Configuring CloudGuard Exclusions

You can select to exclude specific findings that appear in the results of assessments or vulnerability scanning, manually triggered compliance assessments, and Continuous Posture assessments, including these CloudGuard solutions:

  • CSPM

  • CIEM

  • CDR

  • Image Assurance (Vulnerabilities)

  • Admission Control

With exclusions, you can control the findings and show only those applicable to you. After you create an exclusion, the findings that match the exclusion parameters do not appear in the calculation of the assessment result statistics. Excluded findings are not sent as notification messages (by email, SNS, etc.) to external systems.

Some typical cases to make exclusions are:

  • Exclude findings from unrelated rules, for specific or for all environments. For example, when you use preconfigured CloudGuard rulesets, possibly some rules do not apply to your environments, and you can create exclusions to adjust them.

  • Provide temporary correction for rules that require adjustments.

  • Stop generation of findings for specific entities.

Best Practice - Do not overuse exclusions. If it is necessary to have a large number of exclusions to control your assessment results, then perhaps make adjustments to your rulesets. As a result, the rulesets fit better the current state of your cloud environments.

In the Exclusions page, use the Filter and Search toolbar to select parameters to filter out from the exclusion table. Only exclusions that match the parameters show up in the exclusion table.

You can use these preconfigured filters:

  • Platform - Select an environment platform.

  • Environment/OU - Select one or more environments or organizational units.

  • Rulesets - Select from the available rulesets.

  • Rules - Select from the available rules.

  • Status - Select currently Active exclusions (in the Date Range) or Inactive exclusions (out of the Date Range).

  • Severity - Select from the available alert severity objects.

More Links