Download Symantec Enterprise Security Manager 6.0 for PC, Unix

Transcript
242 Using the Symantec ESM utilities
Using the Policy tool
■
Directory permissions
To export a policy, obtain access to an account on the host computer with
the Write permission enabled for the destination directory. By default, the
Policy tool exports policies to the current directory.
■
Exported policies
Before you export a policy, verify that at least one agent of each operating
system type that is registered to the manager has installed the latest
security update. This ensures that the exported policy contains current
security checks, templates, and word lists. Then verify that all of the
security checks in each module of the policy are set to match your
company’s security policy. Also, verify that all of the templates and word
lists that are required by the policy are enabled.
■
Imported policies
Before you import a policy, verify that the latest security update has been
installed on the agents that are registered to the importing manager. This
ensures that the agents can run all of the enabled security checks in the
policy.
Access
Use the following procedure to access the Policy tool.
To access the Policy tool
◆
Do one of the following:
■
Windows:
At the command prompt, change to the directory that contains the
Policy tool. The tool installs in the C:\Program Files\Symantec\ESM
Utilities directory by default.
■
UNIX:
At the command prompt, change to the directory that contains the
Policy tool. The Policy tool installs in the esm/bin directory by default.
Format
Apply these formatting rules when entering a Policy tool command:
■
Capitalize policy names to match the case of the corresponding values that
are stored on a manager.
■
Type policytool as one word.
■
Type Policy tool options last in the command.