Work with policy sets

AppViz automatically gathers policy set information related to the security controls in your cloud accounts, subscriptions, and projects. This topic describes how you can review and manage your policy sets to ensure network security.

Policy set details

You can review detailed information on policy sets detected in your cloud accounts. For more information on policy set details based on the security control:

Merge policy sets

For Azure NSG, Azure Firewall (classic), and AWS SG

Since each detected network policy is assigned its own, individual policy set by default, you'll want to merge similar policy sets together to view and manage them together.

Note:

  1. Merging policy sets is only supported within the same policy type. AppViz does not support merging policy sets across AWS SG, Azure NSG, and Azure Firewall (classic).

  2. For merged policies, risk severity circles are not displayed and the Risks column is greyed out (not active).

Do the following:

  1. View the policy sets you want to merge, using the search box to search for similar items. For details, see Search policy sets.

  2. Expand each policy set to inspect its details and confirm that you want to merge them.

  3. Select the check boxes next to each policy set you want to merge, and then click Merge.

    Tip: If you have many policy sets to select, use the Select all or Unselect all links above the grid as needed.

  4. In the Merge Policy dialog box that appears, enter a name for your new policy set, and an optional description.

    Click Merge to merge the selected policies into a single set.

    The policy set grid is updated with your new set. For example:

Tip: To dissolve your merged policy set and return each policy to its own individual set, commit or discard any changes made, and then edit the properties for your merged set.

For details see Edit policy set properties.

Edit policy set properties

For Azure NSG, Azure Firewall (classic), and AWS SG

Edit the properties for each policy set to change the name, description, or member security controls.

Note: If you want to add or modify policy rules, drill down into the policy set itself.

If your policy set is currently in Edit mode, you will not be able to modify the policy set properties. Commit or discard your changes to make these edits.

For more details, see Edit network policy rules.

Do the following:

  1. View the policy set whose properties you want to edit.

    Tip: You may want to use the search box to find the one you're looking for. For details, see Work with policy sets.

  2. Click the properties button next to the policy set name.

  3. In the Network Policy Set Properties dialog that appears, do any of the following:

    Name Edit the name listed for the policy set in the grid.
    Description Enter a description for the policy set. This description is shown in the grid when you hover over the Description icon.
    Security Controls

    This area lists the security controls included in the policy set.

    • Click an X to remove a single security control from the set.
    • To completely dissolve the set and return each policy to its own individual set, click Clear all controls. In the message that appears, click Yes to confirm.

    Tip: To add a new security to control to a policy set, merge the relevant sets together. For details, see Merge policy sets.

Edit network policy rules

For Azure NSG, Azure Firewall (classic), and AWS SG

Edit each of your network policies by adding, deleting, and modifying rules and rule collections in the network policy set.

  • Any changes made in a specific rule affect all security controls where the rule is installed.

  • Only one user can edit each policy set at a given time. Policy sets are locked while editing and are opened in read-only mode by default.

    When you're done, click Commit or Discard changes to unlock the policy set for others.

For Azure Firewall (classic) only: Once a rule collection is created, its priority, name, and action are all read only. The rules inside a rule collection, however, can be edited.

Note: If you want to make higher-level changes, such as the policy set name, description, or member controls, view the policy set from its parent level. For more details, see Edit policy set properties and Network Policies page.

Do the following:

  1. Browse to and expand a specific network policy set. For details, see Network Policies page.

    Rules are displayed in a boxed grid that lists the source, destination, and protocol details for each rule, as well as the security controls each rule is installed on.

    If you are in read-only mode, a large Edit button is shown at the top right of the policy set box. Click the Edit button to make changes to the expanded policy.

    Note: For Azure Firewall (classic), the rules are grouped by rule collection. Expand the collection to drill down to rule details.

  2. Do any of the following:
  3. Do one of the following:

    • Click Discard changes to revert back to the last saved version of the policy set and unlock it for others.

    • Click Commit at the top of the screen to save your changes.

      AppViz displays a list of the changes you made. Accept the changes to complete the commit.

      The commit provisions your changes on the security controls and unlocks the policy for others.

Note: Your changes are automatically saved, even if you haven't committed them, closed your browser or logged out of AppViz. They will be there for you the next time you browse back to this policy set. However, the policy set remains locked for others until you commit or discard your changes.