Input variant of Rule carrying its writable fields. The id field must be omitted for policyRulesAdd and is required for policyRulesEdit.
Fields
| Input Field | Description |
|---|---|
id - ID
|
The unique identifier for the rule. |
group - String!
|
The group this rule belongs to. |
applyTo - GraphObjectType!
|
Defines what object types this rule should be applied to. |
applyToOptions - [RuleApplyToOptionInput!]
|
Optional key/operator/value constraints that further scope which objects this rule applies to. Omit to apply the rule to every object of its applyTo type. CONFIGURATION rules accept any option their applyTo type can resolve; FILE, PROPRIETARY, SEARCH, THRESHOLD, and VULNERABILITY rules accept only a single OS option with the EQUALS operator. |
osNeutral - Boolean
|
True when the rule's check and remediation hold on every OS, such as a full disk or an outdated agent. An OS-neutral rule can't carry an OS option, and its CLI remediation can't fill in values from the evaluated object. Separately, any rule whose CLI fills in values must name exactly one OS with an OS option, except a FILE rule, whose path glob decides the shell. Defaults to false. |
name - String!
|
The name of the rule. |
discoveryName - String!
|
The name given to the Finding (and paired Issue) objects this rule generates. |
description - String!
|
The description of the rule. |
notes - String
|
Optional free-text notes about the rule. |
enabled - Boolean!
|
Is the rule enabled. |
severity - Severity!
|
The severity of the Finding objects, and the paired Issue, generated by the rule. |
body - RuleBodyInput!
|
The body for this rule's type. The variant set determines the rule's RuleType. An edit can't change a rule to or from VULNERABILITY; add a new rule instead. |
schedule - ScheduleInput
|
When to evaluate this rule. Defaults to NONE, the only schedule a CONFIGURATION rule accepts. FILE, PROPRIETARY, SEARCH, THRESHOLD, and VULNERABILITY rules run on their schedule and need a CRONTAB Schedule; they reject NONE. Default = {type: NONE} |
mockOptions - [MockDataInputOption!]
|
Options used to generate mock data for testing the rule. |
lastMockDataInput - String
|
JSON-encoded test cases for the rule's function: an array of {name, input, expect} where expect is "PASS" or "FAIL". |
remediationInstructions - RemediationInstructionsInput!
|
How to remediate findings from this rule. See RemediationInstructionsInput. |
securityFrameworks - [SecurityFrameworkReferenceInput!]
|
The security frameworks this rule helps satisfy, each with the products it is assessed under and the sections within them it is filed under. See SecurityFrameworkReferenceInput. |
risks - [SecurityRisk!]
|
List of applicable security risks this rule is related to. |
tactics - [SecurityTactic!]
|
List of applicable security tactics this rule is related to. |
Used by
Ruletype: A policy rule evaluated against graph objects.RulesAddInputinput: Input for the policyRulesAdd mutation.RulesEditInputinput: Input for the policyRulesEdit mutation.
Related types
Example
Example
{
"id": "4",
"group": "xyz789",
"applyTo": "ACCOUNT_POLICY",
"applyToOptions": [RuleApplyToOptionInput],
"osNeutral": true,
"name": "abc123",
"discoveryName": "abc123",
"description": "abc123",
"notes": "abc123",
"enabled": true,
"severity": "INFORMATIONAL",
"body": RuleBodyInput,
"schedule": ScheduleInput,
"mockOptions": [MockDataInputOption],
"lastMockDataInput": "abc123",
"remediationInstructions": RemediationInstructionsInput,
"securityFrameworks": [SecurityFrameworkReferenceInput],
"risks": ["VULNERABILITY"],
"tactics": ["RECONNAISSANCE"]
}