<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
   <channel>
      <title>Trend Cloud One Main</title>
      <link>https://docs.trendmicro.com/en-us/documentation/trend-micro-cloud-one-main/trend-micro-cloud-one-main-whats-new/</link>
      <description>New Features, updates, and release notes for Trend Cloud One Main</description>
      <language>en-us</language>
      <lastBuildDate>Mon, 18 May 2026 00:32:35 GMT</lastBuildDate>
<item>
    <title>Cross-Account Scanner Deployment Issue Resolved</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cross-account-scanner-deployment-i</link>
    <description><![CDATA[<div class="p">July 13,  2020, File Storage Security—The scanner stack would not scan if it was deployed
               in a different AWS account from the storage stack in a cross-account scenario. This
               issue has been fixed.</div>]]></description>
    <pubDate>Mon, 13 Jul 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cross-account-scanner-deployment-i</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Request Preview Access button added to File Storage Security page</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-request-preview-access-button-adde</link>
    <description><![CDATA[<div class="p">July 15,  2020, File Storage Security—The Request Preview Access button is now available
               on the <a class="xref" href="https://cloudone.trendmicro.com/filestorage" target="_blank">Coming Soon</a> page.</div>]]></description>
    <pubDate>Wed, 15 Jul 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-request-preview-access-button-adde</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Management role ARN submission failure notification fixed during stack creation</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-management-role-arn-submission-fai</link>
    <description><![CDATA[<div class="p">July 15,  2020, File Storage Security—During a stack creation, a failure notification
               may have been incorrectly displayed when you submitted the management role ARN. This
               issue has been fixed.</div>]]></description>
    <pubDate>Wed, 15 Jul 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-management-role-arn-submission-fai</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved tooltips in stacks table for enhanced user experience</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-tooltips-in-stacks-table</link>
    <description><![CDATA[<div class="p">July 30,  2020, File Storage Security—The console now displays useful on-hover tooltips
               in the stacks table.</div>]]></description>
    <pubDate>Thu, 30 Jul 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-tooltips-in-stacks-table</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced Stack Table Sorting and Infinite Scrolling Feature</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-stack-table-sorting-and-i</link>
    <description><![CDATA[<div class="p">August 11,  2020, File Storage Security—The stack table now supports sorting by stack
               name and infinite scrolling.</div>]]></description>
    <pubDate>Tue, 11 Aug 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-stack-table-sorting-and-i</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Data Collection Notice now accessible for File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-data-collection-notice-now-accessi</link>
    <description><![CDATA[<div class="p">August 18,  2020, File Storage Security—The Data Collection Notice is now available
               <a class="xref" href="https://success.trendmicro.com/en-us/solution/ka-0010640" target="_blank">here</a>.</div>]]></description>
    <pubDate>Tue, 18 Aug 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-data-collection-notice-now-accessi</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced User Interface for File Storage Security Stack Table</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-user-interface-for-file-s</link>
    <description><![CDATA[<div class="p">August 25,  2020, File Storage Security—The header of the stack table now sticks to
               the top while the stack table is scrolling vertically.</div><div class="p">The stack table now displays the default message if no data is received from the API.</div><div class="p">The storage stack table is now a fluid width. (The scanner stack table remains a static
               width.)</div>]]></description>
    <pubDate>Tue, 25 Aug 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-user-interface-for-file-s</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>S3 bucket objects now encrypted with SSE-S3 for enhanced security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-s3-bucket-objects-now-encrypted-wi</link>
    <description><![CDATA[<div class="p">September 07,  2020, File Storage Security—The objects in the `CopyZipsDestBucket`
               S3 bucket are now encrypted using <a class="xref" href="https://docs.aws.amazon.com/AmazonS3/latest/dev/serv-side-encryption.html" target="_blank">Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3)</a>. This functionality requires a stack update.</div>]]></description>
    <pubDate>Mon, 07 Sep 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-s3-bucket-objects-now-encrypted-wi</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved error message display for console loading issues</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-error-message-display-for</link>
    <description><![CDATA[<div class="p">September 11,  2020, File Storage Security—When a problem occurs loading the console,
               a friendly error message is now displayed in the browser window instead of a blank
               page.</div>]]></description>
    <pubDate>Fri, 11 Sep 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-error-message-display-for</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>BytesTransferred attribute removed from File Storage Security scanner result message</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bytestransferred-attribute-removed</link>
    <description><![CDATA[<div class="p">September 14,  2020, File Storage Security—The `BytesTransferred` attribute is no
               longer included in the scanner result message.</div>]]></description>
    <pubDate>Mon, 14 Sep 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bytestransferred-attribute-removed</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>ScanningBucket resource removed, scanning now on existing buckets with stack update</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanningbucket-resource-removed-sc</link>
    <description><![CDATA[<div class="p">September 21,  2020, File Storage Security—The ScanningBucket resource was removed
               from the storage stack. The storage stack now only supports scanning on an existing
               bucket. This functionality requires a stack update.</div>]]></description>
    <pubDate>Mon, 21 Sep 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanningbucket-resource-removed-sc</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved File Storage Security AWS Tag Handling</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-file-storage-security-aws</link>
    <description><![CDATA[<div class="p">September 21,  2020, File Storage Security—The PostScanActionTagLambda no longer overwrites
               a file's existing AWS tags with its own `fss-*` tags. (If a file has previously been
               scanned, and is then scanned again, its existing `fss-*` tags will be overwritten
               by newer ones from the latest scan.) This functionality requires a stack update.</div>]]></description>
    <pubDate>Mon, 21 Sep 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-file-storage-security-aws</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved User Interface and Functionality for File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-user-interface-and-functi</link>
    <description><![CDATA[<div class="p">September 25,  2020, File Storage Security—The stack table now displays a spinner
               when data is loading.</div><div class="p">The Scanner Policy and Storage Policy columns were removed from the console's main
               page since they didn't contain enough information to justify their presence.</div><div class="p">The Deploy All-in-One Stack dialog box now displays a link to the Help Center.</div><div class="p">An Add Post-Scan Action button now appears on the console's main page.</div><div class="p">The instructions in the Deploy All-in-One Stack and Add Storage dialog boxes are now
               more descriptive.</div><div class="p">The stack table can now be resized.</div>]]></description>
    <pubDate>Fri, 25 Sep 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-user-interface-and-functi</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced IAM permissions for Scanner and Storage Stacks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-iam-permissions-for-scann</link>
    <description><![CDATA[<div class="p">October 08,  2020, File Storage Security—Scanner stacks and storage stacks now create
               IAM policies with more limited permissions. This functionality requires a stack update.</div>]]></description>
    <pubDate>Thu, 08 Oct 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-iam-permissions-for-scann</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>New default stack names introduced for File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-default-stack-names-introduced</link>
    <description><![CDATA[<div class="p">October 12,  2020, File Storage Security—The default stack names are now `All-in-one-TM-FileStorageSecurity`
               and `Storage-TM-FileStorageSecurity`.</div>]]></description>
    <pubDate>Mon, 12 Oct 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-default-stack-names-introduced</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced IAM Role Permissions for Scanner and Storage Stacks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-iam-role-permissions-for</link>
    <description><![CDATA[<div class="p">October 16,  2020, File Storage Security—Scanner stacks and storage stacks now create
               management-related IAM roles with more limited permissions. This functionality requires
               a stack update.</div>]]></description>
    <pubDate>Fri, 16 Oct 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-iam-role-permissions-for</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced File Storage Security with Deploy Button and Delete Stack API</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-storage-security-wit</link>
    <description><![CDATA[<div class="p">November 11,  2020, File Storage Security—A Deploy button now appears on the console's
               main page.</div><div class="p">The Deploy dialog box contains the two clickable options. Deploy All-in-One Stack
               and Deploy Scanner Stack.</div><div class="p">New Delete Stack API for deleting stacks.</div>]]></description>
    <pubDate>Wed, 11 Nov 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-storage-security-wit</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>List Stacks API now returns correct &#x27;next&#x27; attribute for improved paging functionality</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-list-stacks-api-now-returns-correc</link>
    <description><![CDATA[<div class="p">November 11,  2020, File Storage Security—List Stacks API now returns the correct
               attribute, `next` (instead of `cursor`), for paging the results.</div>]]></description>
    <pubDate>Wed, 11 Nov 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-list-stacks-api-now-returns-correc</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced Deployment and Stack Management Features for File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-deployment-and-stack-mana</link>
    <description><![CDATA[<div class="p">November 17,  2020, File Storage Security—The Deploy All-in-One Stack, Deploy Scanner
               Stack and Deploy Storage Stack dialog boxes now support deploying to the dedicated
               AWS regions.</div><div class="p">Scanner stacks and storage stacks can now be deleted.</div><div class="p">Change of the background color of the active stack.</div><div class="p">The stack output now provides the value of the SNS ScanResultTopic ARN for the all-in-one
               stack and storage stack. This functionality requires a stack update.</div>]]></description>
    <pubDate>Tue, 17 Nov 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-deployment-and-stack-mana</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>File Storage Security now globally available</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-globally</link>
    <description><![CDATA[<div class="p">November 18,  2020, File Storage Security—File Storage Security has left private preview
               and is now globally available.</div>]]></description>
    <pubDate>Wed, 18 Nov 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-globally</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Memory leak issues resolved in scanner stack</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-memory-leak-issues-resolved-in-sca</link>
    <description><![CDATA[<div class="p">November 19,  2020, File Storage Security—Fix memory leaks in scanner stack.</div>]]></description>
    <pubDate>Thu, 19 Nov 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-memory-leak-issues-resolved-in-sca</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced AWS Region Selector in Deploy Modal for File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-region-selector-in-de</link>
    <description><![CDATA[<div class="p">November 27,  2020, File Storage Security—The AWS region selector in Deploy modal
               dialog boxes now displays the default value based on the last selected.</div>]]></description>
    <pubDate>Fri, 27 Nov 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-region-selector-in-de</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Trend Micro Cloud One - Container Security now released</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-cloud-one---container</link>
    <description><![CDATA[<div class="p">December 01,  2020, Container Security—Trend Micro Cloud One - Container Security
               is now available.</div>]]></description>
    <pubDate>Tue, 01 Dec 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-cloud-one---container</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Scanner Stacks No Longer Collect S3 Object Keys by Default</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanner-stacks-no-longer-collect-s</link>
    <description><![CDATA[<div class="p">December 01,  2020, File Storage Security—From now on, scanner stacks do not collect
               S3 object keys by default.</div>]]></description>
    <pubDate>Tue, 01 Dec 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanner-stacks-no-longer-collect-s</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Geolocation Filtering for Enhanced Network Security Protection</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-geolocation-filtering-for-enhanced</link>
    <description><![CDATA[<div class="p">December 08,  2020, Network Security—Geolocation Filtering: Provides the ability to
               block incoming and outgoing IPv4 requests according to countries or regions. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Geo_Location_filtering-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Tue, 08 Dec 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-geolocation-filtering-for-enhanced</guid>
    <category>Network Security</category>
</item>
<item>
    <title>AWS Network Firewall integration enhances threat detection and disruption on AWS-managed networks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-network-firewall-integration-e</link>
    <description><![CDATA[<div class="p">December 08,  2020, Network Security—AWS Network Firewall: Enables you to pair Network
               Security’s industry-leading threat intelligence with your AWS-managed network infrastructure
               to detect and disrupt common network-based threats. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Digital_Vaccine_packages-#awsNSfirewall" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Tue, 08 Dec 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-network-firewall-integration-e</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Enhanced Cost Allocation Tags for Network Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-cost-allocation-tags-for</link>
    <description><![CDATA[<div class="p">December 08,  2020, Network Security—Vendor-provided cost allocation tags: A Network
               Security cost allocation tag that presents more detailed information about the various
               costs in your AWS environment. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Pay_as_you_Go_billing-#vendor-provided-cost-allocation-tags" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Tue, 08 Dec 2020 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-cost-allocation-tags-for</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Advanced Search supports Fail Open criteria for Firewall Events</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-advanced-search-now-supports-fail</link>
    <description><![CDATA[<div class="p">January 04, 2021, Workload Security—You were unable to do an advanced search on Events
               &amp; Reports &gt; Firewall Events &gt; Advanced Search with the Search criteria set to "Action"
               and "Fail Open" entered as the search value.</div>]]></description>
    <pubDate>Mon, 04 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-advanced-search-now-supports-fail</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved Agent Certificate Generation to Prevent Connection Issues</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-agent-certificate-generat</link>
    <description><![CDATA[<div class="p">January 05, 2021, Workload Security—When Trend Cloud One - Endpoint &amp; Workload Security
               generated a new certificate for an agent that already had one, there were sometimes
               connection issues.</div>]]></description>
    <pubDate>Tue, 05 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-agent-certificate-generat</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Stack table columns can now be resized</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-stack-table-columns-can-now-be-res</link>
    <description><![CDATA[<div class="p">January 05, 2021, File Storage Security—The columns of the stack table can now be
               resized.</div>]]></description>
    <pubDate>Tue, 05 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-stack-table-columns-can-now-be-res</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Activity Monitoring now generally available for enhanced detection and analysis</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-activity-monitoring-now-generally</link>
    <description><![CDATA[<div class="p">January 06, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-xdr-#Enable_Activity_Monitoring" target="_blank">XDR Activity Monitoring</a> is now out of preview and generally available to all customers. When Activity Monitoring
               is enabled, additional information is collected by Trend Cloud One - Endpoint &amp; Workload
               Security and forwarded to Trend Micro XDR to provide correlated detection and root
               cause analysis capabilities.</div>]]></description>
    <pubDate>Wed, 06 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-activity-monitoring-now-generally</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Simplified NSX Manager changes in vCenter for easier management</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-simplified-nsx-manager-changes-in</link>
    <description><![CDATA[<div class="p">January 07, 2021, Workload Security—Updated vCenter to make changing an NSX Manager
               simpler by using the Remove NSX Manager button (Properties &gt; NSX Manager) rather than
               editing the Manager Address: field.</div>]]></description>
    <pubDate>Thu, 07 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-simplified-nsx-manager-changes-in</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Reduced Hourly Price for Extra Large and Not Cloud Instances on AWS Trend Cloud One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-reduced-hourly-price-for-extra-lar</link>
    <description><![CDATA[<div class="p">January 11, 2021, Workload Security—For subscribers to the Trend Cloud One listing
               on AWS, the hourly price of Extra Large and Not Cloud instances has been reduced from
               $0.06 USD to $0.045 USD per instance.</div><div class="p">Note: This change applies only to the Trend Cloud One listing, the pricing for the
               Trend Micro Deep Security listing is unchanged.</div>]]></description>
    <pubDate>Mon, 11 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-reduced-hourly-price-for-extra-lar</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Resource Prefix Configuration for File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-resource-prefix-configura</link>
    <description><![CDATA[<div class="p">January 14, 2021, File Storage Security—All-in-one stacks, scanner stacks and storage
               stacks can now specify resource prefix for IAM role name, IAM policy name, bucket
               name, Lambda function name, Lambda layer name, SQS queue name and SNS policy name.
               This functionality requires a stack update.</div>]]></description>
    <pubDate>Thu, 14 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-resource-prefix-configura</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced File Storage Security supports scanning S3 buckets with SSE-KMS encryption</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-storage-security-sup</link>
    <description><![CDATA[<div class="p">January 15, 2021, File Storage Security—File Storage Security can now scan S3 buckets
               that have <a class="xref" href="https://docs.aws.amazon.com/AmazonS3/latest/dev/serv-side-encryption.html" target="_blank">server-side encryption with customer master keys (CMKs) stored in AWS Key Management
                  Service (SSE-KMS)</a>. This functionality requires a stack update.</div>]]></description>
    <pubDate>Fri, 15 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-storage-security-sup</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Network Security now available for Azure deployment</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-network-security-now-available-for</link>
    <description><![CDATA[<div class="p">January 15, 2021, Network Security—Network Security for Azure is now generally available.
               Learn more about <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Azure_GettingStarted-" target="_blank">deploying Network Security on Azure</a>.</div>]]></description>
    <pubDate>Fri, 15 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-network-security-now-available-for</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Workload Security now supports Amazon Linux 2 on AWS ARM-based Graviton 2</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-workload-security-now-supports-ama</link>
    <description><![CDATA[<div class="p">January 20, 2021, Workload Security—The agent now supports Amazon Linux 2 on AWS ARM-based
               Graviton 2. The agent currently supports the Firewall, Intrusion Prevention, and Web
               Reputation protection modules. Other protection modules are coming soon.</div>]]></description>
    <pubDate>Wed, 20 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-workload-security-now-supports-ama</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>AIX platform now supports Anti-Malware detection</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aix-platform-now-supports-anti-mal</link>
    <description><![CDATA[<div class="p">January 20, 2021, Workload Security—This release adds support for Anti-Malware on
               the AIX platform.</div>]]></description>
    <pubDate>Wed, 20 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aix-platform-now-supports-anti-mal</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Behavior Monitoring now supported on Linux platform</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-behavior-monitoring-now-supported</link>
    <description><![CDATA[<div class="p">January 20, 2021, Workload Security—This release adds support for Behavior Monitoring
               on the Linux platform.</div>]]></description>
    <pubDate>Wed, 20 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-behavior-monitoring-now-supported</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved Display of Add Group(s) Pop-up Menu in Computers Tab</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-display-of-add-groups-pop</link>
    <description><![CDATA[<div class="p">January 25, 2021, Workload Security—In the Computers tab of Trend Cloud One - Endpoint
               &amp; Workload Security, when the Create Group(s) button was clicked, it sometimes failed
               to display the Add Group(s) pop-up menu properly.</div>]]></description>
    <pubDate>Mon, 25 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-display-of-add-groups-pop</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Linux configurations now supported for relay version installation</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-linux-configurations-now-supported</link>
    <description><![CDATA[<div class="p">January 25, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               was unable to install the correct relay version under some Linux configurations.</div>]]></description>
    <pubDate>Mon, 25 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-linux-configurations-now-supported</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Corrected role rights after Trend Vision One onboarding</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-corrected-role-rights-after-trend</link>
    <description><![CDATA[<div class="p">January 25, 2021, Workload Security—After completing Trend Vision One onboarding,
               some roles (Administration &gt; User Management &gt; Roles) did not have the correct rights
               assigned to them.</div>]]></description>
    <pubDate>Mon, 25 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-corrected-role-rights-after-trend</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Trend Cloud One Enhancements: New Compliance and SOC Reports Available</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-cloud-one-enhancements-new-c</link>
    <description><![CDATA[<div class="p">January 26, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               has added compliance for ISO27014, ISO27017 and now has a SOC 2 and SOC 3 report available.
               For details, please see the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--trust-center-" target="_blank">Trend Cloud One Trust Center</a>.</div>]]></description>
    <pubDate>Tue, 26 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-cloud-one-enhancements-new-c</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Additional static IP addresses added for Cloud One - Endpoint &amp; Workload Security relays</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-additional-static-ip-addresses-add</link>
    <description><![CDATA[<div class="p">January 28, 2021, Workload Security—On 2021-03-01, Trend Micro is adding additional
               static IP addresses for the relays hosted by Trend Cloud One - Endpoint &amp; Workload
               Security. If you are using an Trend Cloud One - Endpoint &amp; Workload Security account
               created on or before 2020-11-23 and apply egress traffic policy based on the static
               IP addresses defined in <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-communication-ports-urls-ip-" target="_blank">Port numbers, URLs, and IP addresses</a>, read <a class="xref" href="https://success.trendmicro.com/en-us/solution/ka-0011455" target="_blank">Addition of new static relay IP's for Cloud One accounts created before 2020-11-23</a> for details on this change and the action required to ensure your service continues
               without interruption.</div>]]></description>
    <pubDate>Thu, 28 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-additional-static-ip-addresses-add</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Trend Micro discontinues Deep Security as a Service subscription options on AWS Marketplace</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-discontinues-deep-secu</link>
    <description><![CDATA[<div class="p">January 29, 2021, Workload Security—Beginning 2021-03-01, Trend Micro will no longer
               offer <a class="xref" href="https://aws.amazon.com/marketplace/pp/B07GYLYT14" target="_blank">Deep Security as a Service | Annual + Pay as You Go</a> subscription options to new subscribers on the AWS Marketplace. If you are currently
               subscribed you can continue to use the service until the end of your term, and there
               will be no impact to usage of the service. This service is now available as part of
               <a class="xref" href="https://aws.amazon.com/marketplace/pp/B01LXMNGHB" target="_blank">Trend Cloud One</a> on AWS Marketplace.</div>]]></description>
    <pubDate>Fri, 29 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-discontinues-deep-secu</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Credit card payments no longer accepted for Workload Security subscriptions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-credit-card-payments-no-longer-acc</link>
    <description><![CDATA[<div class="p">January 29, 2021, Workload Security—Beginning 2021-03-31, Trend Micro will no longer
               accept credit card payments for Trend Cloud One - Endpoint &amp; Workload Security or
               Deep Security as a Service. Customers currently subscribed using the credit card billing
               option through Trend Micro's billing partner, Cleverbridge, will need to transition
               to a supported payment option before March 31st to avoid any potential interruption
               in service.</div>]]></description>
    <pubDate>Fri, 29 Jan 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-credit-card-payments-no-longer-acc</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Domain Filtering with FQDN APIs</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-domain-filtering-with-fqd</link>
    <description><![CDATA[<div class="p">February 10, 2021, Network Security—Domain filtering: With appliance version 2021.1.0.10892
               you can use APIs to create and manage a list of fully qualified domain names (FQDNs)
               that have permitted access to your environment. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Domain_Filtering-" target="_blank">Learn more</a> about using these FQDN APIs.</div>]]></description>
    <pubDate>Wed, 10 Feb 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-domain-filtering-with-fqd</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Enhanced Filter Searches for Precise Network Security Results</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-filter-searches-for-preci</link>
    <description><![CDATA[<div class="p">February 10, 2021, Network Security—Filter searches: Filter searches now include exact-match
               results for platform, protocol, and category searches. You can also narrow your results
               by enclosing multi-word searches in quotes for exact-match results. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Filters_overview-#search-filters" target="_blank">Learn more</a> about these enhancements.</div>]]></description>
    <pubDate>Wed, 10 Feb 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-filter-searches-for-preci</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Improved display speed for Integrity Monitoring events</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-display-speed-for-integri</link>
    <description><![CDATA[<div class="p">February 12, 2021, Workload Security—Applying certain filters to Integrity Monitoring
               events (Events &amp; Reports &gt; Events &gt; Integrity Monitoring) caused an extended delay
               before the events were displayed.</div>]]></description>
    <pubDate>Fri, 12 Feb 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-display-speed-for-integri</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>File Storage Security Enhanced with Python 3.8 Upgrade</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-enhanced-wit</link>
    <description><![CDATA[<div class="p">February 17, 2021, File Storage Security—The Python runtime of `CopyZipsLambda` has
               been upgraded to 3.8 to address the <a class="xref" href="https://aws.amazon.com/blogs/compute/upcoming-changes-to-the-python-sdk-in-aws-lambda/" target="_blank">AWS SDK change</a>. This functionality requires a stack update.</div>]]></description>
    <pubDate>Wed, 17 Feb 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-enhanced-wit</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved Report Generation Performance in Trend Cloud One - Endpoint &amp; Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-report-generation-perform</link>
    <description><![CDATA[<div class="p">February 18, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               sometimes timed out when attempting to generate a report (Events &amp; Reports &gt; Generate
               Reports).</div>]]></description>
    <pubDate>Thu, 18 Feb 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-report-generation-perform</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Container Security now allows separate actions for each rule in Admission Policies page</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-now-allows-sepa</link>
    <description><![CDATA[<div class="p">February 24, 2021, Container Security—The Container Security Admission Policies page
               now enables you to specify separate actions for each rule. For details, see the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-policy-create-" target="_blank">Container Security help</a>.</div>]]></description>
    <pubDate>Wed, 24 Feb 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-now-allows-sepa</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Improved wildcard functionality for file and directory exclusions in Trend Cloud One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-wildcard-functionality-fo</link>
    <description><![CDATA[<div class="p">February 24, 2021, Workload Security—Updated Trend Cloud One - Endpoint &amp; Workload
               Security to improve wildcard functionality for file and directory exclusions (Policies
               &gt; Common Objects &gt; Other &gt; Malware Scan Configurations). Details on wildcard use are
               provided in the Exclusions tab of any File List or Directory List.</div>]]></description>
    <pubDate>Wed, 24 Feb 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-wildcard-functionality-fo</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved System Event Reports in Workload Security&#x27;s Trend Cloud One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-system-event-reports-in-w</link>
    <description><![CDATA[<div class="p">February 24, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               "System Event Reports" (Events &amp; Reports &gt; Generate Reports) sometimes had no data
               in the section for "Most Active Computers Ranked by Number of System Events."</div>]]></description>
    <pubDate>Wed, 24 Feb 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-system-event-reports-in-w</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Scheduled Maintenance Required for Pre-2018 Trend Cloud One Accounts</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scheduled-maintenance-required-for</link>
    <description><![CDATA[<div class="p">March 01, 2021, Workload Security—Scheduled maintenance will be required for all Trend
               Cloud One accounts that were created before 2018-10-31. For more information see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-maintenance-schedule-" target="_blank">Trend Cloud One Maintenance</a>.</div>]]></description>
    <pubDate>Mon, 01 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scheduled-maintenance-required-for</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Namespace Rule Customization for Cluster Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-namespace-rule-customizat</link>
    <description><![CDATA[<div class="p">March 02, 2021, Container Security—Previously, the policy assigned to a cluster applied
               the same set of rules to the entire cluster. Now, if your cluster contains more than
               one namespace, you can define separate sets of rules for the namespaces.  For details,
               see the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-policy-create-" target="_blank">Container Security help</a>.</div>]]></description>
    <pubDate>Tue, 02 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-namespace-rule-customizat</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Improved Clickable Links in Computer Status Widget and Agent/Appliance Upgrade Alerts</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-clickable-links-in-comput</link>
    <description><![CDATA[<div class="p">March 05, 2021, Workload Security—Links were sometimes not clickable from the Computer
               Status widget of the Dashboard tab, and from Agent/Appliance Upgrade Recommended (New
               Version Available) alerts opened from the List View of the Alerts tab.</div>]]></description>
    <pubDate>Fri, 05 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-clickable-links-in-comput</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Updated Service Level Agreement now includes all Trend Cloud One services</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-service-level-agreement-no</link>
    <description><![CDATA[<div class="p">March 05, 2021, Workload Security—The Service Level Agreement (SLA) has been updated.
