Evaluates whether all ECS instances in your Alibaba Cloud account have the Security Center agent installed. Instances with the agent installed are evaluated as Compliant.
Scenarios
The Security Center agent detects abnormal logons, scans for vulnerabilities, and checks baseline configurations on Elastic Compute Service (ECS) instances. Use this rule to verify that the agent is installed on all ECS instances in your account.
Risk level
Default risk level: high.
You can change the risk level based on your business requirements when you apply this rule.
Compliance evaluation logic
- If the Security Center agent is installed on all ECS instances in your Alibaba Cloud account, the evaluation result is Compliant.
- If the Security Center agent is not installed on any ECS instance in your Alibaba Cloud account, the evaluation result is Incompliant. For more information about how to remediate an incompliant configuration, see Incompliance remediation.
Rule details
| Item | Description |
| Rule name | ecs-all-enabled-security-protection |
| Rule identifier | ecs-all-enabled-security-protection |
| Tag | SecurityCenter |
| Automatic remediation | Not supported |
| Trigger type | Periodic execution |
| Evaluation frequency | Every 24 hours |
| Input parameter | None. |
Incompliance remediation
To remediate incompliant ECS instances, install the Security Center agent. For more information, see Basic security services.