
VMware, Inc. 89
8
vShieldDataSecurityprovidesvisibilityintosensitivedatastoredwithinyourorganization’svirtualizedand
cloudenvironments.BasedontheviolationsreportedbyvShieldDataSecurity,youcanensurethatsensitive
dataisadequatelyprotectedandassesscompliancewithregulationsaroundtheworld.
Thischapterincludesthefollowingtopics:
“vShieldDataSecurityUserRoles”onpage 89
“DefiningaDataSecurityPolicy”onpage 90
“SavingandPublishingPolicies”onpage 95
“DataSecurityScanning”onpage 96
“QueryingScanResults”onpage 97
“QueryingViolationDetails”onpage 101
TobeginusingvShieldDataSecurity,youcreateapolicythatdefinestheregulationsthatapplytodatasecurity
inyourorganizationandspecifiestheareasofyourenvironmentandfilestobescanned.Whenyoustarta
DataSecurityscan,vShieldanalyzesthedataon
thevirtualmachinesinyourvSphereinventoryandreports
thenumberofviolationsdetectedandthefilesthatviolatedyourpolicy.
Afteryouanalyzetheresultsofthescan,youcanedityourpolicyasrequired.Whenyoueditapolicy,you
mustenableitbypublishingthechanges.
Notethatyou
cannotinstallvShieldDataSecurityusingaRESTAPI.ForinformationoninstallingvShield
DataSecurity,seethevShieldQuickStartGuide.
TodeployvShieldDataSecurity,youmustinstallthelatestversionofVMwareToolsoneachvirtualmachine
thatyouwanttoscan.ThisinstallsaThinAgent,
whichallowstheSVMtoscanthevirtualmachines.
vShield Data Security User Roles
Auser’sroledeterminestheactionsthattheusercanperform.Ausercanonlyhaveonerole.Youcannotadd
aroletoauser,orremoveanassignedrolefromauser,butyoucanchangetheassignedroleforauser.
vShield Data Security Configuration
8
Table 8-1. vShield Data Security User Roles
Role Actions Allowed
Enterpriseadministrator AllvShieldoperationsandsecurity.
vShieldadministrator vShieldoperationsonly:forexample,installvirtualappliances,andconfigureportgroups.
Securityadministrator Createandpublishpolicies,viewviolationreports.Cannotstartorstopdatasecurityscans.
Auditor Viewconfiguredpoliciesandviolationreports.Read‐only.
Comentários a estes Manuais