               <a class="xref" href="https://ohc.blob.core.windows.net/o-help/manual/dc546e95-c7b7-41cc-a724-38a9c0130994/Trend_Micro_Cloud_One_Service_Level_Agreement.pdf" target="_blank">This SLA</a> now includes all Trend Cloud One services and replaces the prior Trend Cloud One
               - Endpoint &amp; Workload Security/Deep Security as a Service SLA.</div>]]></description>
    <pubDate>Fri, 05 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-service-level-agreement-no</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved scanning bucket switching with required stack update</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-scanning-bucket-switching</link>
    <description><![CDATA[<div class="p">March 12, 2021, File Storage Security—Fix the storage stack issue with switching from
               one scanning bucket to another. This functionality requires a stack update.</div>]]></description>
    <pubDate>Fri, 12 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-scanning-bucket-switching</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>XDR Remote Shell added for agent version 20.0.0-2009</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-xdr-remote-shell-added-for-agent-v</link>
    <description><![CDATA[<div class="p">March 16, 2021, Workload Security—This release adds XDR Remote Shell support to agent
               version 20.0.0-2009. Following Trend Vision One onboarding, you can now run commands
               directly through the XDR-integrated Remote Shell. For more information see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-remote-shell-" target="_blank">Trend Vision One (XDR) Remote Shell</a>.</div>]]></description>
    <pubDate>Tue, 16 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-xdr-remote-shell-added-for-agent-v</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved Firewall Event Data Visibility in System Event Reports</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-firewall-event-data-visib</link>
    <description><![CDATA[<div class="p">March 17, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security "System
               Event Reports" (Events &amp; Reports &gt; Generate Reports) sometimes showed no firewall
               event data even if there were Firewall Events (Events &amp; Reports &gt; Events &gt; Firewall
               Events) during the report period.</div>]]></description>
    <pubDate>Wed, 17 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-firewall-event-data-visib</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Smart Folders searchable by Computer Description in Trend Cloud One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-smart-folders-now-searchable-by-co</link>
    <description><![CDATA[<div class="p">March 19, 2021, Workload Security—Updated Trend Cloud One - Endpoint &amp; Workload Security
               to make the Computer Description field for Smart Folders usable as a search criteria
               (Computers &amp; Smart Folders).</div>]]></description>
    <pubDate>Fri, 19 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-smart-folders-now-searchable-by-co</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Maintenance Announcement for Trend Cloud One Accounts Created Before October 31, 2018</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-maintenance-announcement-for-trend</link>
    <description><![CDATA[<div class="p">March 19, 2021, Workload Security—The Trend Cloud One - Endpoint &amp; Workload Security
               RSS feed did not notify subscribers of the Scheduled Maintenance announcement made
               on March 1. To recap that announcement:</div><div class="p">"Scheduled Maintenance will be required for all Trend Cloud One accounts that were
               created before 2018-10-31. For more information see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-maintenance-schedule-" target="_blank">Trend Cloud One Maintenance</a>."</div>]]></description>
    <pubDate>Fri, 19 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-maintenance-announcement-for-trend</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Deploy All-in-One and Storage Stacks with Triggered Scans for File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deploy-all-in-one-and-storage-stac</link>
    <description><![CDATA[<div class="p">March 22, 2021, File Storage Security—<a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-gs-deploy-all-in-one-stack" target="_blank">All-in-one stacks</a> and <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-stack-add-aws-#AddStorage" target="_blank">storage stacks</a> can now be deployed if the `s3:ObjectCreated:*` event of the scanning bucket is in
               use by setting the TriggerWithObjectCreatedEvent option to false.</div><div class="p">You can then trigger the scans by invoking the deployed BucketListenerLambda in storage
               stacks.</div>]]></description>
    <pubDate>Mon, 22 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deploy-all-in-one-and-storage-stac</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Agent package names now aligned with Download Center</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-package-names-now-aligned-wi</link>
    <description><![CDATA[<div class="p">March 23, 2021, Workload Security—Aligned agent package naming with the Download Center.</div>]]></description>
    <pubDate>Tue, 23 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-package-names-now-aligned-wi</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Container Security policies can now block or log images based on CVSS values</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-policies-can-no</link>
    <description><![CDATA[<div class="p">March 29, 2021, Container Security—Container Security policies can now include rules
               that block or log images based on the CVSS values of vulnerabilities found in Smart
               Check scans. For details, see the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-policy-create-#cvss" target="_blank">Container Security help</a>.</div>]]></description>
    <pubDate>Mon, 29 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-policies-can-no</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Improved performance for Trend Cloud One - Endpoint &amp; Workload Security APIs</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-performance-for-trend-clo</link>
    <description><![CDATA[<div class="p">March 29, 2021, Workload Security—Updated Trend Cloud One - Endpoint &amp; Workload Security
               to improve "Search Computer API" and "List Computer API" performance.</div>]]></description>
    <pubDate>Mon, 29 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-performance-for-trend-clo</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>AWS connector synchronization issue resolved in Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-connector-synchronization-issu</link>
    <description><![CDATA[<div class="p">March 30, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security sometimes
               became unable to synchronize with an AWS connector after it had been renamed.</div>]]></description>
    <pubDate>Tue, 30 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-connector-synchronization-issu</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved description for upgrading agent software in Trend Cloud One - Endpoint &amp; Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-description-for-upgrading</link>
    <description><![CDATA[<div class="p">March 30, 2021, Workload Security—Updated Trend Cloud One - Endpoint &amp; Workload Security
               to provide a clearer description for Upgrade Agent Software (Administration &gt; Updates
               &gt; Software &gt; Upgrade Agent/Appliance Software).</div>]]></description>
    <pubDate>Tue, 30 Mar 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-description-for-upgrading</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Cloud One read-only role restricted from create/delete API usage</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloud-one-read-only-role-restricte</link>
    <description><![CDATA[<div class="p">April 08, 2021, File Storage Security—The API now prevents Cloud One read-only role
               from using create or delete API.</div>]]></description>
    <pubDate>Thu, 08 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloud-one-read-only-role-restricte</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced Filter Search Capabilities for Network Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-filter-search-capabilitie</link>
    <description><![CDATA[<div class="p">April 08, 2021, Network Security—Filter searching enhancements: Enhancements to filter
               searches are now available and include partial-match results for filter name, filter
               number, description, platform, severity, CVE, and category searches. This enables
               you to search for a single word in a sentence or phrase. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Filters_overview-#search-filters" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 08 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-filter-search-capabilitie</guid>
    <category>Network Security</category>
</item>
<item>
    <title>TLS Inspection Preview Now Available for Network Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-tls-inspection-preview-now-availab</link>
    <description><![CDATA[<div class="p">April 08, 2021, Network Security—TLS inspection: A preview version of TLS inspection
               for Network Security is now available with appliance version 2021.3.0.10968. TLS inspection
               provides secure web server traffic inspection and insight into your network activity
               without compromising cryptographic security. To access this preview feature and help
               shape the future of this capability for Network Security, click <a class="xref" href="https://cloudone.trendmicro.com/network/ui/sslInspection" target="_blank">Request Access</a>. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-tls_inspection_overview" target="_blank">Learn more</a> about TLS inspection.</div>]]></description>
    <pubDate>Thu, 08 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-tls-inspection-preview-now-availab</guid>
    <category>Network Security</category>
</item>
<item>
    <title>New cost-optimized c5.xlarge instance type for AWS deployments</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-cost-optimized-c5xlarge-instan</link>
    <description><![CDATA[<div class="p">April 08, 2021, Network Security—New instance type: A new, smaller and cost-optimized
               instance type, c5.xlarge, is now available for AWS deployments.  <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-create-ami-instance-#4-create-network-security-instances" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 08 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-cost-optimized-c5xlarge-instan</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Statistics API now customizable for File Storage Security scan results</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-statistics-api-now-customizable-fo</link>
    <description><![CDATA[<div class="p">April 09, 2021, File Storage Security—Statistics API is now available, allowing API
               users to customize their File Storage Security scan results. For more details, <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-api-reference-tag-Statistics" target="_blank">click here</a>.</div>]]></description>
    <pubDate>Fri, 09 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-statistics-api-now-customizable-fo</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved AWS connector management in Trend Cloud One Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-connector-management</link>
    <description><![CDATA[<div class="p">April 12, 2021, Workload Security—Duplicate instances were sometimes created for AWS
               connectors in Trend Cloud One - Endpoint &amp; Workload Security.</div>]]></description>
    <pubDate>Mon, 12 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-connector-management</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Remote Shell Commands Support for Windows and Linux Agents</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-remote-shell-commands-sup</link>
    <description><![CDATA[<div class="p">April 12, 2021, Workload Security—Updated Trend Cloud One - Endpoint &amp; Workload Security
               to support additional Remote Shell commands for agent version 20.0.0-2204+ for Windows
               and Linux. For more information, see the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-remote-shell-#supported-commands" target="_blank">Supported commands</a> section of the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-remote-shell-" target="_blank">Remote Shell</a> article.</div>]]></description>
    <pubDate>Mon, 12 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-remote-shell-commands-sup</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved console functionality for adding storage stacks after deletions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-console-functionality-for</link>
    <description><![CDATA[<div class="p">April 13, 2021, File Storage Security—Fixed the issue that sometimes storage stacks
               cannot be added to the console</div><div class="p">if there were another storage stack(s) deleted from the same scanner stack.</div>]]></description>
    <pubDate>Tue, 13 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-console-functionality-for</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced AWS Account Synchronization Notifications and Events</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-account-synchronizati</link>
    <description><![CDATA[<div class="p">April 20, 2021, Workload Security—Updated Trend Cloud One - Endpoint &amp; Workload Security
               to provide more information during AWS account synchronization, with banner notifications
               after starting synchronization (Computers &gt; Right- or- double-click an AWS account
               &gt; Synchronize Now) and events created when synchronization is requested or completed
               (Events &amp; Reports &gt; System Events).</div>]]></description>
    <pubDate>Tue, 20 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-account-synchronizati</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved handling of Anti-Malware Scan timeouts for scheduled tasks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-handling-of-anti-malware</link>
    <description><![CDATA[<div class="p">April 20, 2021, Workload Security—Anti-Malware Scan scheduled tasks that had timed
               out were sometimes starting again instead of triggering a "Scheduled Task Skipped"
               event as expected.</div>]]></description>
    <pubDate>Tue, 20 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-handling-of-anti-malware</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Trend Micro transitions Endpoint &amp; Workload Security offering to AWS Marketplace</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-transitions-endpoint</link>
    <description><![CDATA[<div class="p">April 21, 2021, Workload Security—As of 2021-04-21, Trend Micro will no longer offer
               Trend Cloud One - Endpoint &amp; Workload Security through the Azure Marketplace for new
               customers. Existing subscribers are not affected by this change and can continue to
               use and pay for the service through the Azure Marketplace. If you are a new customer
               looking to leverage pay-as-you-go hourly billing, please see <a class="xref" href="https://aws.amazon.com/marketplace/pp/B01LXMNGHB" target="_blank">Trend Cloud One</a> on the AWS Marketplace.</div>]]></description>
    <pubDate>Wed, 21 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-transitions-endpoint</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Domain Filtering Feature Re-enabled in Network Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-domain-filtering-feature</link>
    <description><![CDATA[<div class="p">April 22, 2021, Network Security—Domain filtering: Enhancements to FQDN are included
               in this release and this feature has been re-enabled. You can now create and manage
               a list of fully qualified domain names (FQDNs) with defined access to your environment
               from the Network Security interface. To use domain filtering, you must deploy version
               2021.4.0.10991 of the appliance. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Domain_Filtering-#manage-your-permit-list-using-the-gui" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 22 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-domain-filtering-feature</guid>
    <category>Network Security</category>
</item>
<item>
    <title>End of Complimentary Preview for Trend Micro Cloud One Services on AWS Marketplace</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-end-of-complimentary-preview-for-t</link>
    <description><![CDATA[<div class="p">April 26, 2021, Billing and Subscription Management—As of 2021-05-03, Trend Micro
               will end the complimentary preview period for Application Security, Container Security,
               File Storage Security, and Conformity on AWS Marketplace. Billing for these services
               will start from May 3rd for customers subscribed to <a class="xref" href="https://aws.amazon.com/marketplace/pp/B01LXMNGHB" target="_blank">Trend Micro Cloud One</a>. </div>]]></description>
    <pubDate>Mon, 26 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-end-of-complimentary-preview-for-t</guid>
    <category>Billing and Subscription Management</category>
</item>
<item>
    <title>Container Security policies now support Smart Check checklist rules integration</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-policies-now-su</link>
    <description><![CDATA[<div class="p">April 26, 2021, Container Security—Container Security policies can now include rules
               that block or log images based on results from Smart Check checklists. Checklists
               are pre-defined sets of rules that determine how well an image adheres to common compliance
               standards (PCI-DSS v2, NIST 800-190, and HIPAA). For details, see the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-policy-create-#checklist" target="_blank">Container Security help</a>.</div>]]></description>
    <pubDate>Mon, 26 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-policies-now-su</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Heartbeat Interval settings phased out for new tenants in Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-heartbeat-interval-settings-phased</link>
    <description><![CDATA[<div class="p">April 26, 2021, Workload Security—For new tenants, the following Trend Cloud One -
               Endpoint &amp; Workload Security settings will no longer appear in the Administration
               tab:</div><ul class="ul" id="whatsnew_13e_e42_360__ul_469_edb">
<li class="li">Heartbeat Interval</li>
<li class="li">Number of Heartbeats that can be missed before an alert is raised</li>
</ul><div class="p">For existing tenants, the settings above will be gradually removed starting May 26,
               2021.</div><div class="p">These changes are due to a new agent-manager communication design, and should have
               minimal impact on users. Policy changes will still be applied immediately, and the
               Trend Cloud One - Endpoint &amp; Workload Security console can still trigger requests
               for agents to get any accumulated events on demand as required.</div>]]></description>
    <pubDate>Mon, 26 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-heartbeat-interval-settings-phased</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Introducing Scan Activity Page for File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-introducing-scan-activity-page-for</link>
    <description><![CDATA[<div class="p">April 27, 2021, File Storage Security—The Scan Activity page has been added, which
               includes the Scan History chart and its scan counter, so users can see a summary of
               scan results from within File Storage Security. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-dashboard" target="_blank">View scan results on the console Scan Activity page</a>.</div>]]></description>
    <pubDate>Tue, 27 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-introducing-scan-activity-page-for</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved User Experience with Tour Guide Dialog Box Hover Prevention</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-user-experience-with-tour</link>
    <description><![CDATA[<div class="p">April 29, 2021, File Storage Security—Prevent auto-sliding when the cursor is hovering
               on the tour guide dialog box.</div>]]></description>
    <pubDate>Thu, 29 Apr 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-user-experience-with-tour</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>New &quot;Deep Security Migration&quot; role for seamless software migration to Trend Cloud One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-deep-security-migration-role-f</link>
    <description><![CDATA[<div class="p">May 04, 2021, Workload Security—Added a predefined "Deep Security Migration" role
               containing all rights required to migrate Deep Security software over to Trend Cloud
               One - Endpoint &amp; Workload Security.</div>]]></description>
    <pubDate>Tue, 04 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-deep-security-migration-role-f</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved agent package import and download process for better user experience</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-agent-package-import-and</link>
    <description><![CDATA[<div class="p">May 04, 2021, Workload Security—When you imported and then deleted an agent package
               from Trend Cloud One - Endpoint &amp; Workload Security, direct downloads sometimes failed
               afterwards.</div>]]></description>
    <pubDate>Tue, 04 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-agent-package-import-and</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity Release Notes for Latest Updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-release-notes-for-lates</link>
    <description><![CDATA[<div class="p">May 06, 2021, Conformity—Please visit the <a class="xref" href="https://www.cloudconformity.com/help/Release%20Notes/release-notes.html" target="_blank">Conformity Release Notes</a> page for Conformity updates.</div>]]></description>
    <pubDate>Thu, 06 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-release-notes-for-lates</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Default Real-Time Scan Configuration with Behavior Monitoring and Predictive Machine Learning</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-default-real-time-scan-co</link>
    <description><![CDATA[<div class="p">May 06, 2021, Workload Security—Updated Endpoint &amp; Workload Security's Default Real-Time
               Scan Configuration (Computers &gt; Details &gt; Anti-Malware &gt; General &gt; Real-Time Scan
               &gt; Malware Scan Configuration) to enable Behavior Monitoring and Predictive Machine
               Learning by default.</div><div class="p">Newer agents (20.0.0.1559 and higher on Windows, and 20.0.0-1822 and higher on Linux)
               will have "Use custom actions" set to "Pass" by default, and will log Anti-Malware
               Events. Older agents will have Behavior Monitoring turned off if their Possible Malware
               "action to take" is set to "Pass."</div>]]></description>
    <pubDate>Thu, 06 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-default-real-time-scan-co</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Security and Performance in Network Security Virtual Appliance Version 2021.4.1</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-and-performance</link>
    <description><![CDATA[<div class="p">May 06, 2021, Network Security—Network Security virtual appliance version 2021.4.1.11004
               includes important security and performance enhancements.</div>]]></description>
    <pubDate>Thu, 06 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-and-performance</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Improved Filter Searching Capabilities for Enhanced Search Precision</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-filter-searching-capabili</link>
    <description><![CDATA[<div class="p">May 06, 2021, Network Security—Filter searching enhancements: API and UI enhancements
               to filter searching enable you to build a compound query expression to narrow down
               your search results according to multiple criteria. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Filters_overview-#search-filters" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 06 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-filter-searching-capabili</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Gateway Load Balancer Preview Deployment Options Available for Network Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gateway-load-balancer-preview-depl</link>
    <description><![CDATA[<div class="p">May 06, 2021, Network Security—Gateway Load Balancer: A preview version of deployment
               options using a Gateway Load Balancer are now available. The Gateway Load Balancer
               service allows you to deploy and manage Network Security virtual appliances seamlessly
               in a centralized environment. Virtual appliance version 2021.4.1.11004 is required
               for this feature. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Choose%20a%20deployment%20option-" target="_blank">Learn more</a> about these preview deployment options.</div>]]></description>
    <pubDate>Thu, 06 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gateway-load-balancer-preview-depl</guid>
    <category>Network Security</category>
</item>
<item>
    <title>PostScanActionTagLambda now tags objects without issues as &#x27;no issues found&#x27;</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-postscanactiontaglambda-now-tags-o</link>
    <description><![CDATA[<div class="p">May 10, 2021, File Storage Security—The PostScanActionTagLambda now tags object without
               issues with `no issues found`, instead of `clean`.</div><div class="p">To migrate from the breaking change, modify your downstream workflow that checks `fss-scan-result`
               tag.</div><div class="p">For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-scan-tag-overview-#ViewTag" target="_blank">Monitor scan results</a>.</div>]]></description>
    <pubDate>Mon, 10 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-postscanactiontaglambda-now-tags-o</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved Scan History chart functionality for enhanced user experience</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-scan-history-chart-functi</link>
    <description><![CDATA[<div class="p">May 10, 2021, File Storage Security—Prevent API requests when the Scan History chart
               is loading.</div><div class="p">The Scan History chart prevents scrolling the timeline past the current time or later
               than 30 days ago.</div><div class="p">The Scan History chart displays a minimum bar size for an item with small values to
               ensure that the bar is still visible.</div>]]></description>
    <pubDate>Mon, 10 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-scan-history-chart-functi</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved Software Changes Detected Warnings in Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-software-changes-detected</link>
    <description><![CDATA[<div class="p">May 11, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security sometimes
               created "Software Changes Detected" warnings (in the Alerts tab) for software that
               was already allowed, and sometimes encountered alerts which would reappear after a
               user had already resolved them.</div>]]></description>
    <pubDate>Tue, 11 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-software-changes-detected</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Scan trigger issue resolved for folder creation in scanning bucket</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scan-trigger-issue-resolved-for-fo</link>
    <description><![CDATA[<div class="p">May 20, 2021, File Storage Security—Fixed the issue where creating a folder in the
               scanning bucket would trigger a scan.</div>]]></description>
    <pubDate>Thu, 20 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scan-trigger-issue-resolved-for-fo</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Streamlined Onboarding Process for Container Security Subscription Users</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-streamlined-onboarding-process-for</link>
    <description><![CDATA[<div class="p">May 21, 2021, Container Security—In order to improve the onboarding experience with
               Container Security, you will no longer need to acquire an activation code and install
               or upgrade Smart Check with this code if you have a current subscription to the service.
               Simply enroll your Smart Check installation with a valid API key, as you would before,
               and you can use Smart Check without limitation.</div>]]></description>
    <pubDate>Fri, 21 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-streamlined-onboarding-process-for</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Improved Scan History chart display for Safari browser</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-scan-history-chart-displa</link>
    <description><![CDATA[<div class="p">May 21, 2021, File Storage Security—Fixed the issue where the Scan History chart used
               an incorrect aspect ratio for the latest version of the Safari web browser.</div>]]></description>
    <pubDate>Fri, 21 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-scan-history-chart-displa</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved stack creation process reduces timeout errors</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-stack-creation-process-re</link>
    <description><![CDATA[<div class="p">May 26, 2021, File Storage Security—After adding a stack in the console, the waiting
               time is increased, which reduces the chance of getting a timeout error.</div>]]></description>
    <pubDate>Wed, 26 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-stack-creation-process-re</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Container Security enhances continuous compliance, accurate billing, and aligns with Kubernetes standards</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-enhances-contin</link>
    <description><![CDATA[<div class="p">May 27, 2021, Container Security—Container Security now extends the protection of
               your containers to the post-deployment phase. With the new continuous compliance feature,
               Container Security ensures that running containers continue to conform to the policy
               you've defined. If there are changes to the policy after the initial deployment or
               if new vulnerabilities are discovered, Container Security can take action to mitigate
               the problem. To take advantage of this feature, <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-policy-create-" target="_blank">update your policies with the new continuous compliance settings</a>.</div><div class="p">Container Security now monitors the number of nodes and serverless containers that
               it's protecting, to allow for accurate billing, as described in <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--billing-and-subscription-management-billing-pricing-" target="_blank">About billing and pricing</a>.</div><div class="p">This update also aligns the labels for Container Security templates with Kubernetes
               standards. This change means that to upgrade to this release, you must uninstall and
               reinstall the Helm chart, as detailed in the <a class="xref" href="https://github.com/trendmicro/cloudone-container-security-helm" target="_blank">Container Security Helm Chart</a>.</div>]]></description>
    <pubDate>Thu, 27 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-enhances-contin</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Maintenance notifications now consolidated in Trend Cloud One maintenance page</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-maintenance-notifications-now-cons</link>
    <description><![CDATA[<div class="p">May 28, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security maintenance
               notifications have been moved to the Trend Cloud One maintenance page to consolidate
               all maintenance info in one place. The <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central-" target="_blank">Trend Cloud One maintenance page</a> has an RSS feed that you can use to get notifications about any upcoming maintenance.</div>]]></description>
    <pubDate>Fri, 28 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-maintenance-notifications-now-cons</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Check ServiceNow SecOps Module for Viewing Checks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-check-servicenow-secops-module-for</link>
    <description><![CDATA[<div class="p">May 31, 2021, Conformity—View Checks in ServiceNow SecOps Module.</div>]]></description>
    <pubDate>Mon, 31 May 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-check-servicenow-secops-module-for</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Domain Filtering with Custom Ports for FQDN Exceptions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-domain-filtering-with-cus</link>
    <description><![CDATA[<div class="p">June 03, 2021, Network Security—Custom ports for fully qualified domain name (FQDN)
               exceptions: You can specify as many as 20 associated ports to the fully qualified
               domain names in your Domain Filtering exceptions list. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Domain_Filtering-#manage-your-permit-list-using-the-gui" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 03 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-domain-filtering-with-cus</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Gateway Load Balancer now generally available for Network Security deployment</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gateway-load-balancer-now-generall</link>
    <description><![CDATA[<div class="p">June 03, 2021, Network Security—Gateway Load Balancer: The deployment options using
               a Gateway Load Balancer are now generally available. Learn more about <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Choose%20a%20deployment%20option-" target="_blank">deploying Gateway Load Balancer for Network Security in AWS</a>.</div>]]></description>
    <pubDate>Thu, 03 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gateway-load-balancer-now-generall</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Expanded asset protection list available in Network Security, Azure asset support coming soon</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-expanded-asset-protection-list-ava</link>
    <description><![CDATA[<div class="p">June 03, 2021, Network Security—Protectable assets: A more detailed list of which
               assets can be or are currently protected by Network Security is available from the
               Network → Assets page. Azure assets are not yet supported. To request access for this
               feature, <a class="xref" href="mailto:allofcloudonenetworksecurityassetspreview@trendmicro.com" target="_blank">contact us</a>.</div>]]></description>
    <pubDate>Thu, 03 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-expanded-asset-protection-list-ava</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Apply Configuration Changes to Multiple Filters Simultaneously</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-apply-configuration-changes-to-mul</link>
    <description><![CDATA[<div class="p">June 03, 2021, Network Security—Apply the same configuration changes to multiple filters:
               You can use the GUI and APIs to apply specific filter policy overrides to as many
               as 100 filters at one time. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Customize_filter_settings_GUI-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 03 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-apply-configuration-changes-to-mul</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Network Security now available in Azure Marketplace</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-network-security-now-available-in</link>
    <description><![CDATA[<div class="p">June 10, 2021, Network Security—Azure public release: Network Security for Azure is
               now a generally available public offering on Azure Marketplace. Learn more about <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Azure_GettingStarted-" target="_blank">deploying Network Security in Azure</a>.</div>]]></description>
    <pubDate>Thu, 10 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-network-security-now-available-in</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Scanner Lambda publishes detailed skip codes for file scan results</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanner-lambda-publishes-detailed</link>
    <description><![CDATA[<div class="p">June 15, 2021, File Storage Security—Scanner Lambda now publishes scan detail codes
               about skipped scans in scan result and ScanResultTopic.</div><div class="p">The new field helps you make decisions in the downstream workflows on how to handle
               the scanned file.</div><div class="p">NOTE: If your workflows monitor these detail codes with CloudWatch logs,</div><div class="p">then, before October 1, 2021, use the new field in scan results instead.</div><div class="p">For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-scan-result-format-" target="_blank">Scan result format</a>.</div>]]></description>
    <pubDate>Tue, 15 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanner-lambda-publishes-detailed</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>BucketListenerLambda now complies with Lambda function public access prohibition rule</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bucketlistenerlambda-now-complies</link>
    <description><![CDATA[<div class="p">June 15, 2021, File Storage Security—Fixed the issue where BucketListenerLambda violates
               the rule <a class="xref" href="https://docs.aws.amazon.com/config/latest/developerguide/lambda-function-public-access-prohibited.html" target="_blank">Lambda function policies should prohibit public access</a> from AWS Security Hub.</div>]]></description>
    <pubDate>Tue, 15 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bucketlistenerlambda-now-complies</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Network Security introduces free tier with 10GB monthly traffic inspection</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-network-security-introduces-free-t</link>
    <description><![CDATA[<div class="p">June 15, 2021, Network Security—Free tier offering: Network Security now offers 10GB
               of free traffic inspection each month with Pay as You Go billing. With this free tier
               offering, you can get started with Network Security at no charge. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Pay_as_you_Go_billing-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Tue, 15 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-network-security-introduces-free-t</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Enhanced PostScanActionTagLambda now provides detailed scan information for S3 objects</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-postscanactiontaglambda-n</link>
    <description><![CDATA[<div class="p">June 18, 2021, File Storage Security—PostScanActionTagLambda has two new tags, `fss-scan-detail-code`
               and `fss-scan-detail-message`,</div><div class="p">providing more detail about scans for the S3 object, especially scans that were skipped.</div><div class="p">The new tags help you make decisions in the downstream workflows on how to handle
               the scanned file.</div><div class="p">NOTE: If your workflows monitor these detail codes with CloudWatch logs,</div><div class="p">then, before October 1, 2021, use the new field in</div><a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-scan-result-format-" target="_blank">scan results</a><div class="p">or the new tags instead.</div><div class="p">For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-scan-tag-overview-#ViewTag" target="_blank">View Tags</a>.</div>]]></description>
    <pubDate>Fri, 18 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-postscanactiontaglambda-n</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Discontinued &quot;What&#x27;s New in Workload Security&quot; RSS Feed, Subscribe to Trend Cloud One Updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-discontinued-whats-new-in-workload</link>
    <description><![CDATA[<div class="p">June 21, 2021, Workload Security—The "What's New in Workload Security" RSS feed will
               no longer receive notifications. For details on updates and new features for Trend
               Cloud One - Endpoint &amp; Workload Security, or any other Trend Cloud One services, please
               subscribe to the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--what__s-new-trend-micro-cloud-one-updates.rss" target="_blank">What's New in Trend Cloud One RSS feed</a>.</div>]]></description>
    <pubDate>Mon, 21 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-discontinued-whats-new-in-workload</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved Smart Check Performance prevents duplicate registry scans</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-smart-check-performance-p</link>
    <description><![CDATA[<div class="p">June 22, 2021, Container Security—Smart Check performance has been improved. When
               a full registry scan is requested, Smart Check now ensures that a duplicate scan is
               not already in progress. A scan is considered a duplicate if the Registry, Repository,
               Tag, and Digest values match, and the scan is pending or in progress. If the scan
               is a duplicate, the new scan is not queued and the existing scan details are returned
               in the response body of the request.</div>]]></description>
    <pubDate>Tue, 22 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-smart-check-performance-p</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Enhancement: Removal of CopyZipsDestBucket and S3BucketPrefix for Improved Stack Deployment</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhancement-removal-of-copyzipsdes</link>
    <description><![CDATA[<div class="p">June 25, 2021, File Storage Security—Removes `CopyZipsDestBucket` and related resources
               in scanner stacks and storage stacks. Also removes `S3BucketPrefix` parameter, which
               is used as the prefix of `CopyZipsDestBucket` name. This functionality requires a
               stack update.</div><div class="p">This update enables customers who do not have permissions to create S3 buckets to
               deploy their stacks (since it removes the need to create `CopyZipsDestBucket`).</div>]]></description>
    <pubDate>Fri, 25 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhancement-removal-of-copyzipsdes</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Azure Storage Container Scanner Stacks Deployment Now Supported</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-storage-container-scanner-st</link>
    <description><![CDATA[<div class="p">June 28, 2021, File Storage Security—The ability to deploy scanner stacks and storage
               stacks to Azure has been added to the console, allowing scanning of files uploaded
               to an Azure storage container.</div>]]></description>
    <pubDate>Mon, 28 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-storage-container-scanner-st</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>File Storage Security now offers Events API for AWS stack scan results retrieval</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-offers-e</link>
    <description><![CDATA[<div class="p">June 28, 2021, File Storage Security—Events API is now available, allowing API users
               to retrieve their File Storage Security scan results of AWS stacks. For more details,
               <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-api-reference-tag-Events" target="_blank">click here</a>.</div>]]></description>
    <pubDate>Mon, 28 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-offers-e</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Azure Stacks APIs Preview Release for File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-stacks-apis-preview-release</link>
    <description><![CDATA[<div class="p">June 28, 2021, File Storage Security—Stacks APIs for managing Azure stacks are now
               available in a preview release, allowing API users to create, describe, list and delete
               Azure stacks on File Storage Security. For more details, <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-api-reference-tag-Stack" target="_blank">click here</a>.</div>]]></description>
    <pubDate>Mon, 28 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-stacks-apis-preview-release</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Protect SAP Deployments with Trend Cloud One Endpoint &amp; Workload Security Integration</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-protect-sap-deployments-with-trend</link>
    <description><![CDATA[<div class="p">June 30, 2021, Workload Security—You can now protect your SAP deployments using Trend
               Cloud One - Endpoint &amp; Workload Security, helping to secure critical information from
               attack, including a wide variety of threats such as malware, cross-site scripting
               and SQL injection. Trend Cloud One - Endpoint &amp; Workload Security scans content uploaded
               to the SAP NetWeaver technology platform to determine its true type and reports this
               to SAP systems via the NetWeaver-VSI interface. Content scanning protects against
               possible malicious script content that might be embedded or disguised inside documents.
