Getting started with Cloud Security Watcher
    • PDF

    Getting started with Cloud Security Watcher

    • PDF

    Article Summary

    Available in VPC

    If you have checked the support environment and requirements for Cloud Security Watcher and familiarized yourself with the preparations and glossary, you are ready to start using Cloud Security Watcher. The first thing to do now is to request subscription for the Cloud Security Watcher service. You can request subscription to Cloud Security Watcher and manage your subscription in NAVER Cloud Platform's console.

    Request subscription

    The following describes how to request a subscription to Cloud Security Watcher:

    1. Access the NAVER Cloud Platform console.
    2. From the Platform menu, click and select VPC.
    3. Click Services > Security > Cloud Security Watcher.
    4. Click the [Request subscription] button.
    5. Read the Terms and Conditions, agree to them, and then click the [Confirm] button.
    Caution

    The paid products will incur usage fees from the moment of creation even if you haven't actually used it. If you do not want to be charged, you have to cancel or terminate it directly from the console. Please note that the amount charged for not terminating can't be refunded.

    Create Cloud Security Watcher

    The following describes how to create Cloud Security Watcher.

    1. Click the Services > Security > Cloud Security Watcher menu in NAVER Cloud Platform console one by one in order.
    2. Click the Dashboard menu.
    3. Click the [+ Create CSW] button.
    4. Enter the group information to be created in accordance with the conditions.
      csw-start_01_inputinfo_en
      • Group name: basic unit that can be checked on the dashboard. Can check assets included in the group
      • Administrator ID: dashboard administrator’s ID
      • Administrator name: dashboard administrator’s name
      • Email: email information that is used to issue a temporary password or find the password
      • Manager access IP: the main public IP that allows connection to Cloud Security Watcher dashboard
    5. Click the [Create CSW] button when you've entered all the information.
    6. Check the email sent to the registered email.
      csw-start_02_createmail_en

    Group details screen

    The Cloud Security Watcher group details consist of the following:
    csw-start_03_groupinfo_en

    AreaDescription
    ① Basic featuresFeatures displayed when creating Cloud Security Watcher group
  • [Access dashboard] button: click to access as manager
  • [Change settings] button: click to edit email information or manager access representative IP
  • [Delete CSW] button: click to delete Cloud Security Watcher group
  • ② Cloud Security Watcher detailsDisplays detailed information about created groups

    Set admin account

    An admin account is required to access the Cloud Security Watcher manager and use features such as user account registration and use connected accounts. The initial setup of the admin account is as follows.

    1. Check the temporary password issued to the email registered when creating the Cloud Security Watcher group.
      csw-start_04_adminpw_en
    2. From the NAVER Cloud Platform console's Platform menu, click and select VPC.
    3. Click Services > Security > Cloud Security Watcher.
    4. Click the Dashboard menu.
    5. Click the [Access dashboard] button to connect to the manager.
      csw-start_05_dash_en
    6. Enter the necessary information to log in.
      csw-start_06_managerlogin_en
      • ID: admin ID registered when creating the Cloud Security Watcher group
      • PASSWORD: temporary password issued to the email when creating the Cloud Security Watcher group
    7. Change the password.
    8. Log in with the changed password.

    User account registration

    The following describes how to register a user account that can access the Cloud Security Watcher manager.

    1. From the NAVER Cloud Platform console's Platform menu, click and select VPC.
    2. Click Services > Security > Cloud Security Watcher.
    3. Click the Dashboard menu.
    4. Click the [Access dashboard] button to connect to the manager.
    5. Log in with the admin account.
    6. Click the Settings > Basic settings menus, in that order.
    7. Click the [Activate user] tab menu.
    8. Click the [Add] button.
      csw-start_07_adduser_en
    9. When the Add user pop-up window appears, enter the information for the user account.
      csw-start_08_adduserinfo_en
    10. Click the [Save] button.
    11. Select a group for the user under the menu [Group] and click the [Grant permission] button.
      csw-start_09_permission_en
    12. Grant permission and click [Save] button.
      csw-start_10_permissionaccept_en
    Note

    For the user type, check the service user permissions in Cloud Security Watcher concept.

    Set access IP

    The following describes how to configure access IP for user accounts that are trying to accessing Cloud Security Watcher manager.

    1. Log in to the Cloud Security Watcher manager as an admin.
    2. Click the tap menu Setting > Basic settings > [Activated user].
    3. Click [Edit] of the user account for which the public IP will be set.
      csw-start_11_ip_en
    4. Click on the add button under Public IP Setting on User edit page in order to add a public IP.
      csw-start_12_ipadd_en
    5. Click the [Save] button.

    Use connected accounts

    Cloud Security Watcher manager provides API-based and agent-based multi-cloud environment management and auditing. In order to use the API method, you need to add a connected account. How to add a connected account is as follows.

