Security Center Plan

Trend Cloud One™ – Conformity is a continuous assurance tool that provides peace of mind for your cloud infrastructure, delivering over 1000 automated best practice checks.

Risk Level: Medium (should be achieved)
Rule ID: AlibabaCloud-SecurityCenter-004

Ensure that the Security Center plan configured for your Alibaba Cloud account is Advanced or Enterprise Edition. The Advanced or Enterprise Edition plan enables threat detection on both network and endpoints, offering advanced security capabilities such as identifying malware, detecting webshells, and recognizing anomalies within the Security Center.

Security

The Advanced or Enterprise Edition plan in Security Center ensures robust security measures and proactive defense against potential cyber threats, strengthening the overall security posture within your Alibaba Cloud account.


Audit

To determine if your current Security Center plan is set to Advanced or Enterprise Edition, perform the following operations:

Using Alibaba Cloud Console

01 Sign in to your Alibaba Cloud account.

02 Navigate to Security Center console available at https://yundun.console.aliyun.com/?p=sas#/overview/home.

03 In the top navigation bar, select the region where your resources are located (China or Outside China).

04 In the left navigation panel, under Security Center, choose Overview.

05 Check the name of the curent Security Center plan, displayed in the Welcome Security Center section. If the plan name is different than Advanced or Enterprise Edition, your current Security Center plan is not Advanced or Enterprise Edition.

Using Alibaba Cloud CLI

01 Run DescribeVersionConfig command (OSX/Linux/UNIX) to determine the name of the active Security Center plan configured for your Alibaba Cloud account:

aliyun sas DescribeVersionConfig

02 The command output should return the configuration information available for the active Security Center plan:

{
	"IsPaidUser": false,
	"IsSasOpening": true,
	"IsTrialVersion": 0,
	"RequestId": "ABCDABCD-1234-ABCD-1234-ABCD1234ABCD",
	"Version": 1
}

The "Version" attribute value represents the Security Center plan purchased for your Alibaba Cloud account. 1 is for Basic Edition, 3 for Enterprise Edition, 5 for Advanced Edition, 6 for Anti-virus Edition, 7 for Ultimate Edition, 8 for Multi-Version Edition, and 10 for Value-added Plan Edition. For compliance, "Version" must be 3 (Enterprise Edition) or 5 (Advanced Edition). If the "Version" attribute value is not set to 3 or 5, your current Security Center plan is not Advanced or Enterprise Edition.

Remediation / Resolution

To ensure that your Security Center plan is set to Advanced or Enterprise Edition, perform the following operations:

Upgrade or downgrade Security Center plans via Alibaba Cloud CLI (aliyun) is not currently supported.

Using Alibaba Cloud Console

01 Sign in to your Alibaba Cloud account.

02 Navigate to Security Center console available at https://yundun.console.aliyun.com/?p=sas#/overview/home.

03 In the top navigation bar, select the region where your resources are located (China or Outside China).

04 In the left navigation panel, under Security Center, choose Overview.

05 In the Welcome Security Center section, choose Immediate purchase to view the Security Center plans.

06 On the Select a product version panel, select the Basic Services tab, and choose Buy Advanced or Buy Enterprise to upgrade your Security Center plan to Advanced or Enterprise Edition.

07 On the selected plan page you can configure quotas, advanced features, or auto-renewal settings. Once all the necessary settings are configured, select Buy Now, agree to terms and conditions, and choose Pay to finish the payment and upgrade your Security Center plan to Advanced or Enterprise Edition.

References

Publication date Feb 27, 2024