This guide shows you how to modify checks within industry benchmarks by either disabling individual checks or by modifying values in parameter-based checks.
Where can I find Benchmarks?
Navigating to Control > Policies will display a list of all custom policies you have created in your account and all public benchmarks. To view only benchmarks, click the “Public” filter in the left panel.
By clicking on the name of a benchmark you can view the Description, Background and Remediation of the original benchmark document.
Since benchmark customization can be done per node group, you must first assign the benchmark to a node group to start editing and disabling checks.
Adding a Benchmark to a Node Group
You can assign a benchmark to a node group either from the benchmarks list page via the Add to Node Group action, or from the benchmark details page via the Add Node Group button in the Node Groups section of the left panel.
Disabling a Benchmark Check
Once a benchmark has been assigned to a node group, you can start customizing. Locate the benchmark you want to edit in the Benchmarks list under Control > Policies. Then click into the benchmark to see the list of checks defined in the benchmark. You can click on the description of a particular check to bring up the details panel on the right. At the bottom of the panel is a list of node groups this benchmark is assigned to under Involved Node Groups. You can configure whether this check is run by toggling the checkbox next to the associated node group.
The example below shows the togglable checkbox for enabling or disabling the 1.1.1 check of this particular benchmark on all nodes in the Windows Production Nodes node group.
Modifying a Benchmark Parameter
You can also modify a parameter within a particular benchmark check on a per node group basis. Checks that have a modifiable parameter will be listed with a button labelled Modify N value(s).
Clicking this button will display the value or values able to be modified. You can then click on a parameter’s title or value to bring up the parameter’s settings against each assigned node group in the right panel. If a value has not been modified it will display “Default”, otherwise you can click on the corresponding value to modify it.
Once you have customized Benchmarks to meet your needs, you can schedule benchmarks to be excuted against a set of nodes in your environment. For more information around scheduling benchmark reports, please view our guide on How to Schedule Benchmark Reports.