               SAP administrators can then set policy according to which document types should be
               allowed. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-scanner" target="_blank">Integrate with SAP NetWeaver</a>.</div>]]></description>
    <pubDate>Wed, 30 Jun 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-protect-sap-deployments-with-trend</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Fail Open High Availability Preview for AWS Deployment with Gateway Load Balancer</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fail-open-high-availability-previe</link>
    <description><![CDATA[<div class="p">July 01, 2021, Network Security—High availability enhancement: A preview version of
               fail open high availability was added to the AWS deployment to inspect inbound internet
               traffic with Gateway Load Balancer. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-GWLB_CFdeploy1-#high-availability-overview" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 01 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fail-open-high-availability-previe</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Enhanced Filter Searching Capabilities for Network Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-filter-searching-capabili</link>
    <description><![CDATA[<div class="p">July 01, 2021, Network Security—Filter searching enhancements: Filter searching enhancements
               enable you to further refine your compound query expressions according to the latest
               active threats and when the filter was released or modified. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Filters_overview-#search-filters" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 01 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-filter-searching-capabili</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Improved Reset Functionality for Anti-Malware Real-Time Scan Configuration Policies</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-reset-functionality-for-a</link>
    <description><![CDATA[<div class="p">July 06, 2021, Workload Security—Anti-Malware Real-Time Scan Configuration policies
               sometimes did not reset to their inherited value properly.</div>]]></description>
    <pubDate>Tue, 06 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-reset-functionality-for-a</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Smart Feedback now enabled to rapidly identify and address new threats</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-smart-feedback-now-enabled-to-rapi</link>
    <description><![CDATA[<div class="p">July 06, 2021, Workload Security—Smart Feedback is enabled by default for new accounts.
               Smart Feedback shares protected threat information with the Smart Protection Network
               (SPN), allowing Trend Micro to rapidly identify and address new threats. For more
               information, please see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-smart-protection-" target="_blank">Smart Protection in Trend Cloud One - Endpoint &amp; Workload Security</a>.</div>]]></description>
    <pubDate>Tue, 06 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-smart-feedback-now-enabled-to-rapi</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced File Security Scans for AWS S3 Uploads</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-security-scans-for-a</link>
    <description><![CDATA[<div class="p">July 06, 2021, File Storage Security—Fixed the issue where updating a stack with a
               template caused files uploaded to AWS S3 buckets to not be scanned and report an `invalid
               license status` message in the scan results. This functionality requires a stack update.</div>]]></description>
    <pubDate>Tue, 06 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-security-scans-for-a</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved reliability when disabling microservices in Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-reliability-when-disablin</link>
    <description><![CDATA[<div class="p">July 06, 2021, Workload Security—After disabling microservices using console commands,
               Trend Cloud One - Endpoint &amp; Workload Security sometimes failed to restart.</div>]]></description>
    <pubDate>Tue, 06 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-reliability-when-disablin</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved Trend Vision One registration under System Settings prevents account permissions issue</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-trend-vision-one-registra</link>
    <description><![CDATA[<div class="p">July 06, 2021, Workload Security—An account permissions issue sometimes caused Trend
               Vision One registration to fail or display the wrong status (under Administration
               &gt; System Settings &gt; Trend Micro One).</div>]]></description>
    <pubDate>Tue, 06 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-trend-vision-one-registra</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved Smart Check Performance for Registry Scans</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-smart-check-performance-f</link>
    <description><![CDATA[<div class="p">July 08, 2021, Container Security—Smart Check performance has been improved in <a class="xref" href="https://github.com/deep-security/smartcheck-helm/releases/tag/1.2.67" target="_blank">1.2.67</a>. When a full registry scan is requested, Smart Check now checks if the image has
               already been scanned within the <a class="xref" href="https://github.com/deep-security/smartcheck-helm/blob/1.2.67/values.yaml#L393" target="_blank">rescanProhibitedDuration</a> (default = 12 hours). An image is the same if the Registry, Repository, Tag, and
               Digest values match. If already scanned, the new scan is not queued and the completed
               scan details are returned in the response body of the request. If you want to force
               scan the image again, you can queue one using the <a class="xref" href="https://deep-security.github.io/smartcheck-docs/api/index.html#operation/createScan" target="_blank">createScan API</a>.</div>]]></description>
    <pubDate>Thu, 08 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-smart-check-performance-f</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Statistics API now supports AWS provider query parameter with Azure support coming soon</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-statistics-api-now-supports-aws-pr</link>
    <description><![CDATA[<div class="p">July 08, 2021, File Storage Security—Statistics API now supports `provider` query
               parameter. Currently it only allows one value, `aws`.</div><div class="p">Support for `azure` in preview will be added later.</div><div class="p">NOTE: API users that don't want statistics results from both AWS and Azure scans when
               Azure scan statistics is supported</div><div class="p">should add `provider=aws` in the query parameter to focus on AWS results only.</div><div class="p">For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-api-reference-tag-Statistics#operation-listScanStatistics" target="_blank">List scan statistics</a>.</div>]]></description>
    <pubDate>Thu, 08 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-statistics-api-now-supports-aws-pr</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>XDR Network Isolation now available in Deep Security Agent 20.0.0</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-xdr-network-isolation-now-availabl</link>
    <description><![CDATA[<div class="p">July 08, 2021, Workload Security—This release adds XDR Network Isolation support to
               Deep Security Agent version 20.0.0-2593 and later. Following Trend Vision One onboarding,
               you can now isolate potentially compromised endpoints from the rest of your network.
               For more information see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-network-isolation-" target="_blank">Trend Vision One (XDR) Network Isolation</a>.</div>]]></description>
    <pubDate>Thu, 08 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-xdr-network-isolation-now-availabl</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity enhances compliance with new Azure rules and AWS framework updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhances-compliance-wit</link>
    <description><![CDATA[<ul class="ul" id="whatsnew_c16_d06_c80__ul_83b_ca4">
<li class="li">Added Azure rules for AusGov ISM standard.</li>
<li class="li">We’ve also updated AWS Well-Architected Framework to the March 2021 version.</li>
<li class="li">You can now track and view the ‘apply profile’ events via the RTM dashboard or query
                  them via the public events API by using ‘account.apply.profile’ as the          event
                  name.</li>
<li class="li">Checks returned from Template Scanner will now attempt to include logicalResourceId
                  property in addition to usual properties.</li>
<li class="li">Updated the Jira Communications Channel to clear out existing fields when selecting
                  a new 'Project' and 'Issue Type'.</li>
</ul>]]></description>
    <pubDate>Fri, 09 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhances-compliance-wit</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Integrity Monitoring Baseline Removed from Workload Security Console for Improved Performance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-integrity-monitoring-baseline-remo</link>
    <description><![CDATA[<div class="p">July 12, 2021, Workload Security—As baselines have grown larger and workloads have
               become more dynamic, the ability to support the Integrity Monitoring baseline in the
               Trend Cloud One - Endpoint &amp; Workload Security console has become increasingly challenging.</div><div class="p">Trend Micro is committed to evolving the design of Integrity Monitoring to meet the
               performance and operational needs of customers. Through discussions with customers,
               it was determined that in its current form, this feature was not delivering the value
               to offset the performance and operational overhead required to maintain this data.</div><div class="p">The first step in this process is to remove the Integrity Monitoring baseline capability
               from the Trend Cloud One - Endpoint &amp; Workload Security console. This means that the
               View Baseline, Trusted Source Tagging, and Integrity Monitoring Baseline Report will
               no longer be available. For customers who subscribed after July 12, 2021 and are using
               agent version 20.0.0-2593 or later, the baseline is already removed. For customers
               who subscribed before that date, Trend Micro will not remove the baseline until January
               1, 2022.</div><div class="p">To view the Integrity Monitoring baseline, <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-diagnostic-#Deep2" target="_blank">generate an agent diagnostic package</a>.</div><div class="p">For more information, see the following: <a class="xref" href="https://success.trendmicro.com/en-us/solution/ka-0011454" target="_blank">Removal of the Integrity Monitoring "view baseline" option from Trend Cloud One -
                  Endpoint &amp; Workload Security</a> and <a class="xref" href="https://success.trendmicro.com/en-us/solution/ka-0011986" target="_blank">Removal of the Integrity Monitoring Baseline Report from Trend Cloud One - Endpoint
                  &amp; Workload Security</a></div>]]></description>
    <pubDate>Mon, 12 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-integrity-monitoring-baseline-remo</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Transition to New Email-Based Sign In for Trend Cloud One Users</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-transition-to-new-email-based-sign</link>
    <description><![CDATA[<div class="p">July 13, 2021, Workload Security—Trend Cloud One will soon be phasing in a new account
               and user management system, with an updated Sign In page.</div><div class="p">Users who sign up for Trend Cloud One after the release of this new system will only
               require their Email and Password to log in through the Email Address Sign In.</div><div class="p">Existing Trend Cloud One users must continue to use their current credentials (Account,
               Username, and Password) to log in through the Account &amp; Username Sign In. No action
               is required for current customers. Existing accounts will be transitioned to the new
               email-based sign in at a later date.</div>]]></description>
    <pubDate>Tue, 13 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-transition-to-new-email-based-sign</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Lambda alias now points to latest version after stack update</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-alias-now-points-to-latest</link>
    <description><![CDATA[<div class="p">July 19, 2021, File Storage Security—Fixed the issue where updating a stack with a
               template caused Lambda alias `TM-FSS-Managed` to point to the previous version instead
               of the latest one. This functionality requires a stack update.</div>]]></description>
    <pubDate>Mon, 19 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-alias-now-points-to-latest</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Azure added to Statistics and Events API for File Storage Security scan results retrieval</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-added-to-statistics-and-even</link>
    <description><![CDATA[<div class="p">July 19, 2021, File Storage Security—Statistics and events API will soon support `azure`
               in `provider` parameter in a preview release,</div><div class="p">allowing API users to retrieve their File Storage Security scan results of Azure stacks.</div>]]></description>
    <pubDate>Mon, 19 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-added-to-statistics-and-even</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Extended Maintenance Period for Older Trend Cloud One Accounts</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-extended-maintenance-period-for-ol</link>
    <description><![CDATA[<div class="p">July 22, 2021, Workload Security—The scheduled maintenance period for Trend Cloud
               One accounts created before 2018-10-31 is being extended. Accounts that have already
               undergone scheduled maintenance will not be impacted by this extension. Any accounts
               that still require maintenance will have a maintenance window assigned to them before
               2021-12-30.</div><div class="p">For more information see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central-" target="_blank">Trend Cloud One Maintenance</a>.</div>]]></description>
    <pubDate>Thu, 22 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-extended-maintenance-period-for-ol</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced collect-logs.sh script in Smart Check for targeted core file collection</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-collect-logssh-script-in</link>
    <description><![CDATA[<div class="p">July 27, 2021, Container Security—The collect-logs.sh script has been improved in
               Smart Check <a class="xref" href="https://github.com/deep-security/smartcheck-helm/releases/tag/1.2.68" target="_blank">release 1.2.68</a>. The script now allows you to specify the application name and namespace as options,
               and it collects core files from malware-scan pods.</div>]]></description>
    <pubDate>Tue, 27 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-collect-logssh-script-in</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Improved Performance and Synchronization for Smart Check in Container Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-performance-and-synchroni</link>
    <description><![CDATA[<div class="p">July 27, 2021, Container Security—Smart Check performance has been improved in <a class="xref" href="https://github.com/deep-security/smartcheck-helm/releases/tag/1.2.68" target="_blank">1.2.68</a>. Registries can only perform one full registry sync/scan at a time. If multiple concurrent
               requests are made to perform a full registry sync/scan for the same registry, then
               only one is be executed.</div>]]></description>
    <pubDate>Tue, 27 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-performance-and-synchroni</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Bug Fixed for Full Registry Scan with Long Image Names in Container Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fixed-for-full-registry-scan-w</link>
    <description><![CDATA[<div class="p">July 27, 2021, Container Security—Fixed a bug where images with long names were not
               queued when performing a full registry scan in <a class="xref" href="https://github.com/deep-security/smartcheck-helm/releases/tag/1.2.68" target="_blank">1.2.68</a>.</div>]]></description>
    <pubDate>Tue, 27 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fixed-for-full-registry-scan-w</guid>
    <category>Container Security</category>
</item>
<item>
    <title>New key added to scan result for File Storage Security enhancement</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-key-added-to-scan-result-for-f</link>
    <description><![CDATA[<div class="p">July 27, 2021, File Storage Security—The scan result now has a new key, `xamz_request_id`
               with an empty string value.</div><div class="p">We will soon pass the request ID of S3 to that field.</div>]]></description>
    <pubDate>Tue, 27 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-key-added-to-scan-result-for-f</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity Enhancements: Improved Communication Channels, Cloud One Integration, and Bug Fixes</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-improved-c</link>
    <description><![CDATA[<div class="p">July 28, 2021, Conformity—The following updates were released to Conformity on 28th
               July 2021.</div><div class="p">Communication Channels Update</div><ul class="ul" id="whatsnew_2e4_9a9_ab3__ul_937_37a">
<li class="li">Webhook: Updated the Webhook Communication Channel to send checks that have been deleted
                  due to a user removing/deleting a resource. These checks delivered will have an additional
                  field "isDeleted: true" to differentiate them from the current checks being sent via
                  webhook.</li>
</ul><ul class="ul" id="whatsnew_2e4_9a9_ab3__ul_f51_738">
<li class="li">Jira: Updated the Jira Communication Channel 'Create' and ‘Update' screens to no longer
                  support swapping to an alternative connection type (OAuth or API token) to reduce
                  the risk of breaking a successfully configured channel.</li>
</ul><div class="p">Cloud One Users</div><ul class="ul" id="whatsnew_2e4_9a9_ab3__ul_787_193">
<li class="li">With SSOv2 can now access Conformity via Cloud One UI. See our <a class="xref" href="https://www.cloudconformity.com/help/public-api/api-keys.html" target="_blank">help page on SSoV2 Public API</a>.</li>
<li class="li">Will receive account update emails if they have a valid email address in Conformity</li>
</ul><div class="p">Scan a Profile with Template Scanner</div><ul class="ul" id="whatsnew_2e4_9a9_ab3__ul_288_5c4">
<li class="li">Users without Admin privileges can now select and scan a Profile in Template Scanner
                  via Conformity UI or API by calling the `/profiles` API.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_2e4_9a9_ab3__ul_e49_186">
<li class="li">Fixed a bug to reduce the number of failed Schedule Reports generation.</li>
<li class="li">Fixed a bug to return the correct API response when a user typed a value while filtering
                  regions.</li>
<li class="li">Fixed a bug to add an account name and account environment to the body of the system-disabled
                  Conformity bot notification email.</li>
<li class="li">Fixed a bug with Template Scanner API Response body to include the actual accountId
                  in the `account` field only when the `accountId` field is passed in the request body.</li>
<li class="li">Fixed a bug to successfully process intrinsic functions as arguments of '!Join' in
                  the Template Scanner.</li>
<li class="li">Fixed a bug where Reports generated with individual checks did not display the Total
                  counts on the PDF report correctly.</li>
</ul><div class="p">Custom Policy Updates</div><ul class="ul" id="whatsnew_2e4_9a9_ab3__ul_b0d_d88">
<li class="li">There is no change to the custom policy as a result of the new deployment. The current
                  custom policy version is 1.32. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the latest custom policy</a>.</li>
</ul><div class="p">Conformity Bot Updates</div><ul class="ul" id="whatsnew_2e4_9a9_ab3__ul_91e_d3c">
<li class="li">Boosted error handling to prevent outdated or inconsistent checks.</li>
<li class="li">Improvements to prevent Conformity Bot from running longer than expected for European
                  accounts.</li>
</ul><div class="p">Rule Updates</div><ul class="ul" id="whatsnew_2e4_9a9_ab3__ul_7bd_1cc">
<li class="li">EC2-072 - EC2 Instance Not In Public Subnet: This rule has been updated to allow exceptions
                  based on EC2 Instances by name matched with a regex expression pattern.</li>
<li class="li">IAM-066 - AWS IAM Groups with Admin Privileges: This rule has been updated to allow
                  exceptions based on tags and resource id.</li>
</ul><div class="p">Rule Bug Fixes</div><ul class="ul" id="whatsnew_2e4_9a9_ab3__ul_a3a_47c">
<li class="li">IAM-046: Support Role: Fixed a bug where the rule generated false positives due to
                  the throttling of the attached entities.</li>
<li class="li">EKS-002: Kubernetes Cluster Version: Fixed a bug to update the rule to the latest
                  Amazon EKS Kubernetes version 1.20.</li>
<li class="li">Fixed a bug where the following rules failed to generate any checks because of inability
                  to pull data from the ECS Service:</li>
<li class="li">ECS-003: Check for Amazon ECS Service Placement Strategy</li>
<li class="li">ECS-004: Check for Fargate Platform Version</li>
<li class="li">Fixed a bug that prevents checks from being generated when there are a large number
                  of exclusions for the following rules:</li>
<li class="li">Inspector-002: Days since last Amazon Inspector run</li>
<li class="li">Inspector-003: Check for Amazon Inspector Exclusions Updated</li>
</ul>]]></description>
    <pubDate>Wed, 28 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-improved-c</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New sign-in and account system for Trend Micro Cloud One improves user management</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-sign-in-and-account-system-for</link>
    <description><![CDATA[<div class="p">July 28, 2021, General—Trend Micro Cloud One will be releasing a new sign-in and accounts
               system. The new system separates the creation of users from accounts, allowing a single
               user to more easily create and manage multiple Trend Micro Cloud One accounts for
               use across your organization, teams, and global regions.</div><div class="p">Any customers signing up for Trend Micro Cloud One after the release of these features
               will use a new Trend Micro Cloud One account. Customers who created their accounts
               prior to the release will continue to use the legacy account and sign-in. There is
               no functional change or action required for existing customers, and existing accounts
               will be transitioned at a later date.</div><div class="p">To learn more about the changes coming, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central--identity-and-account-management-c1-accounts-about" target="_blank">Changes to Trend Micro Cloud One accounts</a>.</div>]]></description>
    <pubDate>Wed, 28 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-sign-in-and-account-system-for</guid>
    <category>General</category>
</item>
<item>
    <title>Improved Maintenance Mode Activation for Application Control</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-maintenance-mode-activati</link>
    <description><![CDATA[<div class="p">July 29, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security sometimes
               took much longer than expected to turn on Maintenance Mode for Application Control
               (Computers &gt; Application Control &gt; General &gt; Maintenance Mode).</div>]]></description>
    <pubDate>Thu, 29 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-maintenance-mode-activati</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Lambda function license and pattern layer now retained during stack updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-function-license-and-patter</link>
    <description><![CDATA[<div class="p">July 29, 2021, File Storage Security—Fixed the issue where updating a stack with a
               template caused the Lambda function to lose the license and the latest pattern Lambda
               layer. This functionality requires a stack update.</div>]]></description>
    <pubDate>Thu, 29 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-function-license-and-patter</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced asset protection list now available in Network Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-asset-protection-list-now</link>
    <description><![CDATA[<div class="p">July 29, 2021, Network Security—Protectable assets: A more detailed list of which
               assets can be or are currently protected by Network Security is now generally available.
               Azure assets are not yet supported. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-protectable_assets-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 29 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-asset-protection-list-now</guid>
    <category>Network Security</category>
</item>
<item>
    <title>TLS Inspection Configuration Enhancements Available on Azure Platform</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-tls-inspection-configuration-enhan</link>
    <description><![CDATA[<div class="p">July 29, 2021, Network Security—TLS inspection configuration enhancements: TLS inspection
               for Network Security is now available on the Azure platform with appliance version
               2021.7.0.11129. In addition, users with servers running behind a load balancer can
               now configure a subnet (CIDR). <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-tls_inspection_overview-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 29 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-tls-inspection-configuration-enhan</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Azure high availability for Network Security virtual appliance auto-restart on failure</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-high-availability-for-networ</link>
    <description><![CDATA[<div class="p">July 29, 2021, Network Security—Azure high availability enhancement: A Scale Set VM
               deployment enhancement now uses Azure native recovery to automatically restart a Network
               Security virtual appliance if it fails. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Azure_high_availability-#assignmonitorrole" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 29 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-high-availability-for-networ</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Improved TLS Traffic Inspection for Trend Cloud One - Endpoint &amp; Workload Security Customers</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-tls-traffic-inspection-fo</link>
    <description><![CDATA[<div class="p">July 29, 2021, Workload Security—Updated the agent to improve TLS traffic inspection.
               This feature is being rolled out gradually, beginning with Trend Cloud One - Endpoint
               &amp; Workload Security customers.</div>]]></description>
    <pubDate>Thu, 29 Jul 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-tls-traffic-inspection-fo</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Lambda Functions in Scanner and Storage Stacks Now Deployable in VPC</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-functions-in-scanner-and-st</link>
    <description><![CDATA[<div class="p">August 02, 2021, File Storage Security—Lambda functions in scanner stacks and storage
               stacks can now be deployed in a VPC. This functionality requires a stack update.</div><div class="p">For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-aws-vpc-proxy" target="_blank">Deploy FSS in a VPC</a>.</div>]]></description>
    <pubDate>Mon, 02 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-functions-in-scanner-and-st</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity introduces Terraform Template scanning in preview for user feedback</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-terraform-te</link>
    <description><![CDATA[<div class="p">August 04, 2021, Conformity—We’re excited to share that you can now <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-sentry-" target="_blank">preview</a> Terraform Template scanning using the <a class="xref" href="https://www.cloudconformity.com/help/template-scanner.html" target="_blank">Conformity Template Scanner</a> UI as well as <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Template-scanner" target="_blank">API endpoints</a>.</div><div class="p">Find out the supported Terraform resource types for our Preview release <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Template-scanner-" target="_blank">here</a>.</div><div class="p">We will be looking forward to your feedback before we announce the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-sentry-#ga" target="_blank">General Availability</a> (official release).</div>]]></description>
    <pubDate>Wed, 04 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-terraform-te</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Sign-in and Accounts System Streamlines User Management in Trend Micro Cloud One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-sign-in-and-accounts-system-st</link>
    <description><![CDATA[<div class="p">August 04, 2021, General—Trend Micro Cloud One has released a new sign-in and accounts
               system. The new system separates the creation of users from accounts, allowing a single
               user to more easily create and manage multiple Trend Micro Cloud One accounts for
               use across your organization, teams, and global regions.</div><div class="p">Any customers signing up for Trend Micro Cloud One on or after August 4, 2021 will
               use a new Trend Micro Cloud One account. Customers who created their accounts prior
               to the release will continue to use the legacy account and sign-in. There is no functional
               change or action required for existing customers, and existing accounts will be transitioned
               at a later date.</div><div class="p">To learn more about the changes, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central--identity-and-account-management-c1-accounts-about" target="_blank">Changes to Trend Micro Cloud One accounts</a>.</div>]]></description>
    <pubDate>Wed, 04 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-sign-in-and-accounts-system-st</guid>
    <category>General</category>
</item>
<item>
    <title>AWS scanner stack now includes scannerLambdaAliasARN in details for enhanced security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-scanner-stack-now-includes-sca</link>
    <description><![CDATA[<div class="p">August 05, 2021, File Storage Security—Stacks API now provides `scannerLambdaAliasARN`
               in `details` of AWS scanner stack.</div><div class="p">For more information see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-api-reference-tag-Stack#operation-describeStackByID" target="_blank">Describe Stack</a> or <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-api-reference-tag-Stack#operation-listStacks" target="_blank">List Stacks</a>.</div>]]></description>
    <pubDate>Thu, 05 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-scanner-stack-now-includes-sca</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Cost allocation tagging now supported for AWS Marketplace purchases</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cost-allocation-tagging-now-suppor</link>
    <description><![CDATA[<div class="p">August 06, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               now supports cost allocation tagging for customers buying through AWS Marketplace,
               allowing you to track usage and cost with your AWS account using Trend Cloud One.
               For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--billing-and-subscription-management-billing-check-usage-#check-billing-and-usage-in-aws" target="_blank">Use cost allocation tags to check usage by cloud account</a>.</div>]]></description>
    <pubDate>Fri, 06 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cost-allocation-tagging-now-suppor</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Smart Check Upgrades Built-In Database to PostgreSQL 12.7 in Breaking Update</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-smart-check-upgrades-built-in-data</link>
    <description><![CDATA[<div class="p">August 09, 2021, Container Security—Smart Check includes a built-in database pod for
               demonstration purposes. For production deployments, Trend Micro recommends <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-sc-external-database-" target="_blank">using an external database</a>. In previous releases, the built-in database was PostgreSQL 9.6, which will reach
               end-of-life in November 2021. To prepare for this, in an upcoming release, Smart Check
               will be upgraded to use PostgreSQL 12.7 for its built-in database pod. The changes
               between PostgreSQL 9.6 and 12.7 mean that this will be a breaking upgrade because
               data from PostgreSQL 9.6 does not work with version 12.7. Users will need to remove
               the Smart Check application and re-install it. This change does not affect customers
               who are using PostgreSQL 10, 11, 12, or 13 as an external database. It only affects
               customers who are using the built-in database pod.</div>]]></description>
    <pubDate>Mon, 09 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-smart-check-upgrades-built-in-data</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Improved Smart Check Stability and Increased Malware-Scan Work Volume Limit</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-smart-check-stability-and</link>
    <description><![CDATA[<div class="p">August 09, 2021, Container Security—Smart Check stability has been improved in <a class="xref" href="https://github.com/deep-security/smartcheck-helm/releases/tag/1.2.69" target="_blank">release 1.2.69</a>. To avoid a malware-scan pod eviction issue, the default size limit of the malware-scan
               work volume was increased to 500 MB and extra core files are removed when the malware-scan
               service restarts after a timeout.</div>]]></description>
    <pubDate>Mon, 09 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-smart-check-stability-and</guid>
    <category>Container Security</category>
</item>
<item>
    <title>JFrog registry support added for creating new registries in SmartCheck</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-jfrog-registry-support-added-for-c</link>
    <description><![CDATA[<div class="p">August 10, 2021, Container Security—Added a JFrog registry type for creating a new
               registry in SmartCheck <a class="xref" href="https://github.com/deep-security/smartcheck-helm/releases/tag/1.2.70" target="_blank">1.2.70</a>. Refer to <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-sc-registry-add-" target="_blank">how to add a registry</a> for more details.</div>]]></description>
    <pubDate>Tue, 10 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-jfrog-registry-support-added-for-c</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Enhanced UI Notifications for Stack Deployment Issues</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-ui-notifications-for-stac</link>
    <description><![CDATA[<div class="p">August 11, 2021, File Storage Security—Added the UI notifications `Stack has been
               deployed` and `Stack information can't be retrieved` for the stack deployment. Before
               the enhancement, the notifications displayed "Something went wrong" for these issues.</div><ol class="ol" id="whatsnew_6f9_26a_df7__ol_4f6_7ef">
<li class="li">Stack has been deployed: This notification now displays when the stack is created
                  after the deployment but the GET API request of the created stack has reached the
                  maximum number of retries.</li>
<li class="li">Stack information can't be retrieved: This notification now displays when the stacks
                  are deployed with incorrect parameters in your cloud account and File Storage Security
                  is not able to retrieve the information it needs.</li>
</ol>]]></description>
    <pubDate>Wed, 11 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-ui-notifications-for-stac</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>File Storage Security Azure deployment issue fixed</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-azure-deploy</link>
    <description><![CDATA[<div class="p">August 11, 2021, File Storage Security—Fixed the issue where clicking `Launch Stack`
               to deploy stacks on Azure (in preview) caused the Azure portal to display this error
               message:</div><div class="p">`There was an error downloading the template from URI 'https://file-storage-security-preview.s3.amazonaws.com/latest/arm-templates/FSS-All-In-One-Template.json'.
