policies control what the Integrity Clientless Security Scanner
checks for on your end point computers. Policies consist of collections of enforcement
rules, which specify whether to prohibit or require certain applications, and what action
to take if the end point computer is out of compliance with the rule.
Understanding Integrity Clientless Security Scanner
Integrity Clientless Security Scanner requires no pre-installed software on end point
computers, except a supported browser. The Security Scan is performed by a Java or
ActiveX component that is deployed from your Web server to each end point computer
that requests access.
Implementing Policies
This section describes all the steps you need in order to use policies to secure your end
points. If you do not complete all these steps, your policies will not be enforced.
To Implement policies
1 Create your enforcement rules. See Understanding Enforcement Rules on page 24.
2 Use the enforcement rules to create a policy. See Creating Policies on page 32.
3 Activate the policy. See Activating Policies on page 32.
4 Save your configuration.
Understanding Enforcement Rules
Use the Enforcement Rule page in the ICS Administrator Console to manage your
enforcement rules. You must add an enforcement rule to a policy and make that policy
the active policy for the rule to take effect. Any changes you make to an enforcement rule
affects all the policies that contain that rule. When you delete an enforcement rule, it is
removed from all your policies. You are warned when you delete an enforcement rule
that is currently being used in a policy.
Each enforcement rule consists of the following parts:
NOTE: If you do not want to create your own policies, you can use the
sample policies included with ICS. ICS includes high, medium, and low
sample policies that you can activate. You can also edit these rules to
customize them.










