7.4 Using the Secure Configuration Manager Dashboard for Evaluation

The Secure Configuration Manager Dashboard provides a web-based interface for executives and managers to view both the overall compliance of their IT assets and to perform a more granular assessment of specific managed groups and computers. This high-level overview of your environment’s compliance allows you to see the overall posture and trends of security compliance at a single glance. The Dashboard displays compliance data based on the Secure Configuration Manager managed groups and scoring types you want each user role to see.

The Dashboard has a few default dashboards, consisting of charts that display compliance data. You can create your own dashboards, and save them. The data that you will see in the charts will depend on the access rights of your user role.

The Dashboard organizes the views into four logical groups, displayed in the following four dashboards:

  • Secure Configuration Manager

  • Risk Compliance

  • System Compliance

  • Technical Compliance

Click the Load Saved Dashboard icon on the menu bar to navigate to any of these dashboards.

7.4.1 Accessing the Dashboard

All console users can log in to the Dashboard. However, the data that users can view depends on the privileges their role has been assigned by the Secure Configuration Manager administrator. For more information about Secure Configuration Manager users and roles, see Setting up the Dashboard for Your Users.

If your role has been configured with a session limit value, it will be applicable for your Dashboard session too. For more information about session limit, see Assigning Session Limit to Roles.

If your user account is deleted by the Secure Configuration Manager administrator while you are using the Dashboard, your session will be terminated whenever the session is revalidated. For more information about session revalidation interval, see the Validate User in Every field in Working with General Dashboard Settings.

You can launch the Dashboard in one of the following ways:

Web console

If the Web console and the Dashboard are installed in the same domain, click Dashboard in the Web console. You do not need to enter your credentials.

To enable single sign-on from the Web console, see Launching the Dashboard from the Web Console.

Start menu

Use the Dashboard shortcut in the StartSecure Configuration Manager menu of your computer where and the Dashboard are installed.

  1. Go to Start > Secure Configuration Manager Dashboard.

  2. Secure Configuration ManagerSpecify your user name and password.

  3. Click Log In.

For quick and easy access, add the Dashboard URL to the Favorites tab of your browser. For more information about supported browsers, see the Secure Configuration Manager Installation Guide.

7.4.2 Viewing the Secure Configuration Manager Dashboard

The Secure Configuration Manager Dashboard is the default view displayed when you log in to the Dashboard. This dashboard is used to visualize the results of template runs over various endpoints/managed groups. This dashboard provides an overview of the compliance, risk status, and distribution of assets, endpoints, and groups added or created in Secure Configuration Manager.

Following are the charts in the Secure Configuration Manager Dashboard:

Chart Name

Description

Compliance Distribution

This is a pie chart that displays the distribution of the compliance information of the latest runs of templates over the network.

The size of each slice indicates the number of template runs on the endpoints of the network, which ended with corresponding compliance level. Only unique template runs are considered for this chart; multiple runs of same templates are not considered. For example, if you run four different templates, the chart will have four slices. If you run two templates twice, the chart will have two slices.

Group Hierarchy

This is a multi-level pie chart created to visualize the hierarchy and size of the groups on which templates have been run.

The size of each slice will be reflective of the number of endpoints that are part of the corresponding group.

Policy Template Risk Over Time

This is a trend chart that displays the trend of the sum of total risk of each run of a particular template.

By default, the chart follows an interval of one day. The 10 templates with highest sum of total risk are shown in the chart.

ALL templates run (including multiple runs of same templates) are considered for this chart.

Platform Distribution

This is a pie chart that displays the distribution of the network based on the platform of endpoints.

The size of each slice reflects the number of endpoints of corresponding platform.

Endpoint Distribution

This is a pie chart that displays the distribution of the network in terms of the endpoints.

Each slice represents one endpoint.

Policy Template Distribution

This is a pie chart that displays the templates that have been run over the network.

Each slice represents one template.

Check Status Distribution

This is a pie chart that displays the collective status of the execution of the security checks that have been run over the network.

Each slice represents a status such as “Passed”, “Failed”, and “Unknown”.

Group Compliance Detail

This is a bar graph that displays the distribution of compliance levels of the latest runs of the templates run over the groups. The groups are ordered in descending order according to the number of templates run on them.

Asset Compliance Detail

This is a bar graph that displays the distribution of compliance levels of the latest runs of the templates run over the assets. The assets are ordered in a descending order according to the number of templates run over them.

Check Status Detail

This is a bar graph that displays the status of the execution of various security checks. The security checks will be visible in this graph only if they were executed as a part of a template run. The status of a security check can be “Passed”, “Failed”, “Excepted”, or “Unknown”. The security checks are ordered in the descending order of the number of times they have been run.

Risk Score Detail

This is a bar graph that displays the risk distribution of the latest runs of templates on respective endpoints. The size of each bar area indicates the number of template runs having that risk level. The endpoints are ordered in descending order based on the number of templates run on them.

Geolocation of Out of Compliance Endpoints

This is a world map (tile map) that shows the location of endpoints that have template runs which were out of compliance.

NOTE:You must have internet connection in your computer to be able to view this chart.

7.4.3 Viewing the Risk Compliance Dashboard

The Risk Compliance Dashboard is used to visualize the important risk related information of your network. When a template is run on any endpoint, it can result in “Low Risk”, “Medium Risk”, “High Risk”, or “Unknown Risk”.

Following are the charts in the Risk Compliance Dashboard:

Chart Name

Description

Overall Risk Status

This is a pie chart that displays the distribution of the risk levels of all the latest runs of templates over the network.

