Customizing Benchmarks and Disabling Rules in Security Posture Management
search cancel

Customizing Benchmarks and Disabling Rules in Security Posture Management

book

Article ID: 447156

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

When customizing compliance benchmarks (such as the 'PCI DSS v4.0.1 for VCF 9 v1.0' benchmark) in the Security Posture Management section, administrators frequently ask if it is possible to completely disable specific, individual rules from a benchmark.

Environment

VCF Operations 9.1.x

Cause

This is the expected behavior. The framework is designed to strictly enforce the desired settings dictated by the benchmark standard to maintain compliance integrity.

Resolution

Currently, selective or partial rule disablement is not supported. You cannot toggle off a single, specific rule within a benchmark.
By design, most rules within a benchmark are not fully configurable because they enforce a strict compliance standard. However, you can provide site-specific values for certain variable-based rules, such as:
While you cannot disable individual rules, you can exclude an entire component type (e.g., all NSX components) from being evaluated by a benchmark.
To achieve this:
  1. Create a Custom Group that isolates the specific component types you want to exclude.
  2. Create and Apply a Policy to that custom group that excludes those components from the compliance benchmark evaluation.