All Products
Search
Document Center

Security Center:Configure and run baseline check policies

Last Updated:Jun 04, 2026

You can configure baseline check policies by type, create baseline whitelists, or define custom weak password rules. After configuration, you can run baseline risk checks on your target servers for results tailored to your needs.

Prerequisites

  1. The baseline risk check feature is enabled.

  2. Servers you want to check must have the Security Center agent installed and be added to Security Center. For more information, see Install the agent and Manage servers.

Configure check policies

Security Center provides a default baseline check policy with over 70 check items and various baseline types. You can add check items and create policies to meet your needs.

  1. Log on to the Security Center console.

  2. In the left-side navigation pane, choose Risk Governance > Cloud Security Posture Management. In the upper-right corner of the page, click Policy Management.

  3. In the Policy Management panel, configure baseline check policies.

    Scan policies

    On the Baseline Check Policy tab, configure and add check policies.

    • Set the baseline scan coverage level.

      You can set the risk level to High, Medium, Low, or a combination. This setting applies to all check policies.

    • Add a check policy.

      You can add a standard policy to enhance baseline configuration checks for your assets, and a custom policy to check for risks in custom operating system configurations. Security Center uses these policies to check the baseline configurations of your assets.

      1. Click Create Standard Policy or Create Custom Policy.

      2. In the Baseline Check Policy panel, enter a Policy Name, select a Detection Cycle and Check Start Time, and then select the Baseline Category and Baseline Name that you want to check.

        For more information about baseline check items, see Baseline check content.

        Note

        Some custom baselines support parameter customization. Configure these parameters based on your business needs.

        Select the Scan Method (ECS or group) and configure the Effective Servers.

      3. Select the servers to which the policy applies, and then click OK.

        Parameter

        Description

        Scan Method

        Select the method for scanning the target servers. Valid values:

        • Group: Scans servers by server group. You can select one or more entire server groups.

        • ECS: Scans servers by ECS instance. You can select some or all servers from different server groups.

        Effective Server

        Select the servers to which you want to apply this policy.

        Note
        • By default, new assets are added to the All Groups > Ungrouped server group. To automatically apply this policy to new assets, select Ungrouped. If you want to add a new server group or modify an existing one, see Manage servers.

        • Each server group supports only one custom policy. If a server group already has a custom policy, it is dimmed and cannot be selected when you create a new custom policy.

      After configuring scan policies, you can click Edit or Delete in the Actions column to modify or delete a policy.

      Note

      Deleted policies cannot be restored.

      You cannot delete the Default Policy or modify its check items. You can only modify its Check Start Time and the selection of Effective Servers.

    Custom weak passwords

    In addition to its built-in rules, Security Center can use your custom rules to check for weak password risks on your assets.

    On the Custom Weak Password Rule tab, you can add or generate new custom weak password rules by using Upload File or Custom Dictionary.

    Important
    • The following limits apply to file uploads:

      • The file size cannot exceed 40 KB.

      • Each weak password in the file must be on a separate line to ensure accurate checks.

      • A file can contain a maximum of 3,000 weak passwords.

      • Uploading a file overwrites all existing custom weak password rules.

    • The custom dictionary tool supports two modes to generate custom weak password rules: Overwrite and Add.

    Generate custom weak password rules by uploading a file

    Security Center checks your assets for weak password risks based on the uploaded rules.

    1. On the Upload File tab, click Download Template and add your custom weak passwords to the template file.

    2. Click the Drag and Drop File to Upload area to upload the weak password template and complete the configuration.

    Overwrite or add custom weak password rules with a custom dictionary

    1. On the Custom Dictionary tab, click Generate (if you are creating a dictionary for the first time) or Regenerate.

    2. Configure the custom dictionary information, including the asset Domain Name, Company name:, and any Keyword that you want to add to the weak password dictionary.

    3. Click Generate Weak Password in Dictionary.

      In the Weak Password in Dictionary section, you can view all generated weak passwords. You can also manually add, edit, and delete weak passwords.

    4. Choose one of the following methods to complete the weak password dictionary configuration:

      • Click Add and then click OK to add the new dictionary to your existing weak password rules.

      • If you are regenerating a dictionary, click Overwrite and then click OK to overwrite all existing weak password rules.

    Baseline whitelist

    If a baseline check item poses no security risk to certain hosts, you can add it to a whitelist with the Baseline Whitelist feature, causing Security Center to ignore it on those hosts in subsequent checks.

    1. On the Whitelist Policy > By Host Baseline tab, click Create Rule.

    2. In the Create Baseline Whitelist Rule panel, select the Check Item Type and the specific Check Item to whitelist.

    3. For Rule Scope, select All Servers or Specific Servers.

    4. Click Save.

    5. (Optional) On the Baseline Whitelist tab, find the target rule in the rule list:

      • In the Actions column, click Edit to modify the Rule Scope, or add or remove whitelisted hosts.

      • In the Actions column, click Delete to delete the rule and resume baseline checks on the hosts.

Run baseline check policies

The baseline check feature of Security Center supports scheduled automatic checks and on-demand manual checks.

  • Scheduled automatic check: Security Center runs baseline checks according to the schedules defined in the default, standard, and custom policies you configure. The default policy runs a comprehensive, automatic check every two days between 00:00 and 06:00, or at the start time that you specify.

  • On-demand manual check: If you add or modify a check policy, you can go to the Baseline Check page, select the policy on the Baseline Check Policy tab, and immediately run a baseline check to view in real time whether your servers have the corresponding baseline risks.

To run an on-demand check, go to the Baseline Risk tab on the Risk Governance > CSPM page and follow these steps:

  • (Recommended) On the Risk Details tab:

    1. In the Check Item Statistics section, click Scan Now.

    2. In the Scan By Policy panel, find the desired policy and click Scan in the Actions column to start the baseline check.

    The panel table displays the Policy Name, Checked Servers, Baselines, Latest Pass Rate, and Actions columns. You can choose which policy to scan based on the pass rate of each policy.

  • On the Baseline Check Policy tab:

    1. Click the expand icon 三角, and select the desired check policy from the menu.

      The left side of the Baseline Check Policy tab lists the policies. Select a policy and click Check Now on the right side to start a manual check.

    2. On the right, in the Check Item Scan section, click Check Now.

      After you start the scan, the Check Now button is dimmed until the scan completes.

What to do next

After a baseline check is complete, go to the Baseline Risk > Risk Details tab to view failed check items and their details, and promptly fix risk items. For more information, see View and handle baseline risk items.