    1. From the NAVER Cloud Platform console's Platform menu, click and select VPC.
    2. Click Services > Security > Cloud Security Watcher.
    3. Click the Dashboard menu.
    4. Click the [Access dashboard] button to connect to the manager.
    5. Log in with the admin account.
    6. Click the Settings > Basic settings menus, in that order.
    7. Click the [Group] tab menu.
    8. Select the group to add the connected account to.
    9. Click the [+ Add] button in the Connected account menu.
      csw-start_13_1_cloudadd_en
    10. Register the cloud account information to connect.
    Caution

    The cloud account for which you register should not be the root account with the highest level of permissions, but instead be a user account with the IAM permissions for connection.

    How to connect NAVER Cloud Platform accounts

    • Accounts connected to Cloud Security Watcher are sub accounts created in Sub Account, an account management service of NAVER Cloud Platform.
    • Cloud Security Watcher supports NAVER Cloud Platform private account connection.
    • For account connection, specific permission (NCP_ADMINISTRATOR) is required.
    Caution

    Cloud Security Watcher supports private VPC environments and only supports private account connection. Financial and public account connection will be available on NAVER Cloud Platform financial and public platform.

    The following describes how to create a sub account and assign permissions.

    1. Access the NAVER Cloud Platform console.

    2. Click the Services > Management & Governance > Sub Account > Sub Accounts menu, in that order.

    3. Click the [Create sub account] button.

    4. Enter the sub account information.

    5. In the Sub Accounts menu, click the login ID of the created sub account.

    6. Click the [Add] button.

    7. Select and add the NCP_ADMINISTRATOR policy from System Managed policies.
      csw-start_13_2_subaccount_en

    8. Click the [Access Key] tab menu.

    9. In Sub account details > Policy, click the [Add] button to generate an API authentication key.
      csw-start_13_3_subaccountapi_en

    10. Proceed through items 1 to 9 of use connected accounts.

    11. Set the cloud item to NCP.

    12. Enter your account and API authentication key information (Access Key ID, Secret Access Key).
      csw-start_13_cloudaccount_en

      Note

      LoginAlias is automatically registered after validation, so no separate input is required.

    13. Click the [Account validation] button.

    14. Once the validation is complete, click the [Save] button.

    How to connect Multi Cloud accounts

    Connecting the AWS of the Cloud Security Watcher and the Azure cloud account allows you to manage multi cloud asset. Check [Help] on connection by cloud, provided in the Add a connected account and add a connected account.
    csw-start_14_multicloud_en

    Manage asset

    When you register a connected account in the Cloud Security Watcher manager, the cloud assets of the connected account are retrieved using the API method. Depending on your preferences, you can exclude specific assets or re-import them.

    Set up asset exclusion

    To exclude specific assets from the imported assets:

    1. Log in to the Cloud Security Watcher manager as an admin.
    2. Select Settings > Basic settings > Group.
    3. Select the appropriate group from Group status.
    4. Click on the relevant connected account.
    5. In the account details, click the [Assets] button.
    6. Select the assets to exclude.
    7. Click the [Exclude asset] button.
    8. Select the unmanaged assets of the relevant group from Group status.
    9. You can check the list of excluded assets.
      csw-start_15_excepasset_en

    Reset managed assets

    The following describes how to re-import excluded assets:

    1. Log in to the Cloud Security Watcher manager as an admin.
    2. Select Settings > Basic settings > Group.
    3. Select the unmanaged assets of the relevant group from Group status.
    4. Select the assets to re-import.
    5. Click the [Move managed assets] button.
      csw-start_16_setasset_en

    Manage subgroup

    You can use the Cloud Security Watcher manager to create a subgroup within a group and add assets to perform the management of grouped assets.

    Caution

    If there is a subgroup within a Cloud Security Watcher group, you cannot delete the group or unsubscribe. If you want to delete the Cloud Security Watcher group, delete all of its subgroups first.

    Create subgroup

    Take the following steps to create a subgroup.

    1. Log in to the Cloud Security Watcher manager as an admin.
    2. Select Settings > Basic settings > Group.
    3. Select the appropriate group from Group status.
    4. Click the [+ Create subgroup] button.
      csw-start_17_createsubgroup_en
    5. Specify Group name and Group description.
    6. Click the [Save] button.
      csw-start_18_createsubgroup2_en
    7. You can view the subgroup you've created under Group status.

    Add or delete subgroup assets

    Take the following steps to add or delete assets in a subgroup.

    1. Log in to the Cloud Security Watcher manager as an admin.
    2. Select Settings > Basic settings > Group.
    3. Select a subgroup to add assets to under Group status.
    4. Click the [+ Add asset] button.
      csw-start_19_subgroupasset_en
    5. Select an asset to add.
      csw-start_20_subgroupassetadd_en
    6. If you click the Region/Resource Group area in the connected account, you can see the added assets.
      csw-start_21_subgroupinfo_en
    7. If you want to delete an asset, select an asset to delete from the asset information of the Asset tab and click the [Delete] button to delete it.
      csw-start_22_subgroupassetremove_en

    Delete subgroup

    Take the following steps to delete a subgroup.