The size of each slice indicates the number of template runs having that risk level. Only unique template runs are considered for this chart; multiple runs of same templates are not considered. For example, if you run four different templates, the chart will have four slices. If you run two templates twice, the chart will have two slices.

Overall Risk Status Over Time

This is a bar chart that displays the risk distribution of templates over the network on specific dates.

The size of each slice of the bar indicates the number of templates having corresponding risk level.

ALL templates run (including multiple runs of same templates) are considered for this chart.

Risk Score Detail

This is a bar graph which displays the risk distribution of the latest runs of templates on respective endpoints. The size of each bar area indicates the number of template runs having that risk level. The endpoints are ordered in descending order of the number of template runs on them.

Low Risk Score Over Time

This is a trend chart which displays the number of template runs which have resulted in low risk at a given point of time.

7.4.4 Viewing the System Compliance Dashboard

The System Compliance Dashboard is used to visualize the important compliance related information of your network. When a template is run over any endpoint, it can result in “In Compliance”, “Out of Compliance”, or “Unknown Compliance”.

Following are the charts in the System Compliance Dashboard:

Chart Name

Description

Overall Compliance Status

This is a pie chart that displays the compliance distribution of all the latest runs of templates over the network.

The size of each slice indicates the number of template runs having corresponding compliance level. Only unique template runs are considered for this chart; multiple runs of same templates are not considered. For example, if you run four different templates, the chart will have four slices. If you run two templates twice, the chart will have two slices.

Overall Compliance Status Over Time

This is a bar chart that displays the risk distribution of templates over the network on specific dates.

The size of each slice of the bar indicates the number of templates having corresponding compliance level.

ALL templates run (including multiple runs of same templates) are considered for this chart.

System Compliance Detail

This is a bar chart which displays the compliance distribution of the latest runs of templates on respective endpoints.

The size of each bar area indicates the number of template runs having that compliance level.

Passed Compliance Over Time

This is a trend chart that displays the number of templates that are in compliance at a given point of time.

7.4.5 Viewing the Technical Compliance Dashboard

The Technical Compliance Dashboard is used to visualize the check level information of the network. When the check is run on an endpoint it can either result in “Passed”, “Failed”, or “Excepted”.

Following are the charts in the Technical Compliance Dashboard:

Chart Name

Description

Overall Compliance Status

This is a pie chart that displays the distribution of all the check runs on the endpoints based on their returned status.

The size of each slice of the chart indicates the number of checks that returned with that status. Only unique template runs are considered for this chart; multiple runs of same templates are not considered. For example, if you run four different templates, the chart will have four slices. If you run two templates twice, the chart will have two slices.

Overall Compliance Status Over Time

This is a bar chart which displays the risk distribution of templates over the network on the particular dates.

The size of each slice of the bar indicates the number of checks having corresponding compliance level.

ALL templates run (including multiple runs of same templates) are considered for this chart.

Compliance Detail

This is a bar chart that displays the distribution of the check results for all the checks that have been run on a particular endpoint.

The size of each area of bar indicates the number of checks run on that endpoint, which returned in corresponding status. The endpoints are ordered in descending order of the number of checks that have run on them.

Passed Compliance Over Time

This is a trend chart that displays the number of passed or excepted checks over time.

The trend is shown for each template that has such checks.

7.4.6 Customizing the Dashboard

You can perform the following tasks using the options in the menu bar, to customize the Dashboard:

Creating New Dashboard

If you need your own, customized dashboard apart from the four dashboards provided, click the New Dashboard icon to create it. When you click this icon, an empty dashboard is displayed. In this dashboard, you can add the charts based on your requirement.

Adding Charts to Existing Dashboard

You can add charts to your dashboard by clicking the Add Visualization icon.

Saving the Dashboard

If you have created you own dashboard, you can save it by clicking the Save Dashboard icon, and providing a name of your dashboard.

Select Store time with dashboard while saving the dashboard to change the time filter for the dashboard to the currently applied time filter.

Loading Saved Dashboard

You can load any default or saved dashboard by clicking the Load Saved Dashboard icon and selecting the dashboard you want to load.

Changing the Dashboard Theme

You can update the dashboard to use the dark theme by clicking the Options icon and then selecting the Use dark theme option.

NOTE:The Secure Configuration Manager Dashboard leverages Kibana, a browser-based analytics and search dashboard, that helps you to visualize and analyze data. Apart from the customizing functionality that the Dashboard offers, you can also use the Kibana functionality to customize the Dashboard. For more information, see the Kibana documentation.

7.4.7 Screen Capturing and Report Sharing

The Dashboard offers reporting capabilities, which enables you to take a screenshot of your dashboard and export it in multiple formats. NetIQ recommends FireShot as the screen-capturing and sharing tool. When you download FireShot and install it on your computer, you will see the FireShot icon in your browser bar. Click on that icon to start using FireShot for screen capturing and sharing tasks.

With FireShot, you can perform the following reporting tasks:

  • Capture screenshot: You can capture entire dashboard screen, or a selected screen area.

  • Save screenshots as image or PDF: You can save the captured screenshot in various formats: image (.jpg or .png) or as PDF.

  • Print screenshot: You can directly print the screenshot, or copy it to a clipboard.

You can send the saved screenshot file (image or pdf) though email, and use it for any other report sharing purpose.

NOTE:You can also use any other screenshot capturing tool to achieve screen-capturing and reporting with the Dashboard.