Skip to main content
A custom hardening policy lets you tailor SCA benchmark checks to a specific environment, keeping only the rules that matter and applying them to the endpoints you choose. Creating one requires the Wazuh SCA preset store permission. Without it, the Create Custom Policy button is not visible.

The four steps

  1. General Information — name the policy and pick the base benchmark.
  2. Select Checks — choose which compliance rules to include from that benchmark’s catalogue.
  3. Select Endpoints — choose which endpoints to evaluate.
  4. Review — confirm your selections and save.

Create a policy

  1. On Hardening Assessments (/compliance/hardening), click Create Custom Policy.
  2. On Step 1, enter a policy Name and select a base benchmark from the Policy combobox, then click Next. Step 1 of the wizard showing inline validation errors on the empty name and policy fields
  3. On Step 2, select the compliance checks to include. Click any check title to preview its full detail before deciding. Step 2 with compliance checks selected from the benchmark catalogue
  4. Click Next. If nothing is selected, a toast blocks you. Step 2 showing the toast error returned when no checks are selected
  5. On Step 3, select the target endpoints. The table shows Name, IP, and a connection status badge for each. Step 3 with target endpoints selected for evaluation Step 3 showing the error returned when no endpoints are selected
  6. On Step 4, expand the Selected Checks (N) and Selected Endpoints (N) accordions to confirm everything, then click Finish. Step 4 review with the selected checks and endpoints accordions expanded

Validation and behavior

Two behaviors are worth knowing before you start: Changing the base policy resets your work. Selecting a different base policy on step 1 clears every check and endpoint selection you made in later steps. Settle on the base benchmark first. Endpoints must have been scanned. If no base policies exist, or no endpoint has completed an SCA scan, the dropdown reads No policies found. Endpoints must complete a scan first.