Scan Control policy

Use the Scan Control policy on the SiteProtector Console to define the duration of scanning cycles and to assign user-defined perspectives to scans.

Background scanning is based on scanning cycles. Scanning cycles define how frequently you want to rerun scans for a group.

Note: Background scans run during open scan windows that you define in the Scan Window policy.

Important: This policy initiates background scanning, so you should configure it after you have configured the other policies required for background scanning.

Scope

The Scan Control policy applies to background discovery and background assessment scans. This policy does not affect ad hoc scans. Consequently, the behavior for ad hoc scans is different:

vAn ad hoc discovery scan runs only on the group where you define the scan.

vAn ad hoc assessment scan applies to the group where you define the scan and to all the subgroups. This is different from background scans in that background scanning behavior is determined by which Scan Control policy applies to each subgroup.

What is perspective?

When you scan a group of assets, you anticipate and interpret results based on the location of your scanner relative to the location of the assets. Scanning a group of assets from inside a firewall, for example, would produce different results from scanning that same group of assets from outside the firewall. With Enterprise Scanner, you use perspective to identify scanners by their location on the network, such as inside or outside the firewall, and then you configure scans based on the perspective from which you want to scan your assets. You define perspectives in the Network Locations policy.

Chapter 3. Enterprise Scanner policies 57

Page 65
Image 65
IBM Partner Pavilion 2.3 manual Scan Control policy, What is perspective?