Lacework policies provide a framework for validating configuration and behavior in your cloud environment. Lacework provides a set of predefined default policies that are visible from the Lacework Console. You can use the default policies to suppress the generation of unwanted alerts in your environment. Default policy IDs start with the LW_ prefix. You may want to create custom policies that check for unwanted behavior in your environment such as Telnet being used in your environment. You can also customize the triggers and severities for custom policies. Custom policy IDs start with the CUSTOM_ prefix.
When the page displays your desired policies after filtering, you can save the current view by clicking the Save view icon in the top right corner. This allows you to access the saved view later through the Open view icon.
For custom policy queries, Lacework allows simple comparison expressions that are created in the console. Learn more about the types of expressions that you can use here.
Lacework default policies enable out-of-the-box security validation of your AWS environments. But not every organization is the same and custom policies are a great way to add validation specific to your organization’s requirements.