               Ensure that the template is publicly accessible and that the publisher has enabled
               CORS policy on the endpoint. To deploy this template, download the template manually
               and paste the contents in the 'Build your own template in the editor' option below.`</div>]]></description>
    <pubDate>Wed, 11 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-azure-deploy</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Real Time Threat Monitoring for Azure, Organization Profiles, and Enhanced Reports Added</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-real-time-threat-monitoring-for-az</link>
    <description><![CDATA[<div class="p">August 12, 2021, Conformity—The following updates were released to Conformity on 12th
               August 2021.</div><div class="p">RTM for Azure</div><ul class="ul" id="whatsnew_042_93a_941__ul_099_c6b">
<li class="li">You can now set up Real Time Threat Monitoring and monitor events on your Azure accounts
                  via UI and API. For details, see:<a class="xref" href="https://www.cloudconformity.com/help/real-time-threat-monitoring/real-time-threat-monitoring-settings.html" target="_blank">Real-time Monitoring Settings</a>.</li>
</ul><div class="p">Organization Profile</div><ul class="ul" id="whatsnew_042_93a_941__ul_e72_10f">
<li class="li">Conformity enables you to now set up an Organization Profile in your Conformity Account
                  to customize default rule settings for all existing and newly added accounts to your
                  organization. For details: see: <a class="xref" href="https://www.cloudconformity.com/help/profiles.html" target="_blank">Profiles</a>.</li>
</ul><div class="p">CQL Filter Method</div><ul class="ul" id="whatsnew_042_93a_941__ul_01e_c77">
<li class="li">You can now customise your search results using the Conformity Query Language (CQL)
                  to filter and search your checks on Reports. For details, see <a class="xref" href="https://www.cloudconformity.com/help/rules/filter-and-search/cql.html" target="_blank">CQL Filter Method</a>.</li>
</ul><div class="p">Compliance</div><ul class="ul" id="whatsnew_042_93a_941__ul_482_033">
<li class="li">Rule Mappings updated for the HITRUST and NIST 800-53 REV5 Compliance and Standard
                  Reports.</li>
</ul><div class="p">Reports</div><ul class="ul" id="whatsnew_042_93a_941__ul_e53_39e">
<li class="li">You can now include/exclude Account names on pdf reports via a new checkbox when creating
                  reports and report configurations. For details see: <a class="xref" href="https://www.cloudconformity.com/help/reports/generate-and-download-report.html" target="_blank">Generate and Download Report</a>.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_042_93a_941__ul_6d4_6b1">
<li class="li">Fixed a bug where creating your first account using the API would display the message
                  "Trial ends a few seconds ago" on the dashboard.</li>
<li class="li">Fixed a bug to bring the Check status returned by the API endpoints in line with the
                  current behaviour of the UI.</li>
<li class="li">Fixed a bug where problem tickets in the ServiceNow communication channel were not
                  resolving automatically.</li>
<li class="li">Fixed a bug where deleting profiles too quickly was logging the user out of the application</li>
</ul><div class="p">Custom Policy Updates</div><ul class="ul" id="whatsnew_042_93a_941__ul_aa3_2c8">
<li class="li">There is no change to the custom policy as a result of the new deployment. The current
                  custom policy version is 1.32. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the latest custom policy</a>.</li>
</ul><div class="p">Conformity Bot Updates</div><ul class="ul" id="whatsnew_042_93a_941__ul_d1b_395">
<li class="li">Fixed a bug where Conformity bot was switching between 'Success' and 'Failure' states
                  due to throttling errors on targeted IAM Roles.</li>
</ul><div class="p">New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_042_93a_941__ul_4f0_b43">
<li class="li">VPC-017: Unrestricted Inbound Traffic on Remote Server Administration Ports: This
                  rule ensures that no Network ACL (NACL) allows unrestricted inbound traffic on TCP
                  ports 22 and 3389.Boosted error handling to prevent outdated or inconsistent checks.</li>
</ul><div class="p">Rule Update</div><ul class="ul" id="whatsnew_042_93a_941__ul_209_842">
<li class="li">IAM-070: Check for IAM User Group Membership: This rule has been updated to support
                  success checks in order to provide a more accurate compliance score.</li>
<li class="li">Inspector-001: Amazon Inspector Findings: The rule has been optimized to reduce the
                  likelihood of prevent throttling to ensure consistent checks.</li>
</ul><div class="p">Rule Bug Fix</div><ul class="ul" id="whatsnew_042_93a_941__ul_e44_f43">
<li class="li">VPC-001: VPC Flow Logs Enabled: Fixed a bug where shared VPC resources resulted in
                  false positive results for this rule.</li>
</ul>]]></description>
    <pubDate>Thu, 12 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-real-time-threat-monitoring-for-az</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced File Storage Security Scans AWS S3 getObject Requests</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-storage-security-sca</link>
    <description><![CDATA[<div class="p">August 12, 2021, File Storage Security—File Storage Security now supports scanning
               AWS S3 getObject requests.</div><div class="p">The scan is performed when the client sends a GET request to S3 to get an object and
               if the object is malicious, the request is rejected.</div><div class="p">This feature helps users to make sure all files are scanned with the latest pattern
               right before being downloaded.</div><div class="p">It's also an alternative to setting up a scheduled scan or scanning on existing files.</div><div class="p">For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-aws-scan-on-get-object" target="_blank">Scan on getObject request</a>.</div>]]></description>
    <pubDate>Thu, 12 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-storage-security-sca</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>List Template Scanner Rules API endpoints added for Terraform and CloudFormation templates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-list-template-scanner-rules-api-en</link>
    <description><![CDATA[<div class="p">August 16, 2021, Conformity—List Template Scanner Rules API endpoints are now available
               for the Terraform and CloudFormation template types in Conformity Template Scanner.
               For details see: <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Template-scanner-#paths-~1template-scanner~1rules-get" target="_blank">Template Scanner API Documentation</a>.</div>]]></description>
    <pubDate>Mon, 16 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-list-template-scanner-rules-api-en</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Automatic Policy Assignment and Smart Folder Grouping with Azure Tags</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automatic-policy-assignment-and-sm</link>
    <description><![CDATA[<div class="p">August 16, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               now supports the use of Azure tags to assign policies automatically using event-based
               tasks and to group computers together using smart folders.</div>]]></description>
    <pubDate>Mon, 16 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automatic-policy-assignment-and-sm</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Windows Anti-Malware Scan Interface (AMSI) options available</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-windows-anti-malware-scan</link>
    <description><![CDATA[<div class="p">August 18, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               now has two scan action options for Windows Anti-Malware Scan Interface (AMSI). You
               can select either "Pass" or "Terminate" (under Anti-Malware &gt; General &gt; Real-Time
               Scan &gt; Malware Scan Configuration &gt; Edit &gt; General &gt; Windows Antimalware Scan Interface
               (AMSI)).</div>]]></description>
    <pubDate>Wed, 18 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-windows-anti-malware-scan</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Resolved issue displaying &quot;No description&quot; in system event descriptions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-resolved-issue-displaying-no-descr</link>
    <description><![CDATA[<div class="p">August 18, 2021, Workload Security—Resolved an issue that caused some system event
               descriptions to display "No description".</div>]]></description>
    <pubDate>Wed, 18 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-resolved-issue-displaying-no-descr</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Lambda function now retains license and pattern Lambda layer during stack updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-function-now-retains-licens</link>
    <description><![CDATA[<div class="p">August 19, 2021, File Storage Security—Fixed the issue where updating a stack from
               certain versions of template caused the Lambda function to lose the license and the
               latest pattern Lambda layer. This functionality requires a stack update.</div>]]></description>
    <pubDate>Thu, 19 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-function-now-retains-licens</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Runtime Security Preview with Container Activity Visibility and Control</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-runtime-security-preview-with-cont</link>
    <description><![CDATA[<div class="p">August 20, 2021, Container Security—Container Security will be introducing the next
               iteration of runtime security with a preview of the runtime visibility and control
               feature. This runtime security feature will provide visibility and mitigation of container
               activity that violate a customizable set of rules. This preview will be available
               with a set of pre-defined rules that provide visibility into MITRE ATTACK framework
               tactics for containers as well as container drift detection. The preview is compatible
               with Kubernetes and supports Amazon EKS, Microsoft Azure AKS, Google GKE, as well
               as OpenShift.</div>]]></description>
    <pubDate>Fri, 20 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-runtime-security-preview-with-cont</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Azure now supported in File Storage Security scan results retrieval API</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-now-supported-in-file-storag</link>
    <description><![CDATA[<div class="p">August 20, 2021, File Storage Security—The statistics and events API now supports
               `azure` in the `provider` parameter, allowing API users to retrieve their File Storage
               Security scan results of Azure stacks.</div>]]></description>
    <pubDate>Fri, 20 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-now-supported-in-file-storag</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>AWS Launch Stack now auto-populates ScannerLambdaAliasARN for S3 bucket scan enhancement</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-launch-stack-now-auto-populate</link>
    <description><![CDATA[<div class="p">August 20, 2021, File Storage Security—`Launch Stack` for AWS now supports auto population
               of a storage stack parameter, `ScannerLambdaAliasARN`.</div><div class="p">Previously, users wanting to enable <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-aws-scan-on-get-object" target="_blank">scan on getObject request</a> for AWS S3 buckets had to look up the alias ARN when using `Launch Stack` to deploy
               storage stacks.</div><div class="p">For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-stack-add-aws-#AddStorage" target="_blank">Add a storage stack on console</a> and <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-aws-scan-on-get-object" target="_blank">Scan on getObject request</a>.</div>]]></description>
    <pubDate>Fri, 20 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-launch-stack-now-auto-populate</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved accuracy of scan counts in Scan History chart interval switch</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-accuracy-of-scan-counts-i</link>
    <description><![CDATA[<div class="p">August 20, 2021, File Storage Security—Fixed an issue where scan counts displayed
               incorrectly when switching the interval of the Scan History chart from days to hours.</div>]]></description>
    <pubDate>Fri, 20 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-accuracy-of-scan-counts-i</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Fixed issue with updating stacks using prefix parameters</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-issue-with-updating-stacks-u</link>
    <description><![CDATA[<div class="p">August 24, 2021, File Storage Security—Fixed the issue where stacks with prefix parameters
               cannot be updated to latest template.</div>]]></description>
    <pubDate>Tue, 24 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-issue-with-updating-stacks-u</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Appliances page enhancements streamline policy management across scaling groups</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-appliances-page-enhancements-strea</link>
    <description><![CDATA[<div class="p">August 26, 2021, Network Security—Enhancements to appliances page: Appliances on the
               appliances page are now organized by their scaling group. You can change the inspection
               state and distribute policies for all appliances in a group at the same time. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-add_cloud_accounts_appliances-#deploy-protection" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 26 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-appliances-page-enhancements-strea</guid>
    <category>Network Security</category>
</item>
<item>
    <title>CloudWatch now supports TLS logs for enhanced AWS platform security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloudwatch-now-supports-tls-logs-f</link>
    <description><![CDATA[<div class="p">August 26, 2021, Network Security—Cloudwatch support for TLS logs: TLS inspection
               on AWS platforms can now stream its logs to customer CloudWatch accounts. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Manage_Network_Security_instances-#2-configure-cloudwatch-log-settings-on-your-appliance" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 26 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloudwatch-now-supports-tls-logs-f</guid>
    <category>Network Security</category>
</item>
<item>
    <title>TLS Inspection Now Available for AWS and Azure Platforms</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-tls-inspection-now-available-for-a</link>
    <description><![CDATA[<div class="p">August 26, 2021, Network Security—TLS inspection public release: Network Security
               now offers TLS inspection as a generally available security option for both AWS and
               Azure platforms. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-tls_inspection_overview-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 26 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-tls-inspection-now-available-for-a</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Enhanced Deployment Control with ObjectFilterPrefix for File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-deployment-control-with-o</link>
    <description><![CDATA[<div class="p">August 30, 2021, File Storage Security—<a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-gs-deploy-all-in-one-stack" target="_blank">All-in-one stacks</a> and <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-stack-add-aws-#AddStorage" target="_blank">storage stacks</a> can now be deployed with ObjectFilterPrefix to only invoke BucketListenerLambda on
               objects with a given prefix.</div><div class="p">This feature binds the `s3:ObjectCreated:*` event only on the given prefix.</div><div class="p">Previously, if the `s3:ObjectCreated:*` event of the scanning bucket was partially
               in use,</div><div class="p">you could only deploy the stacks by setting the TriggerWithObjectCreatedEvent option
               to false.</div><div class="p">Now with ObjectFilterPrefix, you can deploy the stack on a prefix that hasn't been
               used.</div><div class="p">This feature also helps you to limit the scans on a certain bucket prefix.</div><div class="p">For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-aws-object-created-event-in-use" target="_blank">s3:ObjectCreated:* event in use</a>.</div>]]></description>
    <pubDate>Mon, 30 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-deployment-control-with-o</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity API Integration Enhances AWS Well-Architected Tool Workflow</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-api-integration-enhance</link>
    <description><![CDATA[<div class="p">August 31, 2021, Conformity—Conformity API for AWS Well-Architected Tool</div><div class="p">Conformity's API integration with the AWS Well-Architected Tool now enables you to
               push a report of failed and successful checks from your Conformity accounts to your
               workload review. This report allows you to review checks more accurately with data-driven
               responses.</div><div class="p">Checks generated from rules are mapped to a particular Well-Architected review question.
               The checks are also summarised by 'Risk level' and  'Rule IDs' to allow better visibility
               for remediation based on the review findings. This summary is then pushed to the 'Notes'
               field for the related question. For details, see our <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Well-Architected-Tool" target="_blank">API Documentation for the Well-Architected Tool</a>.</div>]]></description>
    <pubDate>Tue, 31 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-api-integration-enhance</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Trend Micro Cloud One now available in UK region for data sovereignty requirements</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-cloud-one-now-availabl</link>
    <description><![CDATA[<div class="p">August 31, 2021, General—Trend Micro Cloud One is now available in the UK region,
               providing customers who have data sovereignty needs the option to have their account
               and security data hosted in-region. All Trend Micro Cloud One services except Open
               Source Security by Snyk are available for accounts in the UK region.</div><div class="p">Note: Only customers using a new Trend Micro Cloud One account can create their account
               in the UK region. To identify which type of account you have see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central--identity-and-account-management-c1-accounts-about-#whats-the-difference-between-a-new-account-and-a-legacy-account" target="_blank">What's the difference between a new account and a legacy account?</a>.</div>]]></description>
    <pubDate>Tue, 31 Aug 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-cloud-one-now-availabl</guid>
    <category>General</category>
</item>
<item>
    <title>Fixed disappearing scanner stacks issue in File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-disappearing-scanner-stacks</link>
    <description><![CDATA[<div class="p">September 02, 2021, File Storage Security—Fixed the issue where scanner stacks disappeared
               after deleting one scanner stack.</div>]]></description>
    <pubDate>Thu, 02 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-disappearing-scanner-stacks</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Upgrade Network Security virtual appliances to latest versions for AWS and Azure integration</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upgrade-network-security-virtual-a</link>
    <description><![CDATA[<div class="p">September 02, 2021, Network Security—Upgrade your appliance: Network Security virtual
               appliances can now be upgraded to the latest available version, 2021.4.1 or higher
               for AWS or 2021.3 or higher for Azure. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Upgrading_NSVA-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 02 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upgrade-network-security-virtual-a</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Conformity introduces new standards, bug fixes, and optimized rules for AWS users</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-standard</link>
    <description><![CDATA[<div class="p">September 07, 2021, Conformity—The following features and updates were released to
               Conformity on 7th September 2021.</div><div class="p">Standards and Frameworks</div><div class="p">Conformity now supports the  NIS Europe (OES-2019) and FISC Security Compliance(V9).</div><div class="p">Communication Channels Update</div><ul class="ul" id="whatsnew_3eb_a27_35b__ul_78f_9f3">
<li class="li">ServiceNow: Updated ServiceNow communication channel to include ‘cloud provider Id’
                  and ‘cloud provider in the description.</li>
</ul><ul class="ul" id="whatsnew_3eb_a27_35b__ul_639_cd9">
<li class="li">Jira: Disabled the ‘Test settings' and the ‘Save’ buttons for Jira communication channel
                  when the configuration is invalid. This ensures valid configuration must be selected
                  and a successful test must be run before saving.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_3eb_a27_35b__ul_be2_1b2">
<li class="li">Fixed a bug where PDF Reports with 0 checks displayed a blank white page.</li>
<li class="li">Fixed a bug where a default email communication channel was not set up when an account
                  was added on Cloud OneConformity.</li>
<li class="li">Fixed a bug where no error message was displayed for ‘Create/Update’ Communication
                  settings API endpoints with more than 2 statuses were passed in the request.</li>
<li class="li">Fixed a bug where usage of wildcard (* or ?) in the first few characters of the filter<a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Events-" target="_blank">name] field for [Events API</a> was returning an error message.</li>
<li class="li">Fixed a bug where the "Welcome to Trend Micro Cloud One" welcome email was being sent
                  up to three times upon email verification.</li>
<li class="li">Fixed a bug where the user could not see the option to add an Azure account on the
                  Subscription page if they only had AWS accounts configured.</li>
<li class="li">Fixed a bug to generate accurate checks for Lambda-007 Rule in the Template scanner
                  results.</li>
<li class="li">Fixed a bug where the number of active communication channels with manual notifications
                  turned 'ON' was not being reflected immediately.</li>
<li class="li">Fixed a bug to remove ‘Organisational Profile' as an option in the Template Scanner
                  dropdown option for Profile rule settings' because the organisational profile is already
                  checked against by default.</li>
<li class="li">Fixed a bug to prevent users from configuring exceptions using the following APIs
                  for Rules that do not support exceptions:</li>
<li class="li">https://eu-west-1-api.cloudconformity.com/v1/accounts/{id}/settings/rules/{ruleId}</li>
<li class="li">https://eu-west-1-api.cloudconformity.com/v1/accounts/{id}/settings/rules</li>
<li class="li">https://eu-west-1-api.cloudconformity.com/v1/profiles</li>
<li class="li">https://eu-west-1-api.cloudconformity.com/v1/profiles/{id}</li>
</ul><div class="p">Custom Policy Updates</div><ul class="ul" id="whatsnew_3eb_a27_35b__ul_5d9_bd9">
<li class="li">There is no change to the custom policy as a result of the new deployment. The current
                  custom policy version is 1.32. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the latest custom policy</a>.</li>
</ul><div class="p">New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_3eb_a27_35b__ul_ecd_3dc">
<li class="li">IAM-068: Unapproved IAM Policy in Use: This rule checks if there are any unapproved
                  IAM-managed policies in use.</li>
</ul><div class="p">Rule Update</div><div class="p">Optimized rule configurations to prevent the following rules from generating false
               positive checks due to API throttling:</div><ul class="ul" id="whatsnew_3eb_a27_35b__ul_ead_f16">
<li class="li">ELB-005: ELB Insecure SSL Protocol</li>
<li class="li">ELB-006: ELB Insecure SSL Ciphers</li>
<li class="li">IAM-001: Access Keys Rotated 30 Days</li>
<li class="li">IAM-002: Access Keys Rotated 45 Days</li>
<li class="li">IAM-004: Unnecessary Access Keys.</li>
<li class="li">IAM-007: Password Policy Lowercase.</li>
<li class="li">IAM-008: Password Policy Uppercase.</li>
<li class="li">IAM-009: Password Policy Number</li>
<li class="li">IAM-010: Password Policy Symbol</li>
<li class="li">IAM-011: Password Policy Expiration</li>
<li class="li">IAM-012: Password Policy Reuse Prevention</li>
<li class="li">IAM-013: MFA For IAM Users With Console Password</li>
<li class="li">IAM-016: IAM User Policies</li>
<li class="li">IAM-024: IAM User With Password And Access Keys</li>
<li class="li">IAM-025: Unnecessary SSH Public Keys</li>
<li class="li">IAM-026: SSH Public Keys Rotated 30 Days</li>
<li class="li">IAM-027: SSH Public Keys Rotated 45 Days</li>
<li class="li">IAM-028: Inactive IAM Console User</li>
<li class="li">IAM-029: Unused IAM User</li>
<li class="li">IAM-038: Access Keys Rotated 90 Days</li>
<li class="li">IAM-044: SSH Public Keys Rotated 90 Days</li>
</ul><div class="p">Rule Bug Fixes</div><ul class="ul" id="whatsnew_3eb_a27_35b__ul_c16_b0c">
<li class="li">EC2-027: Instance In Auto Scaling Group: Fixed a bug where false positives were generated
                  by RTM for EC2 Instances created by Auto Scaling Group in between the bot runs.</li>
</ul><ul class="ul" id="whatsnew_3eb_a27_35b__ul_b9e_266">
<li class="li">CS-001: AWS Custom Rule: Improved the rule to minimize the likelihood of missing checks
                  due to throttling of AWS Config rules.</li>
</ul><ul class="ul" id="whatsnew_3eb_a27_35b__ul_392_0a9">
<li class="li">CC-003: Conformity Insufficient Access Permissions: Fixed a bug that occasionally
                  had a minor impact on the reliability of some of the IAM rules supported by RTM and
                  Conformity Bot.</li>
</ul>]]></description>
    <pubDate>Tue, 07 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-standard</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved AWS region matching for Launch Stack feature</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-region-matching-for-l</link>
    <description><![CDATA[<div class="p">September 08, 2021, File Storage Security—Fixed the issue where clicking Launch Stack
               of AWS, the AWS region is not matching the selected region from the console.</div>]]></description>
    <pubDate>Wed, 08 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-region-matching-for-l</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Trend Micro Cloud One expands to Japan, Germany, and Australia regions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-cloud-one-expands-to-j</link>
    <description><![CDATA[<div class="p">September 14, 2021, General—Trend Micro Cloud One is now available in the Japan, Germany,
               and Australia regions, providing customers who have data sovereignty needs the option
               to have their account and security data hosted in-region. All Trend Micro Cloud One
               services except Open Source Security by Snyk are available for accounts in these regions.</div><div class="p">Note: Only customers using a new Trend Micro Cloud One account can create their account
               in the new regions. To identify which type of account you have see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central--identity-and-account-management-c1-accounts-about-#whats-the-difference-between-a-new-account-and-a-legacy-account" target="_blank">What's the difference between a new account and a legacy account?</a></div>]]></description>
    <pubDate>Tue, 14 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-cloud-one-expands-to-j</guid>
    <category>General</category>
</item>
<item>
    <title>Upgrade to Resolve Memory Issue on Azure Appliances</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upgrade-to-resolve-memory-issue-on</link>
    <description><![CDATA[<div class="p">September 14, 2021, Network Security—Upgrade to resolve a memory issue on Azure appliances:
               Appliance version 2021.8.0.11160 is now publicly available for both AWS and Azure
               platforms. Trend Micro recommends Azure customers upgrade to this version as soon
               as possible to avoid a memory issue that will result in a disruption of service and
               a reboot of your appliance. This version corrects the memory issue and provides the
               best performance. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Upgrading_NSVA-" target="_blank">Learn more about how to upgrade</a>.</div>]]></description>
    <pubDate>Tue, 14 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upgrade-to-resolve-memory-issue-on</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Resolved AWS stack deployment issue for Lambda alias creation</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-resolved-aws-stack-deployment-issu</link>
    <description><![CDATA[<div class="p">September 17, 2021, File Storage Security—Fixed the issue where deploying stacks in
               AWS sometimes fails at creating Lambda aliases with ResourceConflictException.</div>]]></description>
    <pubDate>Fri, 17 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-resolved-aws-stack-deployment-issu</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity enhances Terraform Template Scanner and introduces new IAM rule</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhances-terraform-temp</link>
    <description><![CDATA[<div class="p">September 21, 2021, Conformity—The following features and updates were released to
               Conformity on 21st September 2021.</div><div class="p">Terraform Template Scanner Update</div><div class="p">Template Scanner now supports scanning AWS RDS DB Cluster resources for Terraform
               templates.</div><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_2a9_dc0_d70__ul_387_ed0">
<li class="li">Fixed a bug to enable Template Scanner to resolve nested intrinsic functions within
                  Fn-Sub maps on CloudFormation templates.</li>
<li class="li">Fixed a bug where the rule - DynamoDB-001: Unused table was being displayed in the
                  Template Scanner results.</li>
<li class="li">Fixed a bug where settings for a newly configured communication channel were not being
                  reflected in the account settings UI.</li>
<li class="li">Fixed a bug where users were being logged out of Conformity after clicking on a profile
                  deleted via the API.</li>
<li class="li">Fixed bug where users weren't able to scroll back up the Main Dashboard after navigating
                  away from provider-specific account settings, for example, AWS RTM settings, Azure
                  access settings, etc.</li>
<li class="li">Fixed a bug where deleting a CQL query and going back to ‘Simple filters’ did not
                  reset the filters.</li>
<li class="li">Fixed a bug for the `Get Excluded Resources` API endpoint to return accurate results
                  for regions `ap-southeast-2` and `eu-west-1`.</li>
</ul><div class="p">Conformity Bot Updates</div><div class="p">We added support for AWS API Gateway Rest API tags to Conformity Bot so that rules
               like AG-005 (API Gateway Private Endpoint) can now support exceptions based on tags.</div><div class="p">Custom Policy Updates</div><ul class="ul" id="whatsnew_2a9_dc0_d70__ul_825_f62">
<li class="li">There is no change to the custom policy as a result of the new deployment. The current
                  custom policy version is 1.32. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the latest custom policy</a>.</li>
</ul><div class="p">New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_2a9_dc0_d70__ul_0aa_3a6">
<li class="li">IAM-071: Receive Permissions via IAM Groups Only: This rule ensures that your Amazon
                  IAM users can receive permissions only through IAM groups to follow the Principle
                  of Least Privilege (POLP), allowing you to manage user-based access to your AWS resources
                  efficiently.</li>
</ul><div class="p">Rule Update</div><ul class="ul" id="whatsnew_2a9_dc0_d70__ul_c25_612">
<li class="li">RG-001: Tags: ResourceGroup Tags now supports API Gateways - REST API and Stages.
                  To enable these resources, please update and save your rule settings.</li>
</ul><div class="p">Rule Bug Fix</div><ul class="ul" id="whatsnew_2a9_dc0_d70__ul_74b_d80">
<li class="li">ELBV2-006: ELBv2 ALB Security Group: Improved this rule to smoothly handle API throttling
                  and prevent the generation of false positives as a result.</li>
</ul>]]></description>
    <pubDate>Tue, 21 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhances-terraform-temp</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Article on troubleshooting sign up and sign in problems now available in Trend Micro Cloud One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-article-on-troubleshooting-sign-up</link>
    <description><![CDATA[<div class="p">September 22, 2021, General—Trend Micro Cloud One now has an article to <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central--identity-and-account-management-c1-user-new-troubleshoot-" target="_blank">help with sign up and sign in problems</a>.</div>]]></description>
    <pubDate>Wed, 22 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-article-on-troubleshooting-sign-up</guid>
    <category>General</category>
</item>
<item>
    <title>GCP account synchronization progress messages now displayed in Trend Cloud One console</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-account-synchronization-progre</link>
    <description><![CDATA[<div class="p">September 22, 2021, Workload Security—The Trend Cloud One - Endpoint &amp; Workload Security
               console now displays messages when a GCP account synchronization is in progress.</div>]]></description>
    <pubDate>Wed, 22 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-account-synchronization-progre</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Network Security for PCI DSS Compliance Guide</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-network-security-for-pci</link>
    <description><![CDATA[<div class="p">September 23, 2021, Network Security—PCI DSS compliance with Network Security: Network
               Security can help you meet your PCI DSS requirements. Learn how by reviewing the new
               <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-PCI_compliance-" target="_blank">checklist</a> to guide you through the process.</div>]]></description>
    <pubDate>Thu, 23 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-network-security-for-pci</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Multiple Appliance Support for TLS Inspection Available</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-multiple-appliance-support-for-tls</link>
    <description><![CDATA[<div class="p">September 23, 2021, Network Security—TLS inspection now supports more than one appliance
               and proxy: You can now configure multiple appliances and proxy servers for TLS inspection.
               <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-tls_inspection_overview-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 23 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-multiple-appliance-support-for-tls</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Enhanced Domain Filtering for PCI Compliance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-domain-filtering-for-pci</link>
    <description><![CDATA[<div class="p">September 23, 2021, Network Security—Updates to domain filtering to facilitate PCI
               compliance: To comply with the PCI requirement for restricting outbound traffic, domain
               filtering on Network Security appliances beginning with version 2021.9.0.11188 will
               only enforce policies in the outbound direction, egress to the internet. For appliances
               running earlier software versions, you can still configure inbound filtering policies.
               <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Domain_Filtering-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 23 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-domain-filtering-for-pci</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Experience Real-Time Attack Blocking with Network Security Trial</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-experience-real-time-attack-blocki</link>
    <description><![CDATA[<div class="p">September 23, 2021, Network Security—Try out Network Security: Experience how your
               virtual appliance blocks inbound and outbound attacks in real-time with our quick
               trial. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-NS_Action-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 23 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-experience-real-time-attack-blocki</guid>
    <category>Network Security</category>
</item>
<item>
    <title>File Storage Security enhances Azure Data Lake Storage Gen2 file scanning</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-enhances-azu</link>
    <description><![CDATA[<div class="p">September 28, 2021, File Storage Security—File Storage Security now supports the scanning
               of files uploaded to Azure Data Lake Storage Gen2.</div>]]></description>
    <pubDate>Tue, 28 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-enhances-azu</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>File Storage Security enables tagging scan results on Azure Blob metadata</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-enables-tagg</link>
    <description><![CDATA[<div class="p">September 28, 2021, File Storage Security—Azure storage stack's Post Scan Action function
               requires the `Microsoft.Storage/storageAccounts/blobServices/containers/blobs/write`
               permission to update the Azure Blob metadata.</div><div class="p">File Storage Security now provides the option of tagging the scan results on Azure
               Blob metadata via the All-in-One Stack and the Azure Storage Stack's ARM template.
