Installation guide

Table Of Contents
You can create your own compliance templates or modify templates that you downloaded from the
Center for Policy and Compliance.
Prerequisites
n
Collect data from your virtual and physical machines for the data types against which your compliance
templates and filter sets run. See "Collect Linux, UNIX, and Mac OS X Data" on page 132 and "Collect
Windows Data" on page 93.
n
Download existing compliance templates that are applicable to your environment from the VMware
Center for Policy and Compliance. See "Download and Import Compliance Content" on page 182.
Procedure
1. "Create Machine Group Compliance Rule Groups" on page 183
Rule groups contain compliance rules and filters. You must create rule groups that you then assign to
compliance templates.
2. "Create and Test Static Machine Group Compliance Rules" on page 184
You create rules that define the ideal values that virtual or physical machines should have to be
considered compliant.
3. "Create and Test Machine Group Compliance Filters" on page 185
You can create filters that limit the virtual or physical machines on which the templates run to only the
machines that meet the filter criteria.
4. "Preview Machine Group Compliance Rule Groups" on page 186
You use the rules preview action, with the filters turned off and then turned on, to determine if a rule
group is returning the expected results.
5. "Create Machine Group Compliance Templates" on page 187
You can create compliance templates that include one or more rule groups that assess your selected
virtual or physical machine group to determine which machines are compliant and noncompliant.
6. "Run Machine Group Compliance Templates" on page 188
You run templates against your collected data to determine which virtual or physical machines are
compliant or noncompliant.
7. "Resolve Noncompliant Compliance Template Results" on page 189
The results for the compliance templates indicate whether the virtual or physical machine are
compliant or noncompliant. If the machine is noncompliant, you can enforce noncompliant results
manually or using VCM, or you can add an exception for expected noncompliant results.
8. "Configure Alerts and Schedule Machine Group Compliance Runs" on page 192
(Optional) To optimize how VCM monitors the compliance of physical and virtual machines in your
environment, configure alerts and schedule regular compliance template runs on your collected
machine group data.
Create Machine Group Compliance Rule Groups
Rule groups contain compliance rules and filters. You must create rule groups that you then assign to
compliance templates.
Templates can include one or more rule groups. Rule groups comprise rules and filters.
Running and Enforcing Compliance
VMware, Inc.
183