Kaspersky Container Security

Scanner policy

Scanner policy determines the settings for scanning different types of resources.

The configured scanner policies are displayed as a table in the PoliciesScanner policy section.

You can use the list to do the following:

  • Change policy settings. You can open the editing window by clicking the policy name link.

    You can also enable and disable policies in the edit window. Kaspersky Container Security does not use disabled policies when operating.

  • Delete policies.

The release 1.0 distribution kit includes the default scanner policy. You can change the settings of this policy, but you cannot delete it. Scanner policy customization is not available.

Page top

[Topic 250397]

Editing scanner policy settings

To change scanner policy settings:

  1. In the Policies → Scanner policies section, click the policy name link.

    The policy settings editing window opens.

  2. If required, use the Disable / Enable toggle switch to change the policy status (enabled / disabled).
  3. Make changes to the policy settings. The following settings are open for editing:
    • The policy's name, description, and scope.
    • Vulnerability control settings. Select the check boxes for the vulnerabilities database(s) to check images against.
    • Malware control settings. Select the check box if you need to scan images for malware and other file threats. This control is conducted by using the File Threat Protection component.
    • Misconfiguration control settings. Select the check box if you need to check images for misconfigurations. The control is conducted with the default settings configured by the Kaspersky Container Security manufacturer.
  4. Click Save.

Page top

[Topic 255392]

Configuration of sensitive data detection rules

The list of configured rules for detecting sensitive data (hereinafter referred to as Secrets) during image scanning is displayed in the Policies → Scanner policiesSensitive data section.

The rules are grouped into categories depending on the purpose and scope of secrets to be detected. The list of categories is determined by the Kaspersky Container Security manufacturer. Categories contain predefined rules.

You can use the list to do the following:

  • View and change the settings for secrets detection rules. You can open the editing window by clicking the rule ID link.
  • Add new rules to the selected category. Click the Add rule button located above the table to open the integration settings window. To add rules that do not belong to any of the preset categories, use the Other category.
  • Delete rules. Check the box next to one or more rules in the list. The delete icon is then displayed.

To change the settings of sensitive data detection rules:

  1. In the table, in the PoliciesScanner policiesPolicies section, select the scanner policy.
  2. In the Sensitive data section, select the necessary rules by selecting the check boxes in the rule lines.
  3. Use the Disable / Enable toggle switch in the Status column in the table with the list of policy rules to enable or disable this policy component.

    Do not click the Save button.

    Kaspersky Container Security immediately applies the changes to the sensitive data settings and displays the corresponding notification. You can also refresh the page to see the settings change.

Page top
[Topic 250398]