               This functionality requires a stack update.</div>]]></description>
    <pubDate>Tue, 28 Sep 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-enables-tagg</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Azure Storage now supports dead lettering for Event Grid and Post Scan Action Tag functions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-storage-now-supports-dead-le</link>
    <description><![CDATA[<div class="p">October 01, 2021, File Storage Security—Azure storage stack now enables dead lettering
               for both the protecting blob storage's Event Grid System Topic and the Post Scan Action
               Tag function's subscription to the Scan Result Topic. You can find the resource ID
               of the dead-letter storages in the `blobSystemTopicDeadLetterStorageID` and `blobScanResultSubscriptionDeadLetterQueueID`
               fields on the storage stack's deployment Outputs page. This functionality requires
               a stack update.</div><div class="p">You monitor errors that occur during Azure functions that either process the blob
               created events or set the scan results to the blob's metadata or index tags from the
               dead-letter storages. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-azure-monitor-errors-" target="_blank">Monitor errors</a>.</div>]]></description>
    <pubDate>Fri, 01 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-storage-now-supports-dead-le</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved AWS stack updates for seamless Lambda alias updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-stack-updates-for-sea</link>
    <description><![CDATA[<div class="p">October 04, 2021, File Storage Security—Fixed the issue where updating stacks in AWS
               sometimes fails at updating Lambda aliases with ResourceConflictException.</div>]]></description>
    <pubDate>Mon, 04 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-stack-updates-for-sea</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Runtime Security Feature Open to All Container Security Customers</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-runtime-security-feature-open-to-a</link>
    <description><![CDATA[<div class="p">October 06, 2021, Container Security—Container Security is introducing a new <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-runtime-security-" target="_blank">runtime security feature</a> that was previously available to a limited number of customers by request only. The
               runtime security preview is now open to all Container Security customers.</div>]]></description>
    <pubDate>Wed, 06 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-runtime-security-feature-open-to-a</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Google Cloud Platform (GCP) Preview, Compliance Reports, Customization, and New Rules Released</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-google-cloud-platform-gcp-preview</link>
    <description><![CDATA[<div class="p">October 08, 2021, Conformity—The following feature and updates were released to Conformity
               on 8th October 2021.</div><div class="p">Preview for Google Cloud Platform (GCP) Now Available!</div><div class="p">You can now onboard Google Cloud Projects to Conformity as cloud accounts and scan
               to produce checks. All GCP projects onboarded to Conformity during the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-sentry-" target="_blank">Preview</a> period will be monitored free of charge. Please refer to the Rules section below
               for Rules included in the Preview release. For details see: <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-" target="_blank">Add a GCP Account</a>.</div><div class="p">Standards and Compliance Reports</div><ul class="ul" id="whatsnew_0f1_cba_964__ul_888_844">
<li class="li">We now support the CIS AWS Foundations v1.3 Compliance Standard reports including
                  the Excel version.</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_079_92f">
<li class="li">We’ve also added the NIST CyberSecurity Framework compliance reporting for Azure.</li>
</ul><div class="p">New Rules Start Date</div><div class="p">You can now customize 'New Rules Start Date' in both organization settings and account
               settings. Any rules released after this set date will be treated as new rules.</div><div class="p">Download Report Summary as PNG</div><div class="p">You can download Report Summary as a PNG image from Dashboard &gt; Overview and click
               on the three dots next to Configured Reports &gt; Export PNG.</div><div class="p">CSV Reports Update</div><div class="p">CSV reports will now include 'Check Id' and 'Link to resource' fields.</div><div class="p">Checks API Update</div><div class="p">Added a `consistentPagination` parameter in the Checks API that can be set to ‘false’
               to get better performance at the cost of consistency when paginating.</div><div class="p">Filter RTM Rules with Services API</div><div class="p">Updated v1/services API to indicate which rules are supported by RTM. Here is an example
               of using 'jq' command to parse the v1/services endpoint response to filter RTM rules:</div><div class="p">```</div><div class="p">curl https://ap-southeast-2.cloudconformity.com/v1/services &gt; conformityservices.json</div><div class="p">cat conformityservices.json | jq '.included[] | select(.attributes.rtm==true)' &gt; rtmrules.json</div><div class="p">```</div><div class="p">View all unmonitored accounts in the Threat Monitoring section</div><div class="p">Conformity now displays all the accounts unmonitored by RTM on the Threat Monitoring
               section as compared to previously displaying up to 10 accounts only.</div><div class="p">Custom Policy Updates</div><ul class="ul" id="whatsnew_0f1_cba_964__ul_6cd_681">
<li class="li">There is no change to the custom policy as a result of the new deployment. The current
                  custom policy version is 1.32. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the latest custom policy</a>.</li>
</ul><div class="p">Conformity Bot Updates</div><ul class="ul" id="whatsnew_0f1_cba_964__ul_f57_911">
<li class="li">Improved Conformity Bot to prevent duplicate notifications or false positives due
                  to throttling without a change in the customer resources. We applied this improvement
                  to some AWS rules for EC2, Route-53, VPC, IAM, KMS, CWL, Inspector, Trusted Advisor,
                  Sheild, EMR, WAF, Lambda, Organisations, Cloud Conformity, Secrets Manager, BackUp,
                  and Well-Architected.</li>
</ul><div class="p">New Rules</div><div class="p">The following new rules will be available with the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-sentry-" target="_blank">Preview</a> release of the Google Cloud Platform to Conformity.</div><ul class="ul" id="whatsnew_0f1_cba_964__ul_474_3c4">
<li class="li">CloudSQL-002: Enable Automated Backups for Cloud SQL Database Instances: This rule
                  ensures that Cloud SQL database instances are configured with automated backups.</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_754_5c3">
<li class="li">CloudSQL-003: Enable High Availability for Cloud SQL Database Instances: This rule
                  ensures that the production SQL database instances are configured to automatically
                  failover to another zone within the selected cloud region.</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_6f6_590">
<li class="li">BigQuery-001: Check for Publicly Accessible BigQuery Datasets: This rule checks for
                  publicly accessible Google Cloud BigQuery datasets.</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_559_b18">
<li class="li">CloudStorage-001: Check for Publicly Accessible Cloud Storage Buckets: This rule ensures
                  that there are no publicly accessible Cloud Storage buckets within your Google Cloud
                  Platform (GCP) account.</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_e0b_2f0">
<li class="li">CloudVPC-001: Check for Unrestricted RDP Access: This rule ensures that there are
                  no VPC firewall rules that allow unrestricted inbound access on TCP port 3389 (RDP).</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_963_7c1">
<li class="li">CloudVPC-002: Check for Unrestricted SSH Access: This rule ensures that no VPC firewall
                  rules allow unrestricted inbound access on TCP port 22 (SSH).</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_c08_d6c">
<li class="li">CloudVPC-003: Enable VPC Flow Logs for VPC Subnets: This rule ensures that the VPC
                  Flow Logs feature is enabled for all VPC network subnets.</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_aa3_5fc">
<li class="li">CloudIAM-001: Restrict Administrator Access for Service Accounts: This rule ensures
                  that user-managed service accounts are not using administrator-based roles.</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_00a_d68">
<li class="li">ComputeEngine-001: Check for Virtual Machine Instances with Public IP Addresses: This
                  rule ensures that your Google Compute Engine instances are not configured to have
                  external IP addresses to minimize their exposure to the Internet.</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_a75_40e">
<li class="li">CloudKMS-001: Check for Publicly Accessible Cloud KMS Keys: This rule ensures that
                  there are no publicly accessible KMS cryptographic keys available within your Google
                  Cloud account.</li>
</ul><div class="p">Rule Updates</div><ul class="ul" id="whatsnew_0f1_cba_964__ul_6c8_3fd">
<li class="li">RTM-009: VPC Network Configuration Changes: This rule now supports an ‘allow list’
                  of users based on ARNs such that checks are not generated for users added to this
                  list. The Supported user types are IAMUser, AssumedRole, and FederatedUser.</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_613_967">
<li class="li">VPC-015: Ineffective Network ACL DENY Rules: Updated this rule to generate a rule
                  failure if a DENY NACL rule is ineffective due to a higher priority ALLOW rule.</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_831_ee5">
<li class="li">Route53-003: Route 53 Domain Transfer Lock: This rule has been updated to not check
                  the transfer lock status of these domains as AWS does not support transfer lock for
                  the following top-level domains:</li>
<li class="li">“.ch”</li>
<li class="li">“.co.nz”</li>
<li class="li">“.co.za”</li>
<li class="li">“.com.ar”</li>
<li class="li">“.com.au”</li>
<li class="li">“.de”</li>
<li class="li">“.es”</li>
<li class="li">“.eu”</li>
<li class="li">“.fi”</li>
<li class="li">1“.fr”</li>
<li class="li">“.jp”</li>
<li class="li">“.net.au”</li>
<li class="li">“.net.nz”</li>
<li class="li">“.nl”</li>
<li class="li">“.it”</li>
<li class="li">“.org.nz”</li>
<li class="li">“.qa”</li>
<li class="li">“.ru”</li>
<li class="li">“.se”</li>
<li class="li">“.uk”</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_b71_db9">
<li class="li">Rules labeled as 'New' have been updated to 'Recently added'.</li>
</ul><div class="p">Rule Bug Fixes</div><ul class="ul" id="whatsnew_0f1_cba_964__ul_0d5_2b9">
<li class="li">The following VPC Network ACLs rules will no longer scan shared VPC and produce checks</li>
<li class="li">VPC-010: Unrestricted Network ACL Outbound Traffic</li>
<li class="li">VPC-011: Unrestricted Network ACL Inbound Traffic</li>
<li class="li">VPC-015: Ineffective Network ACL DENY Rules</li>
<li class="li">VPC-017: Unrestricted Inbound Traffic on Remote Server Administration Ports</li>
</ul><ul class="ul" id="whatsnew_0f1_cba_964__ul_436_a00">
<li class="li">Fixed a bug to prevent false positives from being generated for the following rules:</li>
<li class="li">SNS-006 - SNS Topic Encrypted</li>
<li class="li">SNS-007 - SNS Topic Encrypted With KMS Customer Master Keys</li>
</ul>]]></description>
    <pubDate>Fri, 08 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-google-cloud-platform-gcp-preview</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Agent Version 20.0.0.3165 Released for Trend Cloud One Customers</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-agent-version-20003165-release</link>
    <description><![CDATA[<div class="p">October 08, 2021, Workload Security—Agent version 20.0.0.3165 has been released to
               Trend Cloud One - Endpoint &amp; Workload Security customers. However, it will not be
               made available on the Deep Security Agent software download page or released to customers
               using Deep Security Manager. For information about what's included in this version,
               see <a class="xref" href="https://help.deepsecurity.trendmicro.com/20_0/on-premise/release-notes-dsa.html" target="_blank">What's New in Deep Security Agent</a>.</div>]]></description>
    <pubDate>Fri, 08 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-agent-version-20003165-release</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Security event sharing enhances visibility and collaboration in Network Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-security-event-sharing-enhances-vi</link>
    <description><![CDATA[<div class="p">October 08, 2021, Network Security—Security event sharing: Threat Insights provides
               visibility into the security events of your appliances by compiling statistics from
               those events and sharing them with Nework Security. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-threat_insights-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Fri, 08 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-security-event-sharing-enhances-vi</guid>
    <category>Network Security</category>
</item>
<item>
    <title>File Storage Security API now supports filtering scan results by storage</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-api-now-supp</link>
    <description><![CDATA[<div class="p">October 14, 2021, File Storage Security—The scan statistics and events APIs now support
               the 'storage' parameter. This allows API users to filter their File Storage Security
               scan results by storage.</div><div class="p">For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-api-reference-tag-Statistics-#operation-listScanStatistics" target="_blank">List scan statistics</a> and <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-api-reference-tag-Events#operation-listEvents" target="_blank">List events</a>.</div>]]></description>
    <pubDate>Thu, 14 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-api-now-supp</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced role customization for Trend Micro Cloud One improves access control efficiency</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-role-customization-for-tr</link>
    <description><![CDATA[<div class="p">October 14, 2021, General—Trend Micro Cloud One now supports customization of roles,
               enabling more granular role-based access control (RBAC) across security services and
               administrative functions. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central--identity-and-account-management-c1-roles-" target="_blank">Assign roles to users</a>.</div>]]></description>
    <pubDate>Thu, 14 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-role-customization-for-tr</guid>
    <category>General</category>
</item>
<item>
    <title>Enhanced IAM Service Checks for Conformity Bot Efficiency</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-iam-service-checks-for-co</link>
    <description><![CDATA[<div class="p">October 15, 2021, Conformity—The Conformity Production account experienced a degree
               of outbound API call rate-limiting for the IAM service in AWS, between 30th August
               -16th September 2021, resulting in some missing and outdated checks by Conformity
               Bot.</div><div class="p">Cause</div><div class="p">Working with the AWS account teams, we identified certain instances where Conformity
               was making repetitive API calls. For example, redundant attempts to list and get certain
               AWS managed policies contributing to throttling by AWS.</div><div class="p">Resolution</div><div class="p">We have made Conformity Bot checks for the IAM service more reliable by caching certain
               IAM results to reduce the number of redundant  API calls. This also reduces the likelihood
               of API throttling on your accounts. We will continue to monitor the system to ensure
               the success of these improvements. We have more improvements planned to increase the
               efficiency of the Conformity Bot in the near future and will keep you updated with
               the progress.</div>]]></description>
    <pubDate>Fri, 15 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-iam-service-checks-for-co</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Fixed issue with S3 bucket event notifications post stack deletion</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-issue-with-s3-bucket-event-n</link>
    <description><![CDATA[<div class="p">October 15, 2021, File Storage Security—Fixed the issue where the S3 bucket's event
               notification was not removed correctly after deleting a stack that specified the `ObjectFilterPrefix`
               parameter. This functionality requires a stack update.</div><div class="p">If the stack has already been deleted, you need to remove the bucket's event notification
               manually. For more information, see <a class="xref" href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/how-to-enable-disable-notification-intro.html" target="_blank">Enabling event notifications</a>.</div>]]></description>
    <pubDate>Fri, 15 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-issue-with-s3-bucket-event-n</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>AWS Storage Stack now supports dead-letter queue deployment</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-storage-stack-now-supports-dea</link>
    <description><![CDATA[<div class="p">October 18, 2021, File Storage Security—AWS storage stack now provides the option
               to deploy with a dead-letter queue. This functionality requires a stack update. For
               more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-aws-storage-dlq" target="_blank">Storage Stack DLQ</a>.</div>]]></description>
    <pubDate>Mon, 18 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-storage-stack-now-supports-dea</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>AWS IAM Roles now support permissions boundary for File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-iam-roles-now-support-permissi</link>
    <description><![CDATA[<div class="p">October 18, 2021, File Storage Security—AWS stacks now support specifying a <a class="xref" href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_boundaries.html" target="_blank">permissions boundary</a> for all the IAM roles created by File Storage Security.</div><div class="p">This allows users to make sure the roles created by File Storage Security are limited
               to a scope of permissions.</div><div class="p">For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-stack-add-aws-" target="_blank">Add AWS stacks</a> and <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-aws-permissions-control-" target="_blank">AWS permissions control</a>.</div>]]></description>
    <pubDate>Mon, 18 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-iam-roles-now-support-permissi</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Trend Micro Cloud One expands to Canada and Singapore regions for data sovereignty compliance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-cloud-one-expands-to-c</link>
    <description><![CDATA[<div class="p">October 18, 2021, General—Trend Micro Cloud One is now available in the Canada and
               Singapore regions, providing customers who have data sovereignty needs the option
               to have their account and security data hosted in-region. All Trend Micro Cloud One
               services except Open Source Security by Snyk are available for accounts in these regions.</div><div class="p">Note: Only customers using a new Trend Micro Cloud One account can create their account
               in the new regions. To identify which type of account you have see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central--identity-and-account-management-c1-accounts-about-#whats-the-difference-between-a-new-account-and-a-legacy-account" target="_blank">What's the difference between a new account and a legacy account?</a>.</div>]]></description>
    <pubDate>Mon, 18 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-cloud-one-expands-to-c</guid>
    <category>General</category>
</item>
<item>
    <title>Custom rule creation now displays dates in Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-rule-creation-now-displays</link>
    <description><![CDATA[<div class="p">October 18, 2021, Workload Security—Resolved an issue where when creating custom Log
               Inspection, Integrity Monitoring, or Intrusion Prevention rules, the date wasn't displayed
               in the Issued and Last Updated fields.</div>]]></description>
    <pubDate>Mon, 18 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-rule-creation-now-displays</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Stacks no longer disappear from console</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-stacks-no-longer-disappear-from-co</link>
    <description><![CDATA[<div class="p">October 19, 2021, File Storage Security—Fixed the issue where stacks disappear from
               the console.</div>]]></description>
    <pubDate>Tue, 19 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-stacks-no-longer-disappear-from-co</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>File Storage Security now restricts stack deployment and deletion for Read Only users</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-restrict</link>
    <description><![CDATA[<div class="p">October 20, 2021, File Storage Security—File Storage Security console now disables
               the stack deployment buttons and the stack deleting button if the Cloud One user has
               `Read Only` role.</div>]]></description>
    <pubDate>Wed, 20 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-restrict</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced Azure Security Configurations for Functions and Storage Accounts</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azure-security-configurat</link>
    <description><![CDATA[<div class="p">October 20, 2021, File Storage Security—The following Azure security configurations
               are used for the functions and storage accounts deployed in the Azure stacks:</div><ul class="ul" id="whatsnew_27a_049_7bd__ul_7ac_cf4">
<li class="li">For all Azure functions, the `httpsOnly` property is set to `true`.</li>
<li class="li">For all Azure storage accounts, the `minimumTlsVersion` property is set to `TLS1_2`.</li>
</ul><div class="p">This functionality requires a stack update.</div>]]></description>
    <pubDate>Wed, 20 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azure-security-configurat</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>CloudFormation Stack Creation Support for Enhanced Analysis and Troubleshooting</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloudformation-stack-creation-supp</link>
    <description><![CDATA[<div class="p">October 21, 2021, Network Security—CloudFormation stack creation support: You can
               now send your Cloud Formation stack event logs directly to Trend Micro for further
               analysis and troubleshooting by our team of experts. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Stack_creation_support-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 21 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloudformation-stack-creation-supp</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Improved Troubleshooting Report Submission Process</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-troubleshooting-report-su</link>
    <description><![CDATA[<div class="p">October 21, 2021, Network Security—Troubleshooting report improvements: Sending a
               troubleshooting report to us is now easier. You can now generate and send a report
               from your appliance without creating an S3 bucket. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-troubleshooting-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 21 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-troubleshooting-report-su</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Legacy Trend Micro Cloud One API Endpoints Decommissioned for Certain Accounts</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-legacy-trend-micro-cloud-one-api-e</link>
    <description><![CDATA[<div class="p">October 22, 2021, General—As of December 31st, 2021, API endpoints for the following
               Trend Micro Cloud One services will be decommissioned for legacy Trend Micro Cloud
               One accounts created before August 4th only:</div><ul class="ul" id="whatsnew_2a4_865_2bb__ul_491_8d8">
<li class="li">Network Security</li>
<li class="li">Application Security</li>
<li class="li">File Storage Security</li>
<li class="li">Container Security</li>
</ul><div class="p">Customers currently using these endpoints can contact Trend Micro to upgrade their
               account and access the same API functionality using the Trend Cloud One updated regional
               service API endpoints. For more information, see <a class="xref" href="https://success.trendmicro.com/en-us/solution/ka-0012469" target="_blank">End of Support for Legacy Account API Endpoints for Cloud One - Network Security,
                  Container Security, Application Security, and File Storage Security</a>.</div>]]></description>
    <pubDate>Fri, 22 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-legacy-trend-micro-cloud-one-api-e</guid>
    <category>General</category>
</item>
<item>
    <title>Custom Roles for Workload Security Accounts Now Available</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-roles-for-workload-security</link>
    <description><![CDATA[<div class="p">October 22, 2021, General—Accounts created on or after August 4, 2021 now support
               the use of custom roles for Workload Security, enabling even more granular role-based
               access control (RBAC). For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central--identity-and-account-management-c1-roles-" target="_blank">Assign roles to users</a>.</div>]]></description>
    <pubDate>Fri, 22 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-roles-for-workload-security</guid>
    <category>General</category>
</item>
<item>
    <title>Pay as you go billing for protected containers and VMs in Trend Micro Cloud One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-pay-as-you-go-billing-for-protecte</link>
    <description><![CDATA[<div class="p">October 25, 2021, Billing and Subscription Management—Pay as you go billing is now
               available for containers and VMs protected by Trend Micro Cloud One - Application
               Security. For pricing and additional information, please see <a class="xref" href="https://aws.amazon.com/marketplace/pp/prodview-g232pyu6l55l4" target="_blank">Trend Micro Cloud One on the AWS Marketplace</a>.</div>]]></description>
    <pubDate>Mon, 25 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-pay-as-you-go-billing-for-protecte</guid>
    <category>Billing and Subscription Management</category>
</item>
<item>
    <title>Improved User Experience for Trend Cloud One Account Creation Dates After August 4, 2021</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-user-experience-for-trend</link>
    <description><![CDATA[<div class="p">October 25, 2021, Workload Security—To limit redundancy, users with a Trend Cloud
               One account created on or after August 4, 2021 will no longer see legacy UI items
               in the Trend Cloud One - Endpoint &amp; Workload Security console for elements that are
               controlled at the Trend Cloud One account level, such as API keys and user role assignments.</div>]]></description>
    <pubDate>Mon, 25 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-user-experience-for-trend</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Additional IAM Policy Support for AWS Stacks in File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-additional-iam-policy-support-for</link>
    <description><![CDATA[<div class="p">October 25, 2021, File Storage Security—AWS stacks now support specifying a list of
               additional IAM policies for all the IAM roles created by File Storage Security.</div><div class="p">This provides another option for users to control the permissions of File Storage
               Security in addition to <a class="xref" href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_boundaries.html" target="_blank">permissions boundary</a>.</div><div class="p">For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-stack-add-aws-" target="_blank">Add AWS stacks</a> and <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-aws-permissions-control-" target="_blank">AWS permissions control</a>.</div>]]></description>
    <pubDate>Mon, 25 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-additional-iam-policy-support-for</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Extended Console Session Timeout for New Trend Micro Cloud One Accounts</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-extended-console-session-timeout-f</link>
    <description><![CDATA[<div class="p">October 25, 2021, General—The console session timeout has been extended to 30 minutes
               for new Trend Micro Cloud One accounts created on or after August 4th, 2021.</div>]]></description>
    <pubDate>Mon, 25 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-extended-console-session-timeout-f</guid>
    <category>General</category>
</item>
<item>
    <title>Anti-Malware Protection Status widget loading issue resolved on dashboard</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-anti-malware-protection-status-wid</link>
    <description><![CDATA[<div class="p">October 28, 2021, Workload Security—Resolved an issue where the Anti-Malware Protection
               Status widget on the Trend Cloud One - Endpoint &amp; Workload Security dashboard displayed
               "Unable to load widget".</div>]]></description>
    <pubDate>Thu, 28 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-anti-malware-protection-status-wid</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Agent Installer and Platform Support in Workload Security 20.0.0.3288</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-agent-installer-and-platf</link>
    <description><![CDATA[<div class="p">October 28, 2021, Workload Security—Agent version 20.0.0.3288 has been released.</div><div class="p">Some highlights include:</div><ul class="ul" id="whatsnew_164_9dd_874__ul_813_145">
<li class="li">Evolution of the agent installer: The agent installer now installs most agent content.</li>
<li class="li">Enhanced platform support: Added AlmaLinux 8, Rocky Linux 8, Ubuntu 20.04 (AWS ARM-Based
                  Graviton 2), and Ubuntu 18.04 (AWS ARM-Based Graviton 2).</li>
<li class="li">Secure boot support: Added Oracle Linux 7 and Oracle Linux 8.</li>
</ul><div class="p">For detailed information on what's included in this version, see <a class="xref" href="https://help.deepsecurity.trendmicro.com/20_0/on-premise/release-notes-dsa.html" target="_blank">What's New in Deep Security Agent</a>.</div>]]></description>
    <pubDate>Thu, 28 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-agent-installer-and-platf</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Default timeout for Trend Vision One (XDR) registration increased to 70 seconds</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-default-timeout-for-trend-vision-o</link>
    <description><![CDATA[<div class="p">October 28, 2021, Workload Security—The default timeout for Trend Vision One (XDR)
               registration has changed from 60 seconds to 70 seconds.</div>]]></description>
    <pubDate>Thu, 28 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-default-timeout-for-trend-vision-o</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Security Posture Assessment in Network Security Deployment</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-posture-assessme</link>
    <description><![CDATA[<div class="p">October 29, 2021, Network Security—Security posture assessment: When deploying Network
               Security using the Get Started wizard, you can now view an assessment of your security
               posture to better assess your security needs. This visual evaluation shows you how
               Network Security can optimize and protect your assets. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-add_cloud_accounts_appliances-#view-security-posture" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Fri, 29 Oct 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-posture-assessme</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Annual subscriptions now setup through Trend Micro Activation Service</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-annual-subscriptions-now-setup-thr</link>
    <description><![CDATA[<div class="p">November 01, 2021, Billing and Subscription Management—For customers buying annual
               subscriptions of Trend Micro Cloud One, new purchases and renewal orders are now set
               up using the Trend Micro Activation Service. For more information and instructions,
               see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-billing-subscription-billing--billing-and-subscription-management-?topicid=tm-activation" target="_blank">this article</a>. This does change does not affect customers subscribing to Trend Micro Cloud One
               through AWS Marketplace.</div>]]></description>
    <pubDate>Mon, 01 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-annual-subscriptions-now-setup-thr</guid>
    <category>Billing and Subscription Management</category>
</item>
<item>
    <title>Deploy Network Security in Azure with Gateway Load Balancer</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deploy-network-security-in-azure-w</link>
    <description><![CDATA[<div class="p">November 02, 2021, Network Security—Deploy in Azure with Gateway Load Balancer: A
               new deployment option that leverages Azure Gateway Load Balancer is now generally
               available from Azure Marketplace. With this Gateway Load Balancer offering, you can
               inspect inbound and outbound traffic with minimal changes to your existing network
               infrastructure. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Azure_Deployment6_VMSS_GWLB-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Tue, 02 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deploy-network-security-in-azure-w</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Pay as you go billing introduced for Trend Micro Cloud One - Workload Security Essentials</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-pay-as-you-go-billing-introduced-f</link>
    <description><![CDATA[<div class="p">November 03, 2021, Billing and Subscription Management—Pay as you go billing is now
               available for Trend Micro Cloud One - Workload Security Essentials. Workloads using
               only the Anti-Malware or Activity Monitoring (XDR) modules will now be charged at
               a lower hourly rate. For more information, see <a class="xref" href="https://aws.amazon.com/marketplace/pp/prodview-g232pyu6l55l4" target="_blank">Trend Micro Cloud One on the AWS Marketplace</a>.</div>]]></description>
    <pubDate>Wed, 03 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-pay-as-you-go-billing-introduced-f</guid>
    <category>Billing and Subscription Management</category>
</item>
<item>
    <title>Instance IDs now included in azureARMVirtualMachineSummary object in Computers API response</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-instance-ids-now-included-in-azure</link>
    <description><![CDATA[<div class="p">November 03, 2021, Workload Security—The azureARMVirtualMachineSummary object in the
               computers API response now includes the instanceID, allowing you to get the Instance
               IDs of your Azure VMs by calling Computers API (List Computers).</div>]]></description>
    <pubDate>Wed, 03 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-instance-ids-now-included-in-azure</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Scanner now able to send scan events to File Storage Security backend</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanner-now-able-to-send-scan-even</link>
    <description><![CDATA[<div class="p">November 03, 2021, File Storage Security—Fixed the issue where scanner cannot send
               scan events to File Storage Security backend. The scanner stacks which are added after
               October 28th are not affected.</div>]]></description>
    <pubDate>Wed, 03 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanner-now-able-to-send-scan-even</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>New option to schedule kernel updates for Workload Security agents</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-option-to-schedule-kernel-upda</link>
    <description><![CDATA[<div class="p">November 03, 2021, Workload Security—You can now choose when to perform kernel support
               package updates, using the new Automatically update kernel package when agent restarts
               option in the computer or policy editor. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-agent-linux-kernel-support-#manage_ksp_updates" target="_blank">Manage kernel support package updates</a></div>]]></description>
    <pubDate>Wed, 03 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-option-to-schedule-kernel-upda</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity introduces new rules, bug fixes, and custom policy updates for enhanced security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-rules-bu</link>
    <description><![CDATA[<div class="p">November 04, 2021, Conformity—The following features and updates were released to
               Conformity on 4th November 2021.</div><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_cce_fce">
<li class="li">The Custom Check API now enables a user to specify a TTL field to auto remove/expire
                  their check.</li>
<li class="li">The extra data for checks earlier available through the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Checks#paths-~1checks~1{checkId}-get" target="_blank">Get Check Details API</a> and UI is now included in the 'Meta' column of CSV reports.</li>
<li class="li">We’ve Improved the RTM eventBridge rule to exclude data events.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_00f_3cc">
<li class="li">Fixed an issue with the Jira communication channel configuration where the ‘Save’
                  and the ‘Test’ buttons got stuck when testing against an invalid priority.</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_e99_b03">
<li class="li">Improved the performance of "Create Account" Public API, response time is now reduced.</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_9f9_0b8">
<li class="li">Added missing metadata, page number, and size to the payload response examples in
                  the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Checks-#paths-~1checks-get" target="_blank">Checks API Reference</a> documentation.</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_b7b_033">
<li class="li">Fixed a bug to display corresponding ticketing channels while viewing checks for ‘All
                  Cloud Accounts’.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">The custom policy has been updated as a result of the new deployment. The current
               custom policy version is 1.33. The permissions added are:</div><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_4ca_1ff">
<li class="li">macie2:GetClassificationExportConfiguration</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_fca_9e9">
<li class="li">macie2:ListClassificationJobs</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_702_a6e">
<li class="li">macie2:GetFindingStatistics</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the latest custom policy</a>.</div><div class="p">New Rules</div><div class="p">AWS</div><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_2f3_c33">
<li class="li">S3-029: Amazon Macie Finding Statistics for S3: This rule captures summary statistics
                  about Amazon Macie security findings on a per-S3 bucket basis.</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_9d5_5d5">
<li class="li">Macie2-002: Amazon Macie Sensitive Data Repository: This rule ensures that a data
                  repository bucket is defined for Amazon Macie within each AWS region.</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_e00_bad">
<li class="li">Macie2-003: Amazon Macie Discovery Jobs: This rule ensures that Amazon Macie data
                  discovery jobs are created and configured within each AWS region.</li>
</ul><div class="p">Azure</div><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_aec_756">
<li class="li">SecurityCenter-029: Configure Additional Email Addresses for Azure Security Center
                  Notifications: This rule ensures that additional email addresses are provided to receive
                  security notifications.</li>
</ul><div class="p">Rule Updates</div><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_2bb_146">
<li class="li">SSM-003: Check for SSM Managed Instances: Updated the rule to no longer produce checks
                  for EC2 Instances in 'Stopped' state.</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_c7e_30e">
<li class="li">IAM-054: IAM Configuration Changes: Add a new rule configuration for setting a regular
                  expression of ARNs for users (IAMUser, AssumedRole or FederatedUser) whose activity
                  will not be checked against this rule (e.g. ^(arn:aws:iam::\\d{12}:user\\/James-.+)$)”</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_f1d_e97">
<li class="li">RTM-011: Unintended AWS API Calls Detected: This rule now supports ‘PasswordRecoveryRequested’,
                  ‘PasswordRecoveryCompleted’, ‘PasswordUpdated’ root user events.</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_c52_b17">
<li class="li">Updated Default Risk Levels for S3-026 and S3-027</li>
</ul><div class="p">We’ve updated the default risk levels for these rules to reduce alarm noise and provide
               more relevant notifications from the other S3 rules that do control exposure of a
               bucket to public access.</div><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_703_7bd">
<li class="li">S3-026: Enable S3 Block Public Access for S3 Buckets - from 'Very High' to 'Medium'.</li>
<li class="li">S3-027: Enable S3 Block Public Access for AWS Accounts - from 'Very High' to 'Low'.</li>
</ul><div class="p">Because an Account admin can only use the S3 Block Public Access feature to restrict
               public access to a bucket, but they cannot grant public access to the bucket. They
               need to use a policy or an ACL to open a given access point and buckets to grant public
               access. Therefore, failing the checks for the rules S3-026 &amp; S3-027 with a ‘Very High’
               severity overstates the exposure of the buckets in an account.</div><div class="p">The severities of 'Medium' and 'Low' respectively provide a closer depiction of the
               exposure since the 'Very High' Severity rules S3-001, S3-002, S3-003, S3-004, S3-005,
               and S3-014 directly control public access to a bucket.</div><div class="p">For more information see AWS documentation on <a class="xref" href="https://aws.amazon.com/s3/features/block-public-access/" target="_blank">Block Public Access</a> and <a class="xref" href="https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html" target="_blank">Access Control Block Public Access</a>.</div><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_f76_cf4">
<li class="li">IAM-17: Unused IAM Group: Fixed the bug which RTM generates false positive check result
                  for IAM-017 rule.</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_291_6eb">
<li class="li">Fix a bug where duplicate notifications were generated for the following rules:</li>
<li class="li">VirtualMachines-001: Enable Encryption for Boot Disk Volumes</li>
<li class="li">VirtualMachines-002: Enable Encryption for Non-Boot Disk Volumes</li>
<li class="li">VirtualMachines-003: Enable Encryption for Unattached Disk Volumes</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_fba_7fb">
<li class="li">Fixed a bug where EBS service retained stale checks for users with a large amount
                  of EBS snapshots.</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_60a_fb2">
<li class="li">Fixed a bug where ELB related rules were not being triggered by RTM events. Added
                  support for Terraform plans AWS KMS key resourceDB instance resource.</li>
</ul><ul class="ul" id="whatsnew_f7b_ff9_0cb__ul_451_233">
<li class="li">IAM-047: IAM Manager Roles: Fixed a bug where false negative checks were being generated
                  for the rule.</li>
</ul>]]></description>
    <pubDate>Thu, 04 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-rules-bu</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Mitigation of Runtime Issues with Customized Policies</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-mitigation-of-runtime-iss</link>
    <description><![CDATA[<div class="p">November 04, 2021, Container Security—Container Security will be introducing the ability
               to mitigate problems detected by the runtime visibility and control feature, based
               on user-customized policy. If a pod violates any rule during runtime, the issue will
               be mitigated by terminating or isolating the pod based on the policy.</div>]]></description>
    <pubDate>Thu, 04 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-mitigation-of-runtime-iss</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Lambda scanner now directly sends scan events to File Storage Security backend via API</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-scanner-now-directly-sends</link>
    <description><![CDATA[<div class="p">November 10, 2021, File Storage Security—The Lambda scanner now sends scan events
               to the File Storage Security backend by API instead of AWS SNS topic.</div>]]></description>
    <pubDate>Wed, 10 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-scanner-now-directly-sends</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Container Security Enhances Runtime Visibility and Control Feature</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-enhances-run2</link>
    <description><![CDATA[<div class="p">November 12, 2021, Container Security—Container Security introduces the next iteration
               of <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-runtime-security-" target="_blank">runtime security feature</a> with the new runtime visibility and control feature. This runtime security feature
               provides visibility and mitigation of container activity that violates a customizable
               set of rules. Runtime security includes a set of pre-defined rules that provide visibility
               into MITRE ATT&amp;CK framework tactics for containers as well as container drift detection.
