建立一個 IBM Cloud® Security and Compliance Center Workload Protection 實例
若要善用 IBM Cloud® Security and Compliance Center Workload Protection 所提供的功能,必須具備 Workload Protection 實例。 本教學將說明如何建立一個。
開始之前
管理使用者存取權
對於存取您帳戶中 IBM Cloud Security and Compliance Center Workload Protection 服務的每個使用者,必須向其指派定義了 IAM 使用者角色的存取原則。 此政策決定使用者可在您所選定的服務或執行個體的範圍內執行的操作。 「允許的操作」是經過自訂且定義為可在該服務上執行的操作。 然後動作會對映到 IAM 使用者角色。 如需相關資訊,請參閱管理 IBM Cloud 中的使用者存取。
當使用者在 IBM Cloud 中獲得操作 IBM Cloud Security and Compliance Center Workload Protection 服務的權限時,系統會自動授予該使用者一個服務角色。 這個角色決定使用者有權執行的動作。 如需更多資訊,請參閱「透過 IAM 控制存取權限」。
在為實例進行配置之前,您需要了解:
- 帳戶擁有者可以在 IBM Cloud 中建立、檢視及刪除服務的實例,並可將許可權授與其他使用者來使用 IBM Cloud Security and Compliance Center Workload Protection 服務。
- 您必須具有在 Default 資源群組中建立資源的許可權。
- 其他 IBM Cloud 使用者若具有
administrator或editor權限,即可在 IBM Cloud Security and Compliance Center Workload Protection 中管理 IBM Cloud 服務。 這些使用者還必須具有平台許可權,才能在他們計劃佈建實例之資源群組的環境定義內建立資源。
若要授予使用者該服務的管理員角色,並管理帳戶中資源群組內的執行個體,該使用者必須擁有適用於「IBM Cloud Security and Compliance Center Workload Protection」服務的 IAM 政策。 如需更多資訊,請參閱《 授予使用「IBM Cloud Security and Compliance Center Workload Protection」服務的權限 》。
預設情況下,系統會自動將使用者新增為每個 IBM Cloud Security and Compliance Center Workload Protection 執行個體中預先定義的「安全運作」團隊的成員。 使用者具有完整許可權,可以查看 Web 使用者介面中的所有資料。
佈建實例
若要在 IBM Cloud Security and Compliance Center Workload Protection 中使用 IBM Cloud 來新增監視特性,您必須佈建 IBM Cloud Security and Compliance Center Workload Protection 服務的實例。
實例是在資源群組的背景下進行配置的。 資源群組會將您的服務進行分類,以便進行存取控制與計費。 您可以將 IBM Cloud Security and Compliance Center Workload Protection 實例配置在預設資源群組中,或配置在自訂資源群組中。
若要透過 IBM Cloud 使用者介面建立實例,請完成以下步驟:
-
登入您的 IBM Cloud 帳戶。
開啟「IBM Cloud」儀表板。
在使用您的使用者 ID 和密碼登入之後,IBM Cloud 使用者介面即會開啟。
-
按一下型錄。 即會開啟 IBM Cloud 中可用的服務清單。
-
若要篩選顯示的服務清單,請選取「安全性」類別。
-
按一下 IBM Cloud Security and Compliance Center Workload Protection 磚。
-
請選擇地點。
-
選取服務方案。
如需服務方案的相關資訊,請參閱服務方案。
-
輸入服務名稱。
-
選取資源群組。 依預設,會設定 Default 資源群組。
-
按一下建立以佈建實例。
即會開啟服務使用者介面。
若要透過 CLI 建立實例,請參閱 《透過 IBM Cloud CLI 建立監控實例》。
存取「Workload Protection」儀表板
上一步驟應已將您導向至您剛建立的「Workload Protection」的「概覽」頁面。 接著,您只需點擊「開啟儀表板」即可。 如果您已關閉頁面,但想重新返回,請依照以下步驟進入儀表板:
-
開啟「IBM Cloud」儀表板。
-
點擊「導覽選單」圖示「
> 安全性 > 資源
-
從清單中選取您的 Workload Protection 實例,並點擊該實例。
-
在此情況下,請點擊「開啟儀表板」
下一步:設定代理程式
您已成功建立一個 Workload Protection 實例。 請前往 Workload Protection agent setup, 了解如何在您的 Power Virtual Server 執行個體上安裝和設定代理程式,以及 Virtual Servers for VPC。