    Caution

    You must delete all assets in a subgroup to delete the subgroup.

    1. Log in to the Cloud Security Watcher manager as an admin.
    2. Select Settings > Basic settings > Group.
    3. Select a subgroup to delete from Group status.
    4. Click the Region/Resource Group area in the connected account.
    5. Delete all assets from the asset information of the Asset tab.
    6. Make sure no data exists in the connected account.
      csw-start_23_subgroupassetcheck_en
    7. Click the [Delete] button in Group status.
    8. Make sure the subgroup is successfully deleted.

    Install agent

    Cloud Security Watcher also supports an agent method for more precise data collection and analysis. In the case of the agent method, the server resource information can be collected by the manager by installing the agent on the server.

    • The agent specifications provided by Cloud Security Watcher can be found in Prerequisites for using Cloud Security Watcher.
    • Set the communication permission rules for TCP ports 443 and 8086 in the ACG console outbound rule settings menu on the server where you want to install the agent to allow Manager to collect host information.
    Caution

    Since the agent plays the role of reading the main information of the system and delivering it to the manager, it must be installed with the super admin account due to system requirements.

    Windows version

    1. Access the Cloud Security Watcher manager.
    2. Click the [i] button located at the upper right corner of the Manager.
      csw-start_24_agent1_en
    3. Download the agent that meets the supported specifications.
    4. Unzip the downloaded file.
    5. Run the CSWHost-install.exe installation file.
    6. Go to Start > Run > services.msc and check if there is a list of agents.

    Linux version

    1. Access the Cloud Security Watcher manager.

    2. Click the [i] button located at the upper right corner of the Manager.
      csw-start_24_agent1_en

    3. Download the agent that meets the supported specifications.

    4. Run Terminal and go to the location where the downloaded file is located.

    5. Enter the following command to copy the agent installation files to the /tmp directory.

      # cp CSW-<version_name>.tar.gz /tmp
      
    6. Go to the tmp directory.

    7. Enter the following command to unzip the installation file.

      # tar –zxvf CSW-<version_name>.tar.gz
      
    8. Go to the CSW-<version_name> directory.

    9. Run the following command to install.

      # ./install.sh
      
    10. AstAgentMon Service Start : press the [Enter] key to end the installation after entering Y in the [Y] input box.

    11. Enter the following command to check the service status.

      # ps –ef | grep Ast
      

    Delete agent

    To delete the agent provided by Cloud Security Watcher:

    Windows version

    1. Download the same file you downloaded for agent installation.
    2. Unzip the downloaded file.
    3. Run the CSWHost_Uninstall.exe installation file.
    4. Check whether the service has been deleted from the list of services.

    Linux version

    1. Download the same file you downloaded for agent installation.
    2. Run Terminal and go to the location where the downloaded file is located.
    3. Enter the following command to copy the agent deletion files to the /tmp directory.
      # cp CSW-<version_name>.tar.gz /tmp
      
    4. Go to the tmp directory.
    5. Enter the following command to unzip the installation file.
      # tar –zxvf CSW-<version_name>.tar.gz
      
    6. Go to the CSW-<version_name> directory.
    7. Run the following command to uninstall the agent.
      # ./uninstall.sh
      
    8. Put Y in all Y/N questions.
    9. Ensure that the processes and directories have been deleted.
      # ps –ef | grep Ast
      

    Cancel subscription

    You can cancel the subscription to Cloud Security Watcher from NAVER Cloud Platform console. You can cancel the subscription at any time, but please take note of the billing standard when canceling. The following describes how to cancel your subscription.

    Caution

    When you delete Cloud Security Watcher, all information, including account information that has been connected, will be lost and cannot be recovered.

    1. From the NAVER Cloud Platform console's Platform menu, click and select VPC.
    2. Click Services > Security > Cloud Security Watcher.
    3. Click the Dashboard menu.
    4. Click the [Delete CSW] button.
      csw-start_25_deletegp_en
    5. Enter the Group information.
      csw-start_26_deletegp2_en
    6. Click the [Delete] button.
    7. Click the Subscription menu.
    8. Click the [Product in use] button, and then click [Cancel subscription].
    9. Check the notification in the confirmation pop-up window and click the [Confirm] button.

    Was this article helpful?

    Changing your password will log you out immediately. Use the new password to log back in.
    First name must have atleast 2 characters. Numbers and special characters are not allowed.
    Last name must have atleast 1 characters. Numbers and special characters are not allowed.
    Enter a valid email
    Enter a valid password
    Your profile has been successfully updated.