Home > Use Insights for AWS (Preview) > Risk Definition Administration
Download this articleThe risk definition settings have already been configured when the first tenant user logs into Insights and completes the initial configurations. You can make updates to your risk definition settings as required by clicking Settings > Risk definition. The following tiles can be viewed on the Risk definition page.
Risk Definition Profiles
Scope and Binding
On the Risk definition profiles page, existing profiles are listed in the table, including the built-in Default profile for AWS. You can search for a specific profile by entering the profile name in the search box and pressing Enter on the keyboard.
On this page, the following actions are available to manage profiles.
New profile – Click New profile on the Risk definition profiles page, and the New profile page will appear.
In the Profile information step, enter a name and optional description for the profile, and click Next to go to the next step.
In the Exposure definitions step, configure the exposure definitions that you want to use in the profile. For detailed information, refer to Exposure Definitions.
Click Next to go to the next step.
In the Review step, review your settings and click Save to save the risk definition profile. You can also click Back to go back to the previous step or click Cancel to discard changes.
View – Click View above the table or click View from the ellipsis drop-down list to the right of a profile. The profile details are displayed in the View window on the right.
Edit – Click Edit above the table or click Edit from the ellipsis drop-down list to the right of a profile. The Edit profile page appears, where you can edit the profile information.
Duplicate – Click Duplicate above the table or click Duplicate from the ellipsis drop-down list to the right of a profile. The New profile page appears with the settings of the profile. The new profile name is suffixed with – Copy.
Delete – Select one or multiple profiles that you want to delete and click the Delete button above the table.
Default profile cannot be deleted.
After your desired risk definition profiles created, you can now apply the profiles to data scopes based on your requirements. You can click the Scope and binding link on the right pane to access the Scope and Binding page directly.
You can view the High exposure level, Medium exposure level, and Low exposure level sections on this page.
For the High and Medium exposure levels, you can view the default settings in each section.
Click Edit in the upper-right corner of the section to edit settings for the corresponding exposure level.
When an object matches any of the enabled conditions of the High or Medium exposure level, the object will be classified as the corresponding exposure level. If an object does not match the High or Medium exposure level conditions, it will be automatically classified as the Low exposure level.
Choose to use one or more conditions below by selecting the corresponding checkboxes and configuring settings.
Select Shared with external principals, select one of the following options from The number of external users is drop-down list, and configure the threshold number or number range.
More than – An object that is shared with external users and the number of external users is more than the threshold number will be classified as the corresponding exposure level.
From…to – An object that is shared with external users and the number of external users is within the configured number range will be classified as the corresponding exposure level.
Less than – An object that is shared with external users and the number of external users is less than the threshold number will be classified as the corresponding exposure level.
Shared with all internal users – An object that is shared with all internal users will be classified as the corresponding exposure level.
Select Shared with multiple principals, select one of the following options from The number of principals is drop-down list, and configure the threshold number or number range.
More than – An object that is shared with multiple principals and the number of principals is more than the threshold number will be classified as the corresponding exposure level.
From…to – An object that is shared with multiple principals and the number of principals is within the configured number range will be classified as the corresponding exposure level.
Less than – An object that is shared with multiple principals and the number of principals is less than the threshold number will be classified as the corresponding exposure level.
After configuring settings for the exposure level, click Save to save the settings. You can also click Cancel to discard your edits.
On the Scope and binding page, containers are listed. You can view the AWS account ID and the applied risk definition profile.
Select one or multiple accounts and click Assign profile, and the Assign profile window appears on the right pane. Select a profile for the accounts and click Save to assign the selected risk definition profile to the accounts. The profile name will be displayed as the Risk definition profile column values for the accounts.
If you remove profiles from accounts, these accounts will no longer be scanned. It may take some time to rescan these accounts when they are assigned with profiles again.