Cloud Workload Rules page - Administrator Guide - Cortex CLOUD

Cortex Cloud Runtime Security Documentation

Product
Cortex Cloud Application Security > Cortex CLOUD
License
Cloud Runtime Security
Creation date
2024-12-24
Last date published
2026-06-04
Category
Administrator Guide

The Cloud Workload Rules page allows users to manage rules. Users can create, edit, filter, and manage rules.

Note

Keep the following caveats in my mind when working with Rules:

  • Instance Administrators are able to view all facets of Rules without restrictions, even if Scope Based Access Control (SBAC) roles are in effect. Learn more about SBAC.Manage user scope

  • If you’ve been assigned a custom role with View/Edit permissions limited by SBAC, you may not be able to view specific Rules.

  • You can further narrow your search in a Rules table by using SBAC to limit the scope of the finding, issues, and case counts.

The Widget section enables the users to get 'at-a-glance' based on Platform, Rule type and Scanner type.

The Cloud Workload Rules page displays both the default rules and user-configured rules, with the following fields.

Rule table columns

Column Name

Description

Rule ID

A unique identifier assigned to each rule.

Rule Name

The name of the rule, typically defined by the user or system.

Description

A brief summary of the rule's purpose and functionality.

Policies

Lists the policies in which the rule is included.

Controls

Compliance controls associated with the rule for regulatory adherence.

Platform

Specifies the platform or environment the rule applies to. For example: Linux, Windows or Kubernetes.

Scanner

The tool or method used to evaluate findings, such as Inventory Scanner, Agentless Disk Scan, Host Scanner, Kubernetes Connector or Kubernetes File System Scanner .

Severity

Defines the severity of the rule.

Data Type

The type of data the rule evaluates. For example: Hosts or Kubernetes Resources

Created By

The user who created the rule.

Last Modified

The date and time the rule was last updated.

Rule Type

Indicates whether the rule is a Built-in or Custom rule.

Remediation

Defines the remediation steps to address the detected misconfiguration.

Applicable assets

Supported applicable asset types.

Available actions

Indicates whether the available action is Prevent and Create an Issue or Create an Issue

Standards

Associated compliance standards or controls

Open issue

No. of open issue related to this rule.