               Runtime security is compatible with Kubernetes and supports Amazon EKS, Microsoft
               Azure AKS, Google GKE, as well as OpenShift.</div>]]></description>
    <pubDate>Fri, 12 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-enhances-run2</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Enhanced Mitigation Capabilities for Container Security Runtime Violations</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-mitigation-capabilities-f</link>
    <description><![CDATA[<div class="p">November 12, 2021, Container Security—Container Security introduces the ability to
               mitigate problems detected by the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-runtime-security-" target="_blank">runtime visibility and control feature</a>, based on a user-customized policy. If a pod violates any rule during runtime, the
               issue is be mitigated by terminating or isolating the pod based on the policy.</div>]]></description>
    <pubDate>Fri, 12 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-mitigation-capabilities-f</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Improved Integration: User Email Addresses Imported Directly into Endpoint &amp; Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-integration-user-email-ad</link>
    <description><![CDATA[<div class="p">November 12, 2021, Workload Security—To further improve integration between Trend
               Cloud One and Trend Cloud One - Endpoint &amp; Workload Security, user email addresses
               from Trend Cloud One will soon be imported directly into Trend Cloud One - Endpoint
               &amp; Workload Security's user properties. This change will mean that the same user cannot
               have a different email in Trend Cloud One and Trend Cloud One - Endpoint &amp; Workload
               Security. Users will still be able to send reports to a custom contact and send alerts
               to a custom email. This change only affects new accounts created on or after August
               4, 2021.</div>]]></description>
    <pubDate>Fri, 12 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-integration-user-email-ad</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>File Storage Security now scans over 50 buckets in the same AWS account</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-scans-ov</link>
    <description><![CDATA[<div class="p">November 16, 2021, File Storage Security—File Storage Security now supports scanning
               more than 50 buckets if the storage stack and scanner stack are in the same AWS account.</div>]]></description>
    <pubDate>Tue, 16 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-scans-ov</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>New Trust Entities feature streamlines software changes and reduces manual management</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-trust-entities-feature-streaml</link>
    <description><![CDATA[<div class="p">November 16, 2021, Workload Security—The new Application Control <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-application-control-trust-entities-" target="_blank">Trust Entities</a> feature for Trend Cloud One - Endpoint &amp; Workload Security is now being rolled out
               in some regions. Trust entities lets you configure trust rules to auto-authorize software
               changes in your environments, reducing the number of software changes and security
               events you need to manage manually. Note that when Trust Entities becomes available
               in your region, you will also see Application Control "Software Rulesets" (previously
               known as "Application Control Rulesets") under Policies &gt; Common Objects &gt; Rules &gt;
               Application Control.</div>]]></description>
    <pubDate>Tue, 16 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-trust-entities-feature-streaml</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Appliance health monitoring with Amazon SNS notifications</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-appliance-health-monitoring-with-a</link>
    <description><![CDATA[<div class="p">November 18, 2021, Network Security—Appliance health monitoring and notifications:
               With an Amazon Simple Notification Service (SNS) subscription, AWS users can configure
               Network Security to send notifications to their Amazon SNS topic when their tenants
               or appliances have health issues. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-performance_notifications-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 18 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-appliance-health-monitoring-with-a</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Conformity introduces Terraform Provider, GCP Onboarding, UX Improvements, and New Rules</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-terraform-pr</link>
    <description><![CDATA[<div class="p">November 19, 2021, Conformity—The following features and updates were released to
               Conformity on 19th November 2021.</div><div class="p">Conformity now available in the Terraform Provider Registry</div><div class="p">Conformity is now supported as a Terraform Provider allowing you to provision and
               manage your Conformity account settings via Terraform templates. The functionality
               includes onboarding and managing AWS and Azure accounts, users, profiles and account
               rule settings, reports, conformity bot frequency, and communication channels. <a class="xref" href="https://registry.terraform.io/providers/trendmicro/conformity/latest" target="_blank">Read more &gt;&gt;</a></div><div class="p">GCP Account Onboarding</div><ul class="ul" id="whatsnew_d2e_518_8e2__ul_941_4d5">
<li class="li">You can now upload a service account key file while Adding a GCP account instead of
                  using the copy and paste option.</li>
</ul><ul class="ul" id="whatsnew_d2e_518_8e2__ul_0f6_13b">
<li class="li">You can also view the number of existing GCP projects added to the service account.</li>
</ul><div class="p">Profiles - UX Improvements</div><ul class="ul" id="whatsnew_d2e_518_8e2__ul_445_b8b">
<li class="li">We’ve updated the ‘Apply to’ dialogue box to be more descriptive of the search function.</li>
</ul><ul class="ul" id="whatsnew_d2e_518_8e2__ul_cc3_c92">
<li class="li">We’ve also updated the Profile Summary page providing clarity around the ‘manually
                  configured’ and ‘available to be configured’ rules.</li>
</ul><ul class="ul" id="whatsnew_d2e_518_8e2__ul_2c1_153">
<li class="li">Additionally, we’ve added a ‘Rule Summary’ section under Rule Settings for individual
                  accounts.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_d2e_518_8e2__ul_fcb_9d5">
<li class="li">Fixed a bug to update the Communication Channel API endpoint to make it consistent
                  with the UI.</li>
</ul><ul class="ul" id="whatsnew_d2e_518_8e2__ul_090_453">
<li class="li">Fixed a bug where incomplete accounts were being displayed in the unmonitored account
                  list on the All accounts tab in the Threat monitoring dashboard.</li>
</ul><ul class="ul" id="whatsnew_d2e_518_8e2__ul_330_916">
<li class="li">Fixed a bug to make Azure conformity bot using consistent region naming for filter
                  and check results.</li>
</ul><ul class="ul" id="whatsnew_d2e_518_8e2__ul_b6e_d3a">
<li class="li">Fixed a bug with validation while creating/updating report configs using the API to
                  check for all items and reject the request on finding any invalid formats in the email
                  array.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">The custom policy has been updated as a result of the new deployment. The current
               custom policy version is 1.34.</div><div class="p">The permission added is:</div><ul class="ul" id="whatsnew_d2e_518_8e2__ul_f23_90b">
<li class="li">config:SelectResourceConfig</li>
</ul><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the latest custom policy</a><div class="p">New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_d2e_518_8e2__ul_758_7e5">
<li class="li">ActiveDirectory-024: Enable Security Defaults: This rule ensures that the Security
                  Defaults feature is enabled for Azure Active Directory (AAD) to help protect your
                  organization from common attacks. It is a set of basic identity security mechanisms
                  recommended by Microsoft and provided at no extra cost in Active Directory.</li>
</ul><ul class="ul" id="whatsnew_d2e_518_8e2__ul_caf_d98">
<li class="li">ActiveDirectory-023: Restrict User Access to AAD Group Features in Azure Access Panel:
                  This rule ensures that the ‘Restrict user ability to access groups features in the
                  Access Panel’ setting is enabled to ascertain that non-privileged users are unable
                  to create and manage security groups using the Azure Access Panel.</li>
</ul><div class="p">Rule Updates</div><ul class="ul" id="whatsnew_d2e_518_8e2__ul_af2_f86">
<li class="li">CS-001: AWS Custom Rule (ConfigService): This rule now allows you to configure the
                  following categories to custom rules. If you’ve not configured a custom category,
                  then the default categories will apply to all custom rules.</li>
</ul><ul class="ul" id="whatsnew_d2e_518_8e2__ul_548_cd4">
<li class="li">Security,</li>
<li class="li">Reliability,</li>
<li class="li">Performance Efficiency,</li>
<li class="li">Cost Optimisation, and</li>
<li class="li">Operational Excellence</li>
</ul><ul class="ul" id="whatsnew_d2e_518_8e2__ul_c1a_f4e">
<li class="li">CloudFormation Rules: Updated this rule to generate a rule failure if a DENY NACL
                  rule is ineffective due to a higher priority ALLOW rule.</li>
</ul><div class="p">Rule Bug Fixes</div><ul class="ul" id="whatsnew_d2e_518_8e2__ul_a2d_bd6">
<li class="li">RDS-005: RDS Encrypted With KMS Customer Master Keys: Fixed bug where the rule was
                  generating false positives when encrypted using AWS default keys.</li>
<li class="li">RDS-007: RDS Multi-AZ: Fixed a bug on RDS-007 such that no check is returned Aurora
                  Serverless DB cluster.</li>
<li class="li">Fixed the bug where RTM did not generate checks for the following rules when an IAM
                  role was created or updated.</li>
<li class="li">IAM-50: Cross-Account Access LAcks External ID and MFA</li>
<li class="li">IAM-057: Check for Untrusted Cross-Account IAM Roles</li>
</ul>]]></description>
    <pubDate>Fri, 19 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-terraform-pr</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Scheduled System Maintenance for Trend Micro Cloud One on December 4th, 2021</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scheduled-system-maintenance-for-t</link>
    <description><![CDATA[<div class="p">November 19, 2021, General—System maintenance for Trend Micro Cloud One is scheduled
               for Saturday December 4th, 2021 between 03:00 and 11:00 UTC. During the maintenance,
               console and API access for certain Trend Micro Cloud One services will be unavailable.
               For more information or to be notified of scheduled maintenance, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central-" target="_blank">Trend Micro Cloud One Maintenance</a>.</div>]]></description>
    <pubDate>Fri, 19 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scheduled-system-maintenance-for-t</guid>
    <category>General</category>
</item>
<item>
    <title>Improved Email Integration for Trend Cloud One User Properties</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-email-integration-for-tre</link>
    <description><![CDATA[<div class="p">November 22, 2021, Workload Security—To further improve integration between Trend
               Cloud One and Trend Cloud One - Endpoint &amp; Workload Security, user email addresses
               from Trend Cloud One are now imported directly into Trend Cloud One - Endpoint &amp; Workload
               Security user properties. This means that the same user cannot have a different email
               in Trend Cloud One and Trend Cloud One - Endpoint &amp; Workload Security. Users can still
               send reports to a custom contact and send alerts to a custom email. This change only
               affects new accounts created on or after August 4, 2021.</div>]]></description>
    <pubDate>Mon, 22 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-email-integration-for-tre</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced azureARMVirtualMachineSummary object in Computers API response includes azureresourceid</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azurearmvirtualmachinesum</link>
    <description><![CDATA[<div class="p">November 24, 2021, Workload Security—The azureARMVirtualMachineSummary object in computers
               API response now includes the azureresourceid, allowing you to get the azureresourceid
               of your Azure VMs by calling Computers API (List Computers).</div>]]></description>
    <pubDate>Wed, 24 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azurearmvirtualmachinesum</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Agent now supports Windows Server 2022</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-now-supports-windows-server</link>
    <description><![CDATA[<div class="p">November 24, 2021, Workload Security—The agent (version 20.0.0-3445+) now supports
               Windows Server 2022. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-supported-features-by-platform-" target="_blank">Supported features by platform</a>.</div>]]></description>
    <pubDate>Wed, 24 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-now-supports-windows-server</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>New API Endpoints, Bug Fixes, Custom Policy, and Rules Enhancements Released on Conformity</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-api-endpoints-bug-fixes-custom</link>
    <description><![CDATA[<div class="p">November 25, 2021, Conformity—The following features and updates will be released
               to Conformity on 29th November 2021.</div><div class="p">New API Endpoints for:</div><div class="p">GCP Account Onboarding</div><ul class="ul" id="whatsnew_bdc_12b_22a__ul_801_a49">
<li class="li">Create GCP Organisation: `POST/gcp/organisations`</li>
<li class="li">Create GCP Account: `POST/accounts/gcp`</li>
<li class="li">List GCP Projects in an Organisation: `GET/v1/gcp/organisations/{id}/projects`</li>
</ul><div class="p">Azure Subscriptions Onboarding</div><ul class="ul" id="whatsnew_bdc_12b_22a__ul_92b_144">
<li class="li">Onboard Azure Active Directory: `POST /azure/active-directories`</li>
<li class="li">List all subscriptions in an onboarded Azure Active Directory: `GET azure/active-directories/{directoryId}/subscriptions`</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_bdc_12b_22a__ul_0be_eed">
<li class="li">Fixed a bug where a Conformity user and a CloudOne user having the same email address
                  trying to reset the password over the Conformity screen was resulting in an error.</li>
<li class="li">Fixed a bug to prevent the same checks from being generated on different GCP projects
                  that are onboarded in the same service account.</li>
</ul><div class="p">Custom Policy Updates</div><ul class="ul" id="whatsnew_bdc_12b_22a__ul_dba_309">
<li class="li">There is no change to the custom policy as a result of the new deployment. The current
                  custom policy version is 1.34. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the latest custom policy</a></li>
</ul><div class="p">New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_bdc_12b_22a__ul_94a_f44">
<li class="li">CloudSQL-004:Enable SSL/TLS for Cloud SQL Incoming Connections: This rule checks whether
                  secure SSL/TLS is used for Incoming Connections to Cloud SQL server database instances.</li>
</ul><ul class="ul" id="whatsnew_bdc_12b_22a__ul_91b_25c">
<li class="li">ComputeEngine-002: Enforce HTTPS Connections for App Engine Applications: This rule
                  ensures that all connections made to your Google App Engine applications are using
                  HTTPS in order to protect against eavesdropping and data exposure.</li>
</ul><div class="p">Rule Updates</div><ul class="ul" id="whatsnew_bdc_12b_22a__ul_55b_0f7">
<li class="li">Route53-011: Remove AWS Route 53 Dangling DNS Records: Updated primary resource from
                  “hosted zone” to “hosted zone's record” to allow-list IPs and record names. Please
                  note that only records with AWS IPs can generate checks.</li>
</ul><div class="p">Note: resourceID has changed from "hosted zone" to "hosted zone-record name" (e.g.
               used to be "/hostedzone/xxxx" and now "/hostedzone/xxxx-domain.com."). You’ll need
               to update the existing resourceID exceptions and suppression settings accordingly.</div><ul class="ul" id="whatsnew_bdc_12b_22a__ul_f3a_992">
<li class="li">RTM now supports RDS DB cluster events rules.</li>
</ul>]]></description>
    <pubDate>Thu, 25 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-api-endpoints-bug-fixes-custom</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved handling of user email addresses in primary contact settings</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-handling-of-user-email-ad</link>
    <description><![CDATA[<div class="p">November 25, 2021, Workload Security—Addressed an issue where Trend Cloud One - Endpoint
               &amp; Workload Security did not keep email addresses for Trend Cloud One users when trying
               to set the primary contact.</div>]]></description>
    <pubDate>Thu, 25 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-handling-of-user-email-ad</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Trend Micro Cloud One now offers pay as you go billing on Azure Marketplace</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-cloud-one-now-offers-p</link>
    <description><![CDATA[<div class="p">November 29, 2021, Billing and Subscription Management—Trend Micro Cloud One is now
               available for purchase with pay as you go billing on the Azure Marketplace. All Cloud
               One services are available, and are billed with the same hourly unit prices as Trend
               Micro Cloud One on AWS Marketplace. For more information see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-billing-subscription-billing--billing-and-subscription-management-subscribe-azure-" target="_blank">Subscribe with Azure - Pay as you Go billing</a>.</div>]]></description>
    <pubDate>Mon, 29 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-cloud-one-now-offers-p</guid>
    <category>Billing and Subscription Management</category>
</item>
<item>
    <title>Enhanced File Storage Security Reporting for Object Keys</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-storage-security-rep</link>
    <description><![CDATA[<div class="p">November 29, 2021, File Storage Security—File Storage Security now supports the ability
               to choose whether to report object key in the scanning events to backend service.</div><div class="p">When deploying stacks in cloud providers, enable the option to see the object keys
               of the malicious objects in the response of events API.</div><div class="p">This functionality requires a stack update.</div>]]></description>
    <pubDate>Mon, 29 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-storage-security-rep</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Select specific availability zones for Network Security protection during deployment</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-select-specific-availability-zones</link>
    <description><![CDATA[<div class="p">November 29, 2021, Network Security—Select availability zones to protect: When deploying
               Network Security using the Get Started wizard, you can now select which availability
               zones you want to protect with Network Security virtual appliances. You can also use
               the APIs to select the availability zones. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-api-reference-tag-AWS-Asset-Discovery#operation-discoverAvailabilityZones" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Mon, 29 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-select-specific-availability-zones</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Agent version 20.0.0.3445 introduces offline scheduled scan and security enhancements</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-version-20003445-introduces</link>
    <description><![CDATA[<div class="p">November 30, 2021, Workload Security—Agent version 20.0.0.3445 has been released.</div><div class="p">Some highlights include:</div><ul class="ul" id="whatsnew_797_5bc_602__ul_5c7_5d0">
<li class="li">Anti-Malware offline scheduled scan: The agent (version 20.0.0-3445+ for Windows)
                  adds the offline scheduled scan feature, enabling Anti-Malware scheduled scans to
                  run while an agent is not connected to Trend Cloud One - Endpoint &amp; Workload Security.
                  This feature is only available to certain Trend Cloud One - Endpoint &amp; Workload Security
                  customers at this time.</li>
<li class="li">Enhancements to database size management, TLS security, and the Application Control
                  <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-application-control-trust-entities-" target="_blank">trust entities</a> feature.</li>
</ul><div class="p">For detailed information on what's included in this version, see <a class="xref" href="https://help.deepsecurity.trendmicro.com/20_0/on-premise/release-notes-dsa.html" target="_blank">What's New in Deep Security Agent</a>.</div>]]></description>
    <pubDate>Tue, 30 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-version-20003445-introduces</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Maintenance for Trend Micro Cloud One rescheduled to December 18, 2021</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-maintenance-for-trend-micro-cloud</link>
    <description><![CDATA[<div class="p">November 30, 2021, General—System maintenance for Trend Micro Cloud One that was previously
               scheduled for December 4, 2021 will now take place Saturday December 18, 2021, between
               03:00 and 11:00 UTC. During the maintenance, console and API access for certain Trend
               Micro Cloud One services will be unavailable. For more information or to be notified
               of scheduled maintenance, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central-" target="_blank">Trend Micro Cloud One Maintenance</a>.</div>]]></description>
    <pubDate>Tue, 30 Nov 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-maintenance-for-trend-micro-cloud</guid>
    <category>General</category>
</item>
<item>
    <title>Allow List for Trusted Namespace Resources in Container Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-allow-list-for-trusted-namespace-r</link>
    <description><![CDATA[<div class="p">December 07, 2021, Container Security—Container Security introduces the ability to
               create an allow list of namespaces whose resources are not monitored, evaluated, or
               mitigated by any policies. Use the allow list to avoid monitoring and receiving events
               from known trusted resources such as the Kubernetes Control plane, Calico, or Istio.</div>]]></description>
    <pubDate>Tue, 07 Dec 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-allow-list-for-trusted-namespace-r</guid>
    <category>Container Security</category>
</item>
<item>
    <title>AWS Storage Stack now supports encryption for SNS ScanResultTopic</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-storage-stack-now-supports-enc</link>
    <description><![CDATA[<div class="p">December 08, 2021, File Storage Security—AWS storage stack now provides the option
               to encrypt the SNS ScanResultTopic. If this option is enabled, the AWS scanner stack
               can also send the scan result to an encrypted topic. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-stack-add-aws-" target="_blank">Add AWS stacks</a>.</div><div class="p">This functionality requires a stack update.</div>]]></description>
    <pubDate>Wed, 08 Dec 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-storage-stack-now-supports-enc</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity now supports LGPD Compliance, adds descriptions to Configured Reports, and introduces new G</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-now-supports-lgpd-compl</link>
    <description><![CDATA[<div class="p">December 10, 2021, Conformity—The following features and updates were released to
               Conformity on 10th November 2021.</div><ul class="ul" id="whatsnew_57d_143_0f2__ul_a0e_e57">
<li class="li">Conformity now supports the LGPD (Brazil) Compliance and Conformity AWS Standard and
                  Framework report.</li>
<li class="li">You can also add a description to all of your Configured Reports.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_57d_143_0f2__ul_ab7_0af">
<li class="li">Fixed a bug where Conformity displayed a blank screen when onboarding a GCP project
                  without correct permissions.</li>
</ul><ul class="ul" id="whatsnew_57d_143_0f2__ul_419_840">
<li class="li">Fixed a bug where the Reports API endpoint returned an error on using the curl -L
                  command.</li>
</ul><ul class="ul" id="whatsnew_57d_143_0f2__ul_8fe_67b">
<li class="li">Fixed a bug to hide admin links in the communication channel recipient configuration
                  screen for non admin users.</li>
</ul><div class="p">Custom Policy Updates</div><ul class="ul" id="whatsnew_57d_143_0f2__ul_75d_19f">
<li class="li">There is no change to the custom policy as a result of the new deployment. The current
                  custom policy version is 1.34. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the latest custom policy</a>.</li>
</ul><div class="p">New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_57d_143_0f2__ul_cdc_608">
<li class="li">CloudSQL-005: Disable 'Cross DB Ownership Chaining' Flag for SQL Server Database Instances:
                  This rule ensures that SQL Server database instances have 'cross db ownership chaining'
                  flag set to Off.</li>
</ul><ul class="ul" id="whatsnew_57d_143_0f2__ul_775_a6e">
<li class="li">CloudSQL-006: Disable 'Contained Database Authentication' Flag for SQL Server Database
                  Instances: This rule ensures that SQL Server database instances have 'contained database
                  authentication' flag set to Off.</li>
</ul><ul class="ul" id="whatsnew_57d_143_0f2__ul_6f5_ab5">
<li class="li">CloudSQL-007: Disable "log_min_duration_statement" Flag for PostgreSQL Database Instances:This
                  rule ensures that PostgreSQL database instances have "log_min_duration_statement"
                  flag set to -1 (Off).</li>
</ul><ul class="ul" id="whatsnew_57d_143_0f2__ul_181_d1c">
<li class="li">CloudKMS-002: New Rule: Rotate Google Cloud KMS Keys: This rule ensures that all KMS
                  cryptographic keys available within your Google Cloud account are regularly rotated.</li>
</ul><ul class="ul" id="whatsnew_57d_143_0f2__ul_f54_c12">
<li class="li">CloudIAM-002: Enforce Separation of Duties for Service-Account Related Roles:This
                  rule ensures that separation of duties is implemented for all Google Cloud service
                  account roles.</li>
</ul><div class="p">Azure</div><ul class="ul" id="whatsnew_57d_143_0f2__ul_ac0_4be">
<li class="li">AccessControl-002: Resource Locking Administrator Role: This rule ensures that there
                  is a custom IAM role assigned to manage resource locking within each Microsoft Azure
                  subscription.</li>
</ul><div class="p">Rule Updates</div><ul class="ul" id="whatsnew_57d_143_0f2__ul_f19_3e4">
<li class="li">Inspector-001: Amazon Inspector Findings: This rule now returns EC2 instance tags
                  and finding attributes (tags) related to the finding as part of the check tags data.
                  EC2 instance tags and inspector finding attributes can be disabled or enabled within
                  the rule configuration. Both of these are enabled by default.</li>
</ul><ul class="ul" id="whatsnew_57d_143_0f2__ul_2a4_3e3">
<li class="li">Advisor-001: Check for Azure Advisor Recommendations: This rule now displays checks
                  under the relevant categories when trying to filter, report or calculate scores for
                  each pillar instead of appearing under all 5 categories.</li>
</ul>]]></description>
    <pubDate>Fri, 10 Dec 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-now-supports-lgpd-compl</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Threat Insights show top network traffic regions for better geolocation filtering</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-threat-insights-show-top</link>
    <description><![CDATA[<div class="p">December 15, 2021, Network Security—Insights into the countries and regions that most
               threaten your network: Network Security's Threat Insights now display the top five
               regions or countries that generate the most traffic events in your network. This insight
               enables you to refine your geolocation filtering policy. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-threat_insights" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Wed, 15 Dec 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-threat-insights-show-top</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Improved detection of expired objects in Trend Cloud One - Endpoint &amp; Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-detection-of-expired-obje</link>
    <description><![CDATA[<div class="p">December 16, 2021, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               was sending suspicious objects to the agent even after the objects' expire time had
               ended.</div>]]></description>
    <pubDate>Thu, 16 Dec 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-detection-of-expired-obje</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>File Storage Security console now shows malicious events in scan history chart</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-console-now</link>
    <description><![CDATA[<div class="p">December 27, 2021, File Storage Security—The File Storage Security console now displays
               malicious events below the scan history chart.</div>]]></description>
    <pubDate>Mon, 27 Dec 2021 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-console-now</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Container Security now supports multi-property rule statements, deprecating single-property rules</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-now-supports-mu</link>
    <description><![CDATA[<div class="p">January 04, 2022, Container Security—Container Security Policies API rule statements
               with a single property are deprecated and replaced by multi-properties rule statements.
