Kaspersky Endpoint Agent

Creating the Security Audit task with the default settings

November 17, 2023

ID 231889

The task can be run only if you have an active Kaspersky Industrial CyberSecurity for Node license key with an ICS Audit licensed object.

To create and configure a Standard Security Audit task:

  1. In the main Kaspersky Security Center Web Console window select DevicesTasks.
  2. Click the Add button.

    The task creation wizard will start.

  3. In the Application drop-down list, select Kaspersky Endpoint Agent.
  4. In the Task type drop-down list, select Security audit.
  5. Enter a task name or leave the default name.
  6. Select devices to which the task will be assigned.
  7. Click Next.
  8. On the Source of rules tab, Custom rule base from file is selected by default.
  9. Click the Import rule base from file.
  10. In the window that opens, specify the file with the rule database.

    You can load only one archive containing an XML file with OVAL rules and XCCDF rules.

    The total archive size must not exceed 2 MB.

  11. Click OK.

    The Source of rules section displays information about the loaded rules. Follow the Details links in the Platforms and Products fields to open windows with lists of the operating systems and products mentioned in the rules of the selected source.

  12. If necessary, load the file with external variables:

    You cannot use external variables if the selected rule source contains XCCDF rules.

    1. Select the Use external variables data with custom database check box.
    2. Click the Import external variables from file.
    3. In the window that opens, specify the path to the file with the external variables.
    4. Click OK.
  13. In the Scope section, if necessary, change the vulnerability scan mode:

    The Scope section is unavailable if the selected rule source contains XCCDF rules.

    1. Select one of the modes:
      • Scan all vulnerabilities.

        Kaspersky Endpoint Agent scans the devices to which the task is assigned in order to detect all vulnerabilities described in the rules of the Kaspersky ICS CERT vulnerabilities database for SCADA.

      • Scan all vulnerabilities except added to the list.

        Kaspersky Endpoint Agent scans the devices to which the task is assigned in order to detect all vulnerabilities described in the rules of the Kaspersky ICS CERT vulnerabilities database for SCADA except for those added to the list below.

      • Scan vulnerabilities added to the list.

        Kaspersky Endpoint Agent scans the devices to which the task is assigned in order to detect vulnerabilities added to the list below.

    2. If you selected Scan all vulnerabilities except added to the list or Scan vulnerabilities added to the list, create a list of vulnerabilities using the Add or Add according to conditions.
  14. In the Advanced section, if necessary, determine the statuses of directive-based scans that will be included in the security audit task report:

    Directives cannot be applied if the selected rule source contains XCCDF rules.

    1. Select the Use Directives check box.
    2. Using the switch next to each directive, determine the statuses of directive-based scans that will be displayed in the security audit task report.

      If the switch next to a directive status is on, results of scans based on the directive's rules that have this status will be displayed in the security audit task report.

      By default, the check boxes next to the True and False scan result are selected for all directives.

  15. In the Advanced section, if necessary, configure settings for logging task completion events:
    1. Select the Enable logging check box.
    2. Select the desired Logging level from the list.
  16. Click Next.
  17. In the Selecting an account to run the task window that opens, do one of the following:
    • Select the default account.
    • Enter the name and password of the user whose account permissions will be used to start the task.
  18. Click Next.
  19. In the Finish task creation window, click the Finish button.

    The task with the default settings will be created and displayed in the list of tasks. You can change the task settings later.

You can start the created task manually or configure a scheduled task start.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.