Skip to main content

Overview

Policies provide a structured framework for assessing endpoint security, compliance, and operational risk across the organization. Each policy is composed of a collection of risk factors that evaluate specific security, privacy, operational, or compliance conditions on managed endpoints. Policies help organizations continuously monitor their environments, identify security gaps, prioritize remediation efforts, and measure adherence to internal requirements and industry best practices. Policy coverage may range from focused assessments, such as AI governance or endpoint geolocation , to broad security baselines and compliance frameworks such as SOC 2 .

How Policies Work

A policy consists of one or more risk factors that evaluate specific endpoint conditions or behaviors. Examples of risk factors include:
  • Disabled disk encryption
  • Missing operating system updates
  • Firewall misconfigurations
  • Suspicious authentication activity
  • High resource utilization
  • Unauthorized AI tool usage
  • Access from prohibited geographic locations
When a risk factor is detected, it contributes to the overall policy assessment and may affect the policy health score.

Controls

Each risk factor in the policy is associated with one or more controls. Controls provide a logical way to categorize and organize risk factors according to specific security, operational, privacy, or compliance objectives. A control can be assigned to multiple risk factors, and the same control may be used across multiple policies. Examples of controls include:
  • System Security
  • Network Security
  • Data Protection & Recovery
  • Behavioral & Performance Monitoring
Controls should be viewed as classification tags that help group related risk factors and explain the security objective that each risk factor supports.

Risk Factor Severity

Each risk factor has an assigned severity value that reflects its relative importance within the policy. Severity values range from:
  • 1.0 — Critical severity
  • 0.0 — Not defined
Higher severity values indicate that a risk factor has a greater impact on the overall health assessment and should generally be prioritized for remediation. The severity assigned to a risk factor is determined by its potential impact on security, compliance, privacy, operational stability, or business continuity.

Policy Assignment

Every endpoint must have at least one policy assigned.

Direct Assignment

Policies can be assigned directly to individual endpoints to evaluate specific security or compliance requirements.

Group-Based Assignment

Policies assigned to Endpoint Groups are automatically inherited by all endpoints that belong to those groups:
  • An endpoint may have multiple policies assigned simultaneously.
  • Policies inherited from Endpoint Groups are assigned automatically.
  • Group-assigned policies cannot be manually removed from individual endpoints while group membership remains active.
This approach ensures consistent policy enforcement across large numbers of endpoints and simplifies policy administration.

Health Score

A health score is calculated for each policy assigned to an endpoint. The health score reflects how well the endpoint complies with the requirements defined by the policy and is derived from the evaluation of all policy risk factors, taking their assigned severities into account. A higher health score generally indicates:
  • Fewer detected risks
  • Better security posture
  • Stronger compliance alignment
  • Reduced operational exposure
A lower Health Score indicates that one or more policy requirements are not being met and that remediation actions may be required.

Key Considerations

  • Policies provide a consistent and scalable way to measure security posture and compliance across the organization.
  • Assigning policies to Endpoint Groups helps ensure comprehensive coverage and reduces administrative effort.
  • Policy health scores help prioritize remediation efforts by highlighting the areas that have the greatest impact on risk.
  • The same risk factor or control may contribute to multiple policies, supporting different security and compliance objectives.
  • Regular policy reviews help maintain alignment with evolving security requirements, business needs, and regulatory expectations.

Policies page

Explore security and compliance policies, review their health and assigned endpoints.

Policy details

Analyze a policy’s implementation and impact by reviewing its risk factors, assigned endpoints, and endpoint groups.

Managing policies

Assign and unassign policies for endpoints and endpoint groups to control which risk factors are evaluated during endpoint health assessments.

How to assess and improve policy compliance

Review policy compliance across your environment, identify non-compliant endpoints and risk factors.