               Single-property rule statements will be completely removed by February 1, 2022.</div>]]></description>
    <pubDate>Tue, 04 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-now-supports-mu</guid>
    <category>Container Security</category>
</item>
<item>
    <title>AWS scan results now include S3 request ID for improved security monitoring</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-scan-results-now-include-s3-re</link>
    <description><![CDATA[<div class="p">January 06, 2022, File Storage Security—The AWS scan result now includes the S3 request
               ID in `xamz_request_id`.</div>]]></description>
    <pubDate>Thu, 06 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-scan-results-now-include-s3-re</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Exclude files from Anti-Malware scanning based on digital certificates (Windows only)</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-exclude-files-from-anti-malware-sc</link>
    <description><![CDATA[<div class="p">January 06, 2022, Workload Security—You can now exclude files from Anti-Malware scanning
               based on their digital certificate. This feature is currently supported for agent
               version 20.0.0-3445+ on Windows platforms only. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-anti-malware-exceptions-#exclude-cert" target="_blank">Exclude files signed by a trusted certificate</a>.</div>]]></description>
    <pubDate>Thu, 06 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-exclude-files-from-anti-malware-sc</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved GCP account addition for non-US Trend Cloud One users</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-gcp-account-addition-for</link>
    <description><![CDATA[<div class="p">January 06, 2022, Workload Security—Fixed an issue where some customers in <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--identity-and-account-management-c1-regions-" target="_blank">Trend Cloud One regions</a> outside of the US were not able to add a GCP account to Trend Cloud One - Endpoint
               &amp; Workload Security.</div>]]></description>
    <pubDate>Thu, 06 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-gcp-account-addition-for</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Offline Scheduled Scans now supported for Windows agents</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-offline-scheduled-scans-now-suppor</link>
    <description><![CDATA[<div class="p">January 06, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               now provides an option that enables agents to run scheduled scans when the agent is
               offline and can't access Trend Cloud One - Endpoint &amp; Workload Security. This feature
               is supported with agent version 20.0.3445+ on Windows platforms. See <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-anti-malware-scan-configure-#run-scheduled-scans-when-workload-security-is-not-accessible" target="_blank">Run scheduled scans when Trend Cloud One - Endpoint &amp; Workload Security is not accessible</a>.</div>]]></description>
    <pubDate>Thu, 06 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-offline-scheduled-scans-now-suppor</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>New GCP and Azure rules, bug fixes, and custom policy update in Conformity</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-and-azure-rules-bug-fixes</link>
    <description><![CDATA[<div class="p">January 19, 2022, Conformity—The following features and updates were released to Conformity
               on 19 January 2022.</div><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_17f_7af">
<li class="li">The Jira communication channel configuration modal now displays an error message when
                  the test ticket cannot be transitioned properly when testing a configuration.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_d82_ebd">
<li class="li">Fixed a bug with the JIRA ticket workflows not resolving properly when the workflow
                  has a screen attached to the Done transition and the screen has a required field (for
                  example resolution)</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_3d0_107">
<li class="li">Fixed a bug that was causing 'Resource' &amp; 'Introduced by' fields to be included by
                  default in slack notification messages from Conformity even though the default configuration
                  displayed in the UI indicated otherwise.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_2db_825">
<li class="li">Fixed a bug to enable an Admin user to invite a Cloud One Conformity user to a Conformity
                  direct organization.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_008_ea5">
<li class="li">Fixed a bug where ‘Disable’ and ‘Remove’ buttons were being pushed out of the screen
                  when there were multiple safe listed IP addresses for an API key.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_fd8_e09">
<li class="li">Fixed a bug where previously suppressed checks were displayed as unsuppressed on an
                  update to group settings or to azure access settings.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_6ac_fae">
<li class="li">Fixed an issue wherein the ‘View by Resources’ tab, not scored checks were displaying
                  and counting as failed checks.</li>
</ul><div class="p">Custom Policy Updates</div><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_3fd_b15">
<li class="li">The custom policy has been updated as a result of the new deployment. The current
                  custom policy version is 1.35. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the latest custom policy</a>.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_ffd_ca4">
<li class="li">The permission added is: ‘iam:GetAccountAuthorizationDetails’</li>
</ul><div class="p">New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_4f8_f2d">
<li class="li">ComputeEngine-003: Disable Interactive Serial Console Support: This rule ensures that
                  interactive serial console support is disabled for all your production Google Compute
                  Engine instances.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_c7f_1f1">
<li class="li">ComputeEngine-004: Disable IP Forwarding for Virtual Machine Instances: This rule
                  ensures that the IP Forwarding feature is disabled at the Google Compute Engine instance
                  level for security and compliance reasons, as instances with IP Forwarding enabled
                  to act as routers/packet forwarders.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_e60_b93">
<li class="li">CloudSQL-008: Enable 'log_connections' Flag for PostgreSQL Database Instances:This
                  rule ensures that PostgreSQL database instances have the 'log_connections' configuration
                  flag enabled.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_934_61d">
<li class="li">CloudSQL-009: Enable "log_disconnections" Flag for PostgreSQL Database Instances:
                  This rule ensures that PostgreSQL database instances have the "log_disconnections"
                  flag enabled.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_094_fbb">
<li class="li">CloudSQL-010: Enable "log_checkpoints" Flag for PostgreSQL Database Instances: This
                  rule ensures that PostgreSQL database instances have "log_checkpoints" flag enabled.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_b7c_a01">
<li class="li">CloudSQL-011: Enable "log_lock_waits" Flag for PostgreSQL Database Instances: This
                  rule ensures that PostgreSQL database instances have the "log_lock_waits" flag enabled.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_3dc_e50">
<li class="li">CloudSQL-012: Enable 'log_temp_files' Flag for PostgreSQL Database Instances: This
                  rule ensures that "log_temp_files" database flag is set to 0 (enabled) for all your
                  Google Cloud PostgreSQL database instances.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_fa4_b10">
<li class="li">CloudSQL-013: Configure "log_min_error_statement" Flag for PostgreSQL Database Instances:
                  This rule ensures that PostgreSQL database instances have the appropriate configuration
                  set for the "log_min_error_statement" flag.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_1d6_218">
<li class="li">CloudSQL-014: Disable "local_infile" Flag for MySQL Database Instances: This rule
                  ensures that MySQL database instances have the "local_infile" flag disabled.</li>
</ul><div class="p">Azure</div><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_06f_2a2">
<li class="li">AppService-017: Disable Plain FTP Deployment: This rule ensures that your Microsoft
                  Azure App Services web applications are not configured to be deployed over plain FTP.
                  Instead, the deployment can be disabled over FTP or performed over FTPS. FTPS (Secure
                  FTP) is used to enhance security for your Azure web application as it adds an extra
                  layer of security to the FTP protocol and helps you to comply with industry standards
                  and regulations.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_02a_d03">
<li class="li">VirtualMachines-036: Use Customer Managed Keys for Virtual Hard Disk Encryption: This
                  rule ensures that your Microsoft Azure Virtual Hard Disk (VHD) volumes are using Customer
                  Managed Keys (CMKs) instead of Platform-Managed Keys (PMKs – default keys used by
                  Microsoft Azure for disk encryption) in order to have full control over your VHD data
                  encryption and decryption process.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_04c_b94">
<li class="li">Network-015 (Check for Unrestricted UDP Access)e: This rule ensures that Microsoft
                  Azure network security groups (NSGs) do not allow unrestricted inbound access (i.e.
                  0.0.0.0/0) on UDP ports.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_049_72b">
<li class="li">ActivityLog-027 (Create Alert for "Delete Policy Assignment" Events): This rule ensures
                  that an Azure activity log alert is used to detect "Delete Policy Assignment" events.</li>
</ul><div class="p">Rule Updates</div><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_a06_ae5">
<li class="li">RDS-023: Amazon RDS Public Snapshots: We’ve updated this rule to prevent stale checks
                  due to throttling.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_9ab_3a4">
<li class="li">Updated the following rules so that checks won't be deleted if triggered by DeleteAccessKey,
                  DeleteServiceSpecificCredential, DeleteSigningCertificate, DeleteLoginProfile, DeletePolicyVersion
                  events:</li>
<li class="li">IAM-004: Unnecessary Access Keys</li>
<li class="li">IAM-013: MFA For IAM Users With Console Password</li>
<li class="li">IAM-016: IAM User Policies</li>
<li class="li">IAM-024: IAM User With Password And Access Keys</li>
<li class="li">IAM-025: Unnecessary SSH Public Keys</li>
<li class="li">IAM-028: Inactive IAM Console User</li>
<li class="li">IAM-029: Unused IAM User</li>
<li class="li">IAM-036: AWS IAM Users with Admin Privileges</li>
<li class="li">IAM-058: Check that only safelisted IAM Users exist</li>
<li class="li">IAM-070: Check for IAM User Group Membership</li>
<li class="li">IAM-071: Receive Permissions via IAM Groups Only</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_8b7_fa1">
<li class="li">SSM-003:Check for SSM Managed Instances: Fixed a bug where the checks were generated
                  for EC2 instances in a state that is not pending or running.</li>
</ul><ul class="ul" id="whatsnew_fc4_6ae_47c__ul_ceb_428">
<li class="li">Fixed a bug that prevented RTM from generating checks for the following rules when
                  DB cluster events are triggered:</li>
<li class="li">RDS-007: RDS Multi-AZ</li>
<li class="li">RDS-035: Cluster Deletion Protection</li>
<li class="li">RDS-042: Enable Aurora Cluster Copy Tags to Snapshots</li>
</ul>]]></description>
    <pubDate>Wed, 19 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-and-azure-rules-bug-fixes</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Legacy platform agent support now has defined EOL dates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-legacy-platform-agent-support-now</link>
    <description><![CDATA[<div class="p">January 21, 2022, Workload Security—Agent support for some legacy platforms had been
               extended annually. Those platforms now have a defined EOL date. For detailed EOL dates,
               see Support extensions in <a class="xref" href="https://help.deepsecurity.trendmicro.com/20_0/on-premise/dates-lts.html" target="_blank">Deep Security LTS lifecycle dates</a>.</div>]]></description>
    <pubDate>Fri, 21 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-legacy-platform-agent-support-now</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity now supports CIS Benchmarks for AWS Foundations 1.4 Standard and Framework</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-now-supports-cis-benchm</link>
    <description><![CDATA[<div class="p">January 22, 2022, Conformity—The following features and updates are now available
               with Conformity's latest release on 27 January 2022.</div><ul class="ul" id="whatsnew_908_7b9_0ee__ul_051_d20">
<li class="li">Conformity now supports CIS Benchmarks for AWS Foundations 1.4 Standard and Framework
                  report.</li>
</ul><ul class="ul" id="whatsnew_908_7b9_0ee__ul_8b0_bff">
<li class="li">Added a new property to ‘GET /v1/azure/active-directories/{id}/subscriptions’ to indicate
                  whether or not a subscription has been onboarded onto Conformity.</li>
</ul><ul class="ul" id="whatsnew_908_7b9_0ee__ul_ef2_6fa">
<li class="li">Enhanced Rule Settings &gt; Configure Rule on account level to exclude matched resources
                  between the Conformity Bot runs.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_908_7b9_0ee__ul_172_3f4">
<li class="li">Fixed an issue where a longer account name displayed a broken HTML tag on the RTM
                  dashboard.</li>
</ul><ul class="ul" id="whatsnew_908_7b9_0ee__ul_388_9da">
<li class="li">Fixed incorrect sample requests for the 'Update Rule Setting' and the 'Update Rule
                  Settings' APIs.</li>
</ul><ul class="ul" id="whatsnew_908_7b9_0ee__ul_759_169">
<li class="li">Fixed an issue where reports generated in "Improve compliance across your organisation"
                  were not saved in the ‘Other Reports - History’ section.</li>
</ul><div class="p">Custom Policy Updates</div><ul class="ul" id="whatsnew_908_7b9_0ee__ul_77f_d02">
<li class="li">There is no change to the custom policy as a result of the new deployment. The current
                  custom policy version is 1.35. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</li>
</ul><div class="p">New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_908_7b9_0ee__ul_921_2d9">
<li class="li">ComputeEngine-005: Enable "Shielded VM" Security Feature: This rule ensures that the
                  ‘Shielded VM’ feature is enabled for your virtual machine (VM) instances.</li>
</ul><ul class="ul" id="whatsnew_908_7b9_0ee__ul_e1a_0d8">
<li class="li">ComputeEngine-006: Check for Instances Associated with Default Service Accounts: This
                  rule ensures that your VM instances are not associated with the default GCP service
                  account.</li>
</ul><ul class="ul" id="whatsnew_908_7b9_0ee__ul_586_e49">
<li class="li">ComputeEngine-008: Check for Instance-Associated Service Accounts with Full API Access:This
                  rule ensures that VM instances are not associated with default service accounts that
                  allow full access to all Google Cloud APIs.</li>
</ul><ul class="ul" id="whatsnew_908_7b9_0ee__ul_d40_572">
<li class="li">CloudIAM-003: Check for IAM Members with Service Roles at the Project Level: This
                  rule ensures that the Service Account User and Service Account Token Creator roles
                  are assigned to a user for a specific GCP service account rather than to a user at
                  the GCP project level.</li>
</ul><div class="p">Bug Fix</div><ul class="ul" id="whatsnew_908_7b9_0ee__ul_697_70a">
<li class="li">S3-025: S3 Buckets Encrypted with Customer-Provided CMKs: Fixed a bug where the disabled
                  rule was generating checks.</li>
</ul>]]></description>
    <pubDate>Sat, 22 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-now-supports-cis-benchm</guid>
    <category>Conformity</category>
</item>
<item>
    <title>App.deepsecurity.trendmicro.com login page to be removed, redirects to cloudone.trendmicro</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-appdeepsecuritytrendmicrocom-login</link>
    <description><![CDATA[<div class="p">January 24, 2022, Workload Security—Trend Micro will soon remove the app.deepsecurity.trendmicro.com
               login page for Trend Cloud One - Endpoint &amp; Workload Security and will redirect all
               visitors to cloudone.trendmicro.com. Please use your existing credentials to sign
               in to Trend Cloud One at cloudone.trendmicro.com.</div><div class="p">Note: This change does not affect accounts using SAML single sign-on.</div>]]></description>
    <pubDate>Mon, 24 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-appdeepsecuritytrendmicrocom-login</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>New Deployment Rules Enhance Container Security in Kubernetes</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-deployment-rules-enhance-conta</link>
    <description><![CDATA[<div class="p">January 25, 2022, Container Security—Container Security introduced two new deployment
               rules to protect running containers from attacks via Kubernetes credentials or misconfigured
               role-based access control. With these two rules, you can log or block attempts to
               run a command in a container using kubectl exec or to add port forwarding using kubectl
               port-forward. Trend Micro recommends enabling these rules to protect privileged containers
               and containers with confidential information.</div>]]></description>
    <pubDate>Tue, 25 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-deployment-rules-enhance-conta</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Improved usability for New Ruleset window in Trust Entities section</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-usability-for-new-ruleset</link>
    <description><![CDATA[<div class="p">January 25, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security's
               trust entities New Ruleset window (Application Control Rulesets &gt; Trust Entities &gt;
               Trust Ruleset &gt; New) had its "OK" and "Close" buttons blocked on some screen resolutions.</div>]]></description>
    <pubDate>Tue, 25 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-usability-for-new-ruleset</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Discontinuation of Free 5 Computers License for Trend Micro Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-discontinuation-of-free-5-computer</link>
    <description><![CDATA[<div class="p">January 27, 2022, Workload Security—Trend Micro will soon be discontinuing the "Free
               - Maximum 5 Protected Computers" license offering for Trend Cloud One - Endpoint &amp;
               Workload Security and Deep Security as a Service. Customers currently using this license
               option will need to transition to a supported payment option before March 15th, 2022
               to avoid any potential interruption of service. Please see <a class="xref" href="https://success.trendmicro.com/en-us/solution/ka-0012741" target="_blank">Free - 5 Computers End of Support for Trend Micro Cloud One - Workload Security and
                  Deep Security as a Service</a> for more information.</div>]]></description>
    <pubDate>Thu, 27 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-discontinuation-of-free-5-computer</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Redesigned Sign-in Page with Videos, Customer References, and Resources Available Soon</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-redesigned-sign-in-page-with-video</link>
    <description><![CDATA[<div class="p">January 27, 2022, General—Very soon you're going to see something quite different
               when you go to <a class="xref" href="https://cloudone.trendmicro.com/" target="_blank">https://cloudone.trendmicro.com/</a> to sign in. We're redesigning this page and adding videos, customer references, resource
               links, and other content to help you really see how much you can do with Trend Micro
               Cloud One.</div><div class="p">Don't worry  it will still be easy for you to sign in from this new page but you can
               also bookmark <a class="xref" href="https://cloudone.trendmicro.com/signin" target="_blank">https://cloudone.trendmicro.com/signin</a> if you'd rather go directly to the sign-in page. But we are hoping you will like
               the new page and the new content!</div><div class="p">And while we have your attention, why not go check out our recently redesigned <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central--" target="_blank">Trend Micro Cloud One Docs</a> page? We have freshened up the design of that page and added more resources for you.</div>]]></description>
    <pubDate>Thu, 27 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-redesigned-sign-in-page-with-video</guid>
    <category>General</category>
</item>
<item>
    <title>Test Network Security features with free interactive demo</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-test-network-security-features-wit</link>
    <description><![CDATA[<div class="p">January 28, 2022, Network Security—Put Network Security to the test: Network Security
               now offers the option to try out features, such as malware blocking and vulnerability
               shielding, in a free dedicated test environment. With this Interactive demo, Trend
               Micro creates an environment in AWS to test out simulated attacks. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Interactive_demo" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Fri, 28 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-test-network-security-features-wit</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Enhanced Network Security with Real-Time Threat Protection</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-network-security-with-rea</link>
    <description><![CDATA[<div class="p">January 28, 2022, Network Security—Protect your network from the latest threats: Select
               Policy &gt; Emerging Threats for up-to-date information on ongoing threats to your environment
               and for best practices you can take to protect your network from them. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-emerging_threats-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Fri, 28 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-network-security-with-rea</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Agents now connect to XDR Activity Monitoring using Trend Cloud One regions for improved connectivity</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agents-now-connect-to-xdr-activity</link>
    <description><![CDATA[<div class="p">January 28, 2022, Workload Security—New agents now use a domain from your <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--identity-and-account-management-c1-regions-" target="_blank">Trend Cloud One region</a> to connect to XDR activity monitoring rather than an AWS provided domain. Agents
               that have already connected to XDR Activity Monitoring will be transitioned to use
               the new URL on April 4, 2022. Agents that have been unable to connect to XDR Activity
               Monitoring will be updated with the new URL earlier in the transition period to fix
               connectivity issues.</div><div class="p">Why is Trend making this change?</div><div class="p">Trend Micro is transitioning the URLs used for XDR Activity Monitoring from AWS-provided
               FQDNs to FQDNs for your Trend Cloud One region. This means you do not have to keep
               an entry in your firewall allowlist for the AWS-provided URL, and can simply rely
               on your existing entry if you have one.</div><div class="p">How do I know whether I need to change something in my environment? What should I
               change?</div><div class="p">If you do not filter outbound traffic, there is no action required. If you filter
               outbound traffic in your environment:</div><ul class="ul" id="whatsnew_ebd_fb8_ac5__ul_2b8_93b">
<li class="li">If you are already allowlisting the wildcard domain for your region (for example,
                  *.workload.us-1.cloudone.trendmicro.com), there is no action required. After the transition
                  period, your agents that connect to Activity Monitoring will automatically update
                  to use the new URL during their next communication with Trend Cloud One - Endpoint
                  &amp; Workload Security.</li>
<li class="li">If you cannot allowlist wildcard domains, you must add the FQDN starting with `agent-comm`
                  for your Trend Cloud One region to your firewall's allowlist. This FQDN is listed
                  on the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-communication-ports-urls-ip-#FQDNs" target="_blank">Port numbers, URLs, and IP addresses</a> page.</li>
</ul>]]></description>
    <pubDate>Fri, 28 Jan 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agents-now-connect-to-xdr-activity</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Correct User IP Address Displayed in Trend Cloud One - Endpoint &amp; Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-correct-user-ip-address-displayed</link>
    <description><![CDATA[<div class="p">February 04, 2022, Workload Security—Updated Trend Cloud One - Endpoint &amp; Workload
               Security to display the correct user IP address during authentication. The console
               previously recorded the CloudFront IP address in authentication-related logs, such
               as the user sign in event. This issue only affected new accounts created on or after
               August 4, 2021.</div>]]></description>
    <pubDate>Fri, 04 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-correct-user-ip-address-displayed</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>File Storage Security now shows time strings in user-specific time zone</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-shows-ti</link>
    <description><![CDATA[<div class="p">February 07, 2022, File Storage Security—The File Storage Security console now displays
               time strings in the specific time zone based on CloudOne Account Settings.</div>]]></description>
    <pubDate>Mon, 07 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-shows-ti</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Network Security Virtual Appliance Upgraded with Critical Security and Performance Improvements</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-network-security-virtual-appliance</link>
    <description><![CDATA[<div class="p">February 10, 2022, Network Security—Network Security virtual appliance version 2022.1.0.11311
               includes important security and performance enhancements.</div>]]></description>
    <pubDate>Thu, 10 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-network-security-virtual-appliance</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Automated Verification of Network Asset Prerequisites Before Deployment</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automated-verification-of-network</link>
    <description><![CDATA[<div class="p">February 10, 2022, Network Security—Verify network asset prerequisites: You can now
               automatically verify that all of the prerequisites required for deployment are met
               before you deploy using the Get Started wizard. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-aws_deploy_protection_checklist-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Thu, 10 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automated-verification-of-network</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Conformity resolves AWS data retrieval errors impacting IAM and TrustedAdvisor checks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-resolves-aws-data-retri</link>
    <description><![CDATA[<div class="p">February 11, 2022, Conformity—From approximately 00:30 UTC 19 January 2022 to approximately
               10:00 UTC 10 February 2022, Conformity experienced data retrieval errors for the AWS
               IAM and TrustedAdvisor services, which resulted in missing checks for certain rules.
               The issues have now been resolved and the affected checks have been regenerated.</div><div class="p">Incident Summary</div><div class="p">Due to changes deployed on 19 January to how Conformity handles certain AWS credentials,
               AWS Conformity Bot was not able to retrieve certain resource data for two AWS services.
               These changes affected rules dependent upon AWS TrustedAdvisor Checks and IAM Credential
               Reports.</div><div class="p">Impact</div><div class="p">Checks related to the AWS Trusted Advisor and IAM Credential Report services were
               removed and deleted by Conformity Bot due to not being able to retrieve any resources
               for these services. The following IAM and TrustAdvisor rules were affected:</div><div class="p">IAM Rules</div><ul class="ul" id="whatsnew_67c_fae_b56__ul_3f8_9fa">
<li class="li">IAM-055: Canary Access Token</li>
<li class="li">IAM-048:  Root Account Active Signing Certificates</li>
<li class="li">IAM-042: Hardware MFA for AWS Root Account</li>
<li class="li">IAM-041:IAM User Password Expiry 45 Days</li>
<li class="li">IAM-040: IAM User Password Expiry 30 Days</li>
<li class="li">IAM-039: IAM User Password Expiry 7 Day</li>
<li class="li">IAM-035: Root Account Usage</li>
<li class="li">IAM-003: Credentials Last Used</li>
</ul><div class="p">TrustedAdvisor Rules</div><ul class="ul" id="whatsnew_67c_fae_b56__ul_a9c_372">
<li class="li">TrustedAdvisor-001: Trusted Advisor Service Limits</li>
<li class="li">TrustedAdvisor-002: Trusted Advisor Checks</li>
<li class="li">TrustedAdvisor-003:  Exposed IAM Access Keys</li>
</ul><div class="p">Resolution</div><div class="p">We’ve improved how Conformity Bot handles the way we retrieve TrustedAdvisor Checks
               and IAM Credential Reports to be compatible with the changes we introduced in January
               2022.</div>]]></description>
    <pubDate>Fri, 11 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-resolves-aws-data-retri</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Option to Disable Malware Scanning Added for Faster Container Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-option-to-disable-malware-scanning</link>
    <description><![CDATA[<div class="p">February 14, 2022, Container Security—Trend Micro learned that malware scanning is
               not always a useful use case for customers, especially given the potential for a very
               long scan time. Trend Micro has added the ability to disable malware scanning as an
               option.</div>]]></description>
    <pubDate>Mon, 14 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-option-to-disable-malware-scanning</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Real-time Integrity Monitoring now generates delete events for edited files</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-real-time-integrity-monitoring-now</link>
    <description><![CDATA[<div class="p">February 15, 2022, Workload Security—With real-time Integrity Monitoring enabled,
               Integrity Monitoring delete events were not being generated for files that were edited
               before being deleted.</div>]]></description>
    <pubDate>Tue, 15 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-real-time-integrity-monitoring-now</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved Deep Security Agent now displays accurate host IP addresses</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-deep-security-agent-now-d</link>
    <description><![CDATA[<div class="p">February 15, 2022, Workload Security—Updated Deep Security Agent to correctly display
               the host's IP address in the "LastIpUsed" field. Previously, the field displayed the
               load balancer or proxy IP in environments using one of those.</div>]]></description>
    <pubDate>Tue, 15 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-deep-security-agent-now-d</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>New Google Cloud Platform rules and bug fixes enhance Conformity&#x27;s security and compliance capabilities</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-google-cloud-platform-rules-an</link>
    <description><![CDATA[<div class="p">February 16, 2022, Conformity—The following features and updates are now available
               with Conformity's latest release on 16 February 2022.</div><div class="p">Bug Fix</div><ul class="ul" id="whatsnew_c31_5d2_041__ul_a09_0b0">
<li class="li">Fixed a bug where the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Accounts-#paths-~1accounts~1%7Bid%7D~1settings~1rules-patch" target="_blank">PATCH Rule Settings API endpoint</a> was returning an error when the request had misplaced exception attributes.</li>
</ul><div class="p">Custom Policy Updates</div><ul class="ul" id="whatsnew_c31_5d2_041__ul_66d_bba">
<li class="li">There is no change to the custom policy as a result of the new deployment. The current
                  custom policy version is 1.35. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</li>
</ul><div class="p">New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_c31_5d2_041__ul_c9e_7b9">
<li class="li">CloudSQL-015: Check for Publicly Accessible Cloud SQL Database Instances: This rule
                  ensures that your Google Cloud SQL database instances are configured to accept connections
                  from trusted networks and IP addresses only.</li>
</ul><ul class="ul" id="whatsnew_c31_5d2_041__ul_3ca_48b">
<li class="li">ComputeEngine-007: Enable VM Disk Encryption with Customer-Supplied Encryption Keys:
                  This rule ensures that the disks attached to your production Google Compute Engine
                  instances are encrypted with Customer-Supplied Encryption Keys (CSEKs).</li>
</ul><ul class="ul" id="whatsnew_c31_5d2_041__ul_e0d_e16">
<li class="li">CloudIAM-004: Delete User-Managed Service Account Keys:This rule ensures that VM instances
                  are not associated with default service accounts that allow full access to all Google
                  Cloud APIs.</li>
</ul><div class="p">Rules Updates</div><ul class="ul" id="whatsnew_c31_5d2_041__ul_d0a_374">
<li class="li">Firehose-001: Firehose Delivery Stream Destination Encryptions: This rule has been
                  updated to specify the relevant encryption type. The rule ensures that Firehose delivery
                  stream data records are encrypted at the destination.</li>
</ul><ul class="ul" id="whatsnew_c31_5d2_041__ul_fc5_31a">
<li class="li">Lambda-001: Lambda Runtime Environment Version: Customers can now configure the end
                  of support runtime in the rule settings.</li>
</ul><div class="p">Rule Bug Fixes</div><ul class="ul" id="whatsnew_c31_5d2_041__ul_4ca_93a">
<li class="li">ECS-002: ECS Task Log Driver In Use: Fixed a bug where the disabled rule was generating
                  checks.</li>
</ul><ul class="ul" id="whatsnew_c31_5d2_041__ul_7ff_e92">
<li class="li">ECS-003: ECS Configuration Changes: We've fixed a bug where Conformity Bot was unable
                  to correctly scan ECS Clusters.</li>
</ul>]]></description>
    <pubDate>Wed, 16 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-google-cloud-platform-rules-an</guid>
    <category>Conformity</category>
</item>
<item>
    <title>File Storage Security now includes scan start timestamp in scan result</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-includes</link>
    <description><![CDATA[<div class="p">February 21, 2022, File Storage Security—The scan result now includes the timestamp
               when the scan started in `scan_start_timestamp`.</div>]]></description>
    <pubDate>Mon, 21 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-includes</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced Container Security: Detects kubectl exec and kubectl attach Usage</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-container-security-detect</link>
    <description><![CDATA[<div class="p">February 22, 2022, Container Security—Container Security extends the coverage of existing
               kubectl exec rule. Now the deployment rule detects the usage of both kubectl exec
               and kubectl attach. Trend Micro recommends enabling this rule to prevent access to
               privileged containers and containers with confidential information.</div>]]></description>
    <pubDate>Tue, 22 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-container-security-detect</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Scheduled Network Security Maintenance Update on March 1st, 2022</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scheduled-network-security-mainten</link>
    <description><![CDATA[<div class="p">February 23, 2022, Network Security—Network Security is making a scheduled maintenance
               update on March 1st, 2022, between 19:00 and 23:00 (UTC). This update might temporarily
               cause API error messages to display during the update. Traffic inspection is not affected
               by this scheduled maintenance.</div>]]></description>
    <pubDate>Wed, 23 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scheduled-network-security-mainten</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Container Security rules now enforce undefined context fields, pod-level rule deprecated</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-rules-now-enfor</link>
    <description><![CDATA[<div class="p">February 24, 2022, Container Security—Rules that are based on a container security
               context field are now in violation when that field is undefined. This affects rules
               for containers that are permitted to run as root, for containers with privilege escalation
               rights, and for containers that can write to the root filesystem. Also, the pod-level
               rule for containers that run as root is now deprecated and covered by the corresponding
               container-level rule. The container-level rule for containers that are permitted to
               run as root evaluates both the pod and container security context.</div>]]></description>
    <pubDate>Thu, 24 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-rules-now-enfor</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Enhanced Coverage for Stratum Protocol and Privilege Escalation Detection</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-coverage-for-stratum-prot</link>
    <description><![CDATA[<div class="p">February 25, 2022, Container Security—Container Security extends the coverage of two
               existing runtime rules. The rule "(T1496)Detect crypto miners using the Stratum protocol"
               now provides coverage for variants of the stratum protocol. The rule "(T1068)Sudo
               Potential Privilege Escalation" improves its detection of privilege escalation.</div>]]></description>
    <pubDate>Fri, 25 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-coverage-for-stratum-prot</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Expanded SAML Single Sign-On across all Cloud One products</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-expanded-saml-single-sign-on-acros</link>
    <description><![CDATA[<div class="p">February 25, 2022, General—It will be possible to log into all of Cloud One using
               Security Assertion Markup Language (SAML). Previously, only Cloud One Workload Security
               supported single-sign on via SAML.</div>]]></description>
    <pubDate>Fri, 25 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-expanded-saml-single-sign-on-acros</guid>
    <category>General</category>
</item>
<item>
    <title>Container Security enhances protection with new runtime rule for Linux namespace switch</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-enhances-protec</link>
    <description><![CDATA[<div class="p">February 28, 2022, Container Security—Container Security introduces new runtime rule
               "(T1611) Switch Linux namespace". The new rule provides coverage of unauthorized usage
               of setns syscalls, which could lead to container escape.</div>]]></description>
    <pubDate>Mon, 28 Feb 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-enhances-protec</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Relays now optimized for efficiency and speed in preview release</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-relays-now-optimized-for-efficienc</link>
    <description><![CDATA[<div class="p">March 01, 2022, Workload Security—Major improvements to relays were introduced with
               agent version 20.0.0-3445+. These changes are in still in preview and are only available
               for certain Trend Cloud One - Endpoint &amp; Workload Security customers at this time.</div><div class="p">Earlier versions of the relay downloaded every agent software package supported by
               Trend Cloud One - Endpoint &amp; Workload Security (all versions, all platforms). This
               took approximately 400 GB of disk space and the download could take several hours
               to complete.</div><div class="p">Relays that use agent version 20.0.0-3445+ are a reverse proxy and only download the
               agent packages that are deployed in your environment. These new relays use a maximum
               of 50 GB of disk space and can use as little as 2 GB, depending on your environment.
