Administer > Audit and compliance > Compliance > Compliance statuses

Compliance statuses

In general, a server or group of servers can be Compliant or Non-Compliant. This information is displayed in the Compliance View.

Compliant : The Compliance view displays this icon when a server is in compliance with the policy attached to it. A server is considered Compliant if the rules defined in the policy match the actual configuration on the server that the policy is attached to.

Non-compliant : The Compliance view displays this icon when the server’s actual configuration does not match the rules configured in a policy. For example, you can configure an audit to make sure that a Windows Server 2003 server has the Windows CIS recommended minimum password length of at least 8 characters. When the audit runs and checks the server’s user password and discovers a user password that is only 4 characters, the Compliance view shows the server’s audit policy as Non-Compliant.

 

Do not confuse non-compliant rules with object differences. A non-compliant rule can show more than one object difference. SA counts non-compliant rules—it does not count object differences. For example, when a directory rule includes many files (objects) in that directory and the audit finds that some objects are different, SA counts this as one difference. SA does not count this as multiple differences. In the SA Client, the Compliance view and the summary view in the Audit Results browser display a count for non-compliant rules. These views do not show a count for object differences.

When more than one policy is attached to a server, the aggregation column combines (rolls up) the status of all policies. If this server belongs to a device group of multiple servers, you can access the Compliance view for the group to see compliance status levels for all audits that run on all servers in the group, including servers in any sub-groups. The method used for determining compliance statuses for groups is based on a default calculation. The group of servers is considered Compliant if at least 95% of the servers that belong to the group have a status of Compliant. If less than 95% of the servers have a status of Compliant, the status of the group is shown as Partial Compliant.

You can customize the default compliance status threshold for groups of servers. See Change device group compliance settings.

Tip It is possible that actual server configurations, including policy information, might have changed from the last time you viewed compliance for a server or group in the Compliance view. To get the latest compliance data from the SA core, select Refresh from the View menu or press F5. You can also run a compliance scan on the server or group to determine the latest compliance status.