Users with the Senior security officer role can enable or disable one or several rules, as well as all rules at once.
To enable or disable the use of a TAA (IOA) rule when scanning events:
This opens the TAA (IOA) rule table.
The use of the rule when scanning events is enabled or disabled.
To enable or disable the use of all or multiple TAA (IOA) rules when scanning events:
This opens the TAA (IOA) rule table.
You can select all rules by selecting the check box in the line containing the headers of columns.
A control panel appears in the lower part of the window.
The use of the selected rules when scanning events is enabled or disabled.
These changes do not affect TAA (IOA) rules defined by Kaspersky. If you do not want to use a Kaspersky TAA (IOA) rule for scanning, add it to exclusions.
Users with the Security auditor and Security officer roles cannot enable or disable TAA (IOA) rules based on event search conditions.