               After deployment, the relay is ready to serve packages within 1 minute. For details,
               see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-relay-overview-#improvements" target="_blank">Improvements to the relay</a>.</div>]]></description>
    <pubDate>Tue, 01 Mar 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-relays-now-optimized-for-efficienc</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>New Container Security rule detects Ingress Remote File Copy Tools</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-container-security-rule-detect</link>
    <description><![CDATA[<div class="p">March 02, 2022, Container Security—Container Security introduces new runtime rule
               "(T1105)Launch Ingress Remote File Copy Tools in Container". The new rule provides
               coverage for ingress tool transfer through commands like wget or curl.</div>]]></description>
    <pubDate>Wed, 02 Mar 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-container-security-rule-detect</guid>
    <category>Container Security</category>
</item>
<item>
    <title>File Storage Security now links malware names to TrendMicro Threat Encyclopedia</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-links-ma</link>
    <description><![CDATA[<div class="p">March 03, 2022, File Storage Security—The malware name displayed in the File Storage
               Security console is now a link to the malware information on the TrendMicro Threat
               Encyclopedia website.</div>]]></description>
    <pubDate>Thu, 03 Mar 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-links-ma</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity Enhancements: Updated Compliance Metrics, Special Characters Support, New GCP Rules</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-updated-co</link>
    <description><![CDATA[<div class="p">March 09, 2022, Conformity—The following features and updates are now available with
               Conformity's latest release on 9 March 2022.</div><ul class="ul" id="whatsnew_d87_90b_7ad__ul_f0c_7bf">
<li class="li">Updated Compliance Evolution Score Calculation: Conformity Compliance Status numbers
                  are calculated based on the latest Conformity Bot run.  We’ve updated the calculation
                  of the evolution chart compliance to match the formula used in the live Conformity
                  compliance status dashboard i.e. using the unweighted formula: (Total number of successful
                  Checks / Total number of Checks) * 100</li>
</ul><ul class="ul" id="whatsnew_d87_90b_7ad__ul_4eb_7d4">
<li class="li">Previously, the evolution compliance was an average of the compliances across accounts,
                  which produced daily results that were not comparable with the live results because:</li>
<li class="li">The Compliance level evolution numbers are calculated based on the last 24 Conformity
                  Bot runs</li>
<li class="li">The base dataset to calculate the values for each widget is different, therefore,
                  even if the calculation method is the same - total successes / total checks * 100, 
                  the results are likely to be different.</li>
<li class="li">This change will affect the evolution chart API, Dashboard and the results received
                  in the Conformity weekly summary email.  For details see: <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-compliance-evolution-#compliance-evolution" target="_blank">Compliance Evolution</a></li>
</ul><ul class="ul" id="whatsnew_d87_90b_7ad__ul_738_443">
<li class="li">Special Characters in Report Title and Description</li>
</ul><div class="p">We now support Chinese characters in the Title and Description fields of Report Configurations.</div><ul class="ul" id="whatsnew_d87_90b_7ad__ul_b67_4e3">
<li class="li">Search and View Accounts by Account ID</li>
</ul><div class="p">As an Admin user, you can allow users to view and search for a cloud account by its
               Account ID by toggling the ON/OFF button from Administration &gt; Subscription &gt; Conformity
               Accounts. For more info see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-subscriptions-#view-account-size" target="_blank">Subscriptions</a></div><div class="p"> </div><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.35. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_d87_90b_7ad__ul_24a_e8f">
<li class="li">CloudVPC-004: Default VPC Network In Use: This rule ensures that the default VPC network
                  is not being used within your GCP projects.</li>
</ul><ul class="ul" id="whatsnew_d87_90b_7ad__ul_297_263">
<li class="li">CloudVPC-005: Check for Legacy Networks: This rule ensures that legacy networks are
                  not being used anymore within your GCP projects.</li>
</ul><ul class="ul" id="whatsnew_d87_90b_7ad__ul_e4b_0dc">
<li class="li">CloudIAM-005: Enable Multi-Factor Authentication for User Accounts: This rule ensures
                  that Multi-Factor Authentication (also known as 2-Step Verification or 2SV) is enabled
                  for all user accounts in order to help protect the access to your Google Cloud Platform
                  (GCP) resources, applications and data.</li>
</ul><ul class="ul" id="whatsnew_d87_90b_7ad__ul_9df_dfd">
<li class="li">CloudIAM-006: Enable Security Key Enforcement for Admin Accounts: This rule ensures
                  that security key enforcement is enabled for all Google Cloud Platform (GCP) organization
                  administrator accounts.</li>
</ul><ul class="ul" id="whatsnew_d87_90b_7ad__ul_ee1_631">
<li class="li">CloudSQL-016: Configure Root Password for MySQL Database Access: This rule ensures
                  that Google Cloud MySQL database instances do not allow anyone to connect with administrative
                  privileges only, without needing a root password.</li>
</ul><div class="p">Rules Updates</div><ul class="ul" id="whatsnew_d87_90b_7ad__ul_853_c4d">
<li class="li">EC2-034: Unrestricted Security Group Ingress on Uncommon Ports: We’ve updated:</li>
<li class="li">The rule’s name from ‘Unrestricted Security Group Ingress’ to ‘Unrestricted Security
                  Group Ingress on Uncommon Port’ and</li>
<li class="li">Added a configuration to enable users to allowlist AWS Security Groups by name with
                  Regex.</li>
</ul><div class="p">Rules Bug Fixes</div><ul class="ul" id="whatsnew_d87_90b_7ad__ul_6d9_a2a">
<li class="li">RDS-034: Backtrack: Fixed a bug for the rule where checks for Aurora RDS instances
                  were not being generated.</li>
</ul><ul class="ul" id="whatsnew_d87_90b_7ad__ul_e88_97f">
<li class="li">VPC-016: VPC Endpoints in Use: Fixed a bug where the rule returned false positives
                  for VPCs’ shared from another account.</li>
</ul><ul class="ul" id="whatsnew_d87_90b_7ad__ul_014_34d">
<li class="li">VPC-010: Unrestricted Network ACL Outbound Traffic and VPC-011: Unrestricted Network
                  ACL Inbound Traffic: The rules have been updated to:</li>
<li class="li">Include a list of the number of compliant/non-compliant rules in the check message</li>
<li class="li">Restrict the ICMP protocol from contributing to the ‘FAILURE’ status checks</li>
</ul><ul class="ul" id="whatsnew_d87_90b_7ad__ul_9ef_741">
<li class="li">IAM-13: MFA for IAM Users with Console Password: Fixed a bug where a stale check still
                  existed after the IAM User Login Profile has been removed.</li>
</ul>]]></description>
    <pubDate>Wed, 09 Mar 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-updated-co</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New introduction page added to File Storage Security console</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-introduction-page-added-to-fil</link>
    <description><![CDATA[<div class="p">March 10, 2022, File Storage Security—The File Storage Security console now displays
               a new introduction page as the landing page.</div>]]></description>
    <pubDate>Thu, 10 Mar 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-introduction-page-added-to-fil</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>View and Improve Network Security Posture against Latest Threats</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-view-and-improve-network-security</link>
    <description><![CDATA[<div class="p">March 10, 2022, Network Security—Determine your network's posture against the latest
               threats: You can now view the status of your network policy's current defense posture
               and learn which recommended actions to take to be protected. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-emerging_threats-" target="_blank">Learn more</a> about Emerging Threats.</div>]]></description>
    <pubDate>Thu, 10 Mar 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-view-and-improve-network-security</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Enhanced Geolocation Filtering for AWS ALB Support</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-geolocation-filtering-for</link>
    <description><![CDATA[<div class="p">March 10, 2022, Network Security—Enhancements to geolocation filtering: Network Security
               geolocation filtering can now block and report traffic for XFF IP addresses when your
               Network Security virtual appliance is behind an AWS Application Load Balancer (ALB)
               in your cloud network. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Geo_Location_filtering-" target="_blank">Learn more</a> about geolocation filtering.</div>]]></description>
    <pubDate>Thu, 10 Mar 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-geolocation-filtering-for</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Agent Upgrade Task Time Zone Configuration Added for Deep Security Agent Version 20</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-upgrade-task-time-zone-confi</link>
    <description><![CDATA[<div class="p">March 21, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security now
               provides an option to create a task to upgrade agents that supports setting a time
               zone for the task. Previously, agents were upgraded based on the UTC time zone. You
               can see the new option by going to Administration &gt; Scheduled Tasks and selecting
               Scheduled Agent Upgrade Task as the task type. This feature is available only for
               Deep Security Agent version 20 on Windows and Linux platforms.</div>]]></description>
    <pubDate>Mon, 21 Mar 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-upgrade-task-time-zone-confi</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved AWS and Azure scanner result handling and object tagging</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-and-azure-scanner-res</link>
    <description><![CDATA[<div class="p">March 22, 2022, File Storage Security—Fixed the issue where AWS and Azure scanner
               DLQ handler did not publish 'unsuccessful scanner invocation' scan result, and the
               objects were not tagged when scanner timed out.</div>]]></description>
    <pubDate>Tue, 22 Mar 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-and-azure-scanner-res</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced Monitoring of Internet-Facing AWS Assets for Compliance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-monitoring-of-internet-fa</link>
    <description><![CDATA[<div class="p">March 24, 2022, Network Security—Verify status of internet-facing assets: Network
               Security can now provide updates on the status of AWS assets located behind internet-facing
               Application Load Balancers (ALBs). The posture assessment summary dashboard now includes
               information about the protection status of these assets helping you comply with PCI
               11.4 standards. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Create_security_groups_and_IAM_roles" target="_blank">Learn More</a>.</div>]]></description>
    <pubDate>Thu, 24 Mar 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-monitoring-of-internet-fa</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Agent-triggered malware scans now available in preview for jp-1 region customers</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-triggered-malware-scans-now</link>
    <description><![CDATA[<div class="p">March 25, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security now
               provides an option to allow agents to trigger all scheduled scans for malware. To
               enable the option, from the computer editor, select Anti-Malware &gt; General, then ensure
               that Enable agent to trigger scheduled scans for malware is selected. This feature
               is still in preview and is currently available only for Trend Cloud One - Endpoint
               &amp; Workload Security customers in the jp-1 region.</div>]]></description>
    <pubDate>Fri, 25 Mar 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-triggered-malware-scans-now</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity introduces updated compliance reports, new rules, and bug fixes</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-updated-comp</link>
    <description><![CDATA[<div class="p">March 28, 2022, Conformity—The following features and updates are now available with
               Conformity's latest release on 28 March 2022.</div><ul class="ul" id="whatsnew_530_765_4a7__ul_3ae_609">
<li class="li">Updated NIST 800-53 Rev5 Compliance &amp; Conformity Report: We've updated the NIST 800-53
                  Rev5 Compliance &amp; Conformity report to include rules and enhanced controls.</li>
</ul><ul class="ul" id="whatsnew_530_765_4a7__ul_bca_92a">
<li class="li">Updated Suppression Data Behaviour for Azure Accounts:  We've updated the suppression
                  data behaviour for Azure accounts where suppressed Azure checks disappeared on recreating
                  the check.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">The custom policy has been updated as a result of the new deployment. The current
               custom policy version is 1.36 and the permission added is: firehose:ListTagsForDeliveryStream.
               <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_530_765_4a7__ul_f1b_f54">
<li class="li">StorageAccounts-018: Account Encryption using Customer Managed Keys: This rule ensures
                  that your Microsoft Azure Storage accounts are using Customer Managed Keys (CMKs)
                  instead of Microsoft Managed Keys (i.e. default keys used by Microsoft Azure for data
                  encryption), to have more granular control over your Azure Storage data encryption
                  and decryption process.</li>
</ul><div class="p">AWS</div><ul class="ul" id="whatsnew_530_765_4a7__ul_e3f_52c">
<li class="li">Firehose-002: Firehose Delivery Stream Server-Side Encryption: This rule ensures that
                  Kinesis Data Firehose delivery streams enforce Server-Side Encryption, ideally using
                  Customer-Managed Keys (CMKs).</li>
</ul><div class="p">GCP</div><ul class="ul" id="whatsnew_530_765_4a7__ul_00e_dd0">
<li class="li">CloudIAM-007: Login Credentials In Use: This rule ensures the use of corporate login
                  credentials instead of personal accounts such as Gmail accounts.</li>
</ul><ul class="ul" id="whatsnew_530_765_4a7__ul_140_97e">
<li class="li">CloudStorage-002: Check for Enable Uniform Bucket-Level Access: This rule ensures
                  that Google Cloud Storage buckets have uniform bucket-level access enabled. With this
                  level of access, object access is controlled entirely through bucket-level permissions
                  (IAM) to ensure uniform access to all the objects within a storage bucket.</li>
</ul><div class="p">Rules Updates</div><ul class="ul" id="whatsnew_530_765_4a7__ul_ad0_c21">
<li class="li">StorageAccounts-006: Disable Anonymous Access to Blob Containers</li>
<li class="li">StorageAccounts-012: Enable Immutable Blob Storage</li>
<li class="li">StorageAccounts-016: Check for Publicly Accessible Web Containers</li>
<li class="li">StorageAccounts-017: Review Storage Accounts with Static Website Configuration</li>
</ul><div class="p">The rules now support exceptions by tags retrieved from Azure Blob Container Metadata.</div><ul class="ul" id="whatsnew_530_765_4a7__ul_cd9_e61">
<li class="li">Lambda-008: Enable Encryption in Transit for Environment Variables</li>
<li class="li">Lambda-009: Enable Encryption at Rest for Environment Variables using Customer Master
                  Keys</li>
</ul><div class="p">Updated the rules' names and descriptions to clearly specify encryption in transit
               and at rest.</div><ul class="ul" id="whatsnew_530_765_4a7__ul_ad8_33f">
<li class="li">IAM-054: IAM Configuration Changes: Updated this rule allowing you to change the severity
                  for each IAM configuration event via rule settings.</li>
</ul><div class="p">Rules Bug Fixes</div><ul class="ul" id="whatsnew_530_765_4a7__ul_294_508">
<li class="li">IAM-034: Valid IAM Identity Providers: We've improved how we handle IAM identity provider
                  data and fixed an issue with remediating OpenID Connect identity providers to prevent
                  false positives.</li>
</ul><ul class="ul" id="whatsnew_530_765_4a7__ul_08e_a42">
<li class="li">EBS-004: EBS Volumes Recent Snapshots</li>
<li class="li">EBS-005: EBS Volumes Too Old Snapshots</li>
</ul><div class="p">We've updated the way we handle AWS EBS Volumes and EBS Volume Snapshots to improve
               reliability and functionality for the rules. AWS rules EBS-004 and EBS-005.</div><ul class="ul" id="whatsnew_530_765_4a7__ul_dee_b50">
<li class="li">AG-001: APIs CloudWatch Logs</li>
<li class="li">AG-002: APIs Detailed CloudWatch Metrics</li>
<li class="li">AG-003: Tracing Enabled</li>
<li class="li">AG-004: Content Encoding</li>
<li class="li">AG-007: Private Endpoint</li>
<li class="li">AG-008: Rotate Expiring SSL Client Certificates</li>
<li class="li">AG-009: Enable Encryption for API Cache</li>
<li class="li">AG-010: Enable API Cache</li>
<li class="li">RG-001: Tags</li>
</ul><div class="p">Fixed a bug to resolve the throttling issue for API Gateway rules by reducing the
               API Gateway API call concurrency.</div>]]></description>
    <pubDate>Mon, 28 Mar 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-updated-comp</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Self-serve trials for Cloud One Security Services now available for extended trial periods</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-self-serve-trials-for-cloud-one-se</link>
    <description><![CDATA[<div class="p">March 31, 2022, Billing and Subscription Management—Self-serve trials for Cloud One
               Security Services are now available! For any service that does not have a current
               subscription, a customer may activate a 30-day free trial, once per Security Service,
               from the Subscription Management page. Additionally, customers in an existing trial
               for a Cloud One Security Service can use this feature to extend their trial by 30
               days.</div><div class="p">Note: Currently this does not include accounts subscribed to Cloud One on AWS or Azure
               Marketplace.</div>]]></description>
    <pubDate>Thu, 31 Mar 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-self-serve-trials-for-cloud-one-se</guid>
    <category>Billing and Subscription Management</category>
</item>
<item>
    <title>Enhanced Container Security UI Indicates Disabled Malware Scanner and Default SmartCheck Update</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-container-security-ui-ind</link>
    <description><![CDATA[<div class="p">April 05, 2022, Container Security—To go with the ability to disable malware scanning,
               Trend Micro has modified the user interface to indicate when the malware scanner is
               disabled. Trend Micro has also updated SmartCheck to disable malware scanning by default.</div>]]></description>
    <pubDate>Tue, 05 Apr 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-container-security-ui-ind</guid>
    <category>Container Security</category>
</item>
<item>
    <title>ZDI Predisclosure Filters Enhance Network Security Defenses</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-zdi-predisclosure-filters-enhance</link>
    <description><![CDATA[<div class="p">April 07, 2022, Network Security—Zero Day Initiative (ZDI) predisclosure filters now
               included in all Network Security deployments (version 2022.3.0.11400 and later): ZDI
               predisclosure filters identify vulnerabilities within a product or application that
               have not yet been patched by the vendor. By restricting the information they contain,
               predisclosure filters preemptively defend your network from attacks against these
               vulnerabilities until the vendor develops a patch. After a patch is available, the
               filters are fully disclosed and include more details about the vulnerability. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Filters_overview-" target="_blank">Learn More</a> about the components of filters included in your Digital Vaccine security package.</div>]]></description>
    <pubDate>Thu, 07 Apr 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-zdi-predisclosure-filters-enhance</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Conformity Introduces Sustainability Pillar Support and New Rules for Azure, AWS, and G</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-sustainabili</link>
    <description><![CDATA[<div class="p">April 08, 2022, Conformity—The following rules and updates will be available with
               Conformity's latest release on 12 April 2022.</div><div class="p">Conformity will now support the new 'Sustainability' pillar</div><div class="p">Conformity can now help customers benchmark and remediate their sustainability impact.
               AWS Well-Architected Framework added the 'Sustainability' pillar in December 2021.
               We've updated our Rules, Reports, Checks filter, Compliance Level Comparison Table,
               and the Compliance Status Widget in accordance with the AWS Well-Architected Framework
               updated version.</div><div class="p">API Updates</div><ul class="ul" id="whatsnew_c96_36c_4dd__ul_bc3_204">
<li class="li">Conformity now supports Trend Micro's domain when using Conformity's public API</li>
<li class="li">The legacy users (signed up for Conformity in the 'us-west-2', 'ap-southeast-2', 
                  and 'eu-west-1' regions) won't be affected by this change.</li>
<li class="li">Cloud One Conformity users can now use 'https://conformity.{region}.cloudone.trendmicro.com/api'
                  to access Conformity's public APIs.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There are no changes to the custom policy as a result of the new deployment. The current
               custom policy version is 1.36. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_c96_36c_4dd__ul_795_4e2">
<li class="li">Monitor-007: Configure Diagnostic Setting Categories: This rule ensures that the diagnostic
                  settings are configured to capture the appropriate categories.</li>
</ul><ul class="ul" id="whatsnew_c96_36c_4dd__ul_9f7_e34">
<li class="li">Monitor-008: Enable Diagnostic Logs for the Supported Resources: This rule ensures
                  that Diagnostic Logs are enabled for the supported Azure cloud resources.</li>
</ul><div class="p">AWS</div><ul class="ul" id="whatsnew_c96_36c_4dd__ul_b00_2d9">
<li class="li">EC2-077: Require IMDSv2 for EC2 Instances: This rule ensures that all the Amazon EC2
                  instances require the use of Instance Metadata Service Version 2 (IMDSv2) when requesting
                  instance metadata in order to protect against vulnerabilities that could be used to
                  access the Instance Metadata Service (IMDS).</li>
</ul><div class="p">GCP</div><ul class="ul" id="whatsnew_c96_36c_4dd__ul_2af_a3d">
<li class="li">CloudDNS-001: Enable DNSSEC for Google Cloud DNS Zones: This rule ensures that DNSSEC
                  security feature is enabled for all your Google Cloud Domain Name System (DNS) managed
                  zones.</li>
</ul><ul class="ul" id="whatsnew_c96_36c_4dd__ul_41a_1c8">
<li class="li">CloudDNS-002: Check for DNSSEC Key-Signing Algorithm in Use: This rule ensures that
                  RSASHA1 signature algorithm is not used for DNSSEC key signing.</li>
</ul><ul class="ul" id="whatsnew_c96_36c_4dd__ul_fac_c7c">
<li class="li">CloudAPI-002: Check for API Key Application Restrictions: This rule ensures that your
                  Google Cloud API key usage is restricted to trusted hosts, HTTP referrers, or applications.</li>
</ul><ul class="ul" id="whatsnew_c96_36c_4dd__ul_c5e_623">
<li class="li">CloudAPI-003: Check for API Key API Restrictions: This rule ensures that API keys
                  have restrictions in place to only allow access to specific APIs, and not general
                  access to all GCP APIs.</li>
</ul><ul class="ul" id="whatsnew_c96_36c_4dd__ul_750_0d2">
<li class="li">CloudIAM-008: Rotate Google Cloud API Keys: This rule ensures that all the API keys
                  created for your Google Cloud Platform (GCP) projects are regularly rotated.</li>
</ul><div class="p">Rules Updates</div><ul class="ul" id="whatsnew_c96_36c_4dd__ul_1a5_762">
<li class="li">SQL-005: Enable Transparent Data Encryption for SQL Databases: Updated the rule title
                  to 'Enable Transparent Data Encryption for SQL Databases' for an appropriate representation
                  of the best practice recommendation.</li>
</ul><div class="p">Rule Bug Fixes</div><ul class="ul" id="whatsnew_c96_36c_4dd__ul_2b0_dd1">
<li class="li">Firehose-001: Firehose Delivery Stream Destination Encryption</li>
<li class="li">Firehose-002: Enable Firehose Delivery Stream Server-Side Encryption</li>
</ul><div class="p">Fixed a bug where the rule - Firehose-001 did not have a link to their resources.
               Also, both the rules Firehose-001 and Firehose-002 did not support tags for "DirectPut"
               Delivery Stream Type Firehose Delivery Streams.</div><ul class="ul" id="whatsnew_c96_36c_4dd__ul_088_df6">
<li class="li">Lambda-009: Enable Encryption at Rest for Environment Variables using Customer Master
                  Keys</li>
</ul><div class="p">Fixed a bug where Lambda-009 did not generate a SUCCESS check after remediation steps
               have been followed to encrypt Lambda Environment variables at rest using CMKs.</div>]]></description>
    <pubDate>Fri, 08 Apr 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-sustainabili</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Account ID displayed for Cloud One subscriptions on AWS marketplace</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-account-id-displayed-for-cloud</link>
    <description><![CDATA[<div class="p">April 20, 2022, Billing and Subscription Management—On the Subscription Management
               page in Cloud One, an AWS Account ID is now displayed for accounts subscribed to Trend
               Micro Cloud One on AWS marketplace.</div>]]></description>
    <pubDate>Wed, 20 Apr 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-account-id-displayed-for-cloud</guid>
    <category>Billing and Subscription Management</category>
</item>
<item>
    <title>False positive checks for Azure rule AppService-018 resolved</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-false-positive-checks-for-azure-ru</link>
    <description><![CDATA[<div class="p">April 20, 2022, Conformity—Incident Update: False positive checks generated for the
               Azure rule - AppService-018</div><div class="p">From approximately 2022-03-09 10:00:00 UTC to 2022-04-19 03:20:00 UTC, the Conformity
               Bot incorrectly produced failure checks associated with the rule AppService-018 for
               Azure AppService resources. This was caused due to an error in our deployment where
               some components of AppService-018 were released prematurely. We’ve removed the rule
               from the application and all the associated checks and will notify you in a release
               notice when we re-introduce the rule.</div>]]></description>
    <pubDate>Wed, 20 Apr 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-false-positive-checks-for-azure-ru</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Cloud One now displays user sign-in and API Key last used times</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloud-one-now-displays-user-sign-i</link>
    <description><![CDATA[<div class="p">April 25, 2022, General—Cloud One now includes the last sign-in time for users and
               the last used time for API Keys in the respective console pages and API responses.</div>]]></description>
    <pubDate>Mon, 25 Apr 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloud-one-now-displays-user-sign-i</guid>
    <category>General</category>
</item>
<item>
    <title>AWS Scanner Lambda now updated to Python 3.8 runtime</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-scanner-lambda-now-updated-to</link>
    <description><![CDATA[<div class="p">April 26, 2022, File Storage Security—The AWS Scanner Lambda is now running on Python
               3.8 runtime. Python 3.6 runtime will be end of support by AWS at July 18, 2022. For
               more information, see <a class="xref" href="https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html#runtime-support-policy" target="_blank">Runtime deprecation policy</a>. We encourage you to update the runtime as soon as possible by updating the Scanner
               Stack.</div><div class="p">This functionality requires a stack update.</div>]]></description>
    <pubDate>Tue, 26 Apr 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-scanner-lambda-now-updated-to</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity Introduces New Rules and Updates for AWS, Azure, and GCP Integration</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-rules-an</link>
    <description><![CDATA[<div class="p">April 28, 2022, Conformity—The following rules and updates are now available with
               Conformity's latest release on 28 April 2022.</div><ul class="ul" id="whatsnew_616_fb6_802__ul_663_c78">
<li class="li">We've updated the PCI DSS c3.2.1 standard to support the new AWS and Azure rules added
                  to Conformity.</li>
</ul><ul class="ul" id="whatsnew_616_fb6_802__ul_9bf_352">
<li class="li">You can now view the GCP Project ID for the GCP Account under Settings &gt; Update General
                  Settings.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_616_fb6_802__ul_8b8_50a">
<li class="li">Fixed a bug with the API documentation to include descriptions for the fields appearing
                  under the API endpoint.</li>
</ul><ul class="ul" id="whatsnew_616_fb6_802__ul_68b_9aa">
<li class="li">Fixed a bug with the check count statistics on the Evolution API to reflect the average
                  number across bot runs instead of a cumulative number.</li>
</ul><ul class="ul" id="whatsnew_616_fb6_802__ul_45b_506">
<li class="li">Fixed a bug that stopped the Conformity bot from running successfully.</li>
</ul><ul class="ul" id="whatsnew_616_fb6_802__ul_6f6_f90">
<li class="li">Fixed up a bug to display an error for the unverified user(s) when creating or updating
                  an SMS or email channel via our public API.</li>
</ul><ul class="ul" id="whatsnew_616_fb6_802__ul_fe3_47f">
<li class="li">Fixed a bug to set the default cooldown value for the Autoscaling group to 300 seconds
                  if it is not specified in the CloudFormation template.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">We've updated the custom policy as a result of the new deployment. The latest custom
               policy version is 1.37 and the permissions added are:</div><ul class="ul" id="whatsnew_616_fb6_802__ul_e2e_590">
<li class="li">inspector:DescribeAssessmentTargets</li>
</ul><ul class="ul" id="whatsnew_616_fb6_802__ul_098_64e">
<li class="li">inspector:DescribeResourceGroups</li>
</ul><ul class="ul" id="whatsnew_616_fb6_802__ul_ecb_fa8">
<li class="li">inspector:ListAssessmentTargets</li>
</ul><ul class="ul" id="whatsnew_616_fb6_802__ul_978_0d3">
<li class="li">inspector:PreviewAgents</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_616_fb6_802__ul_492_eec">
<li class="li">Monitor-009: Enable Exporting Activity Logs for Azure Cloud Resources: This rule ensures
                  that exporting activity logs is enabled for each cloud resource within a subscription.</li>
</ul><ul class="ul" id="whatsnew_616_fb6_802__ul_651_f43">
<li class="li">StorageAccounts-019: Enable Logging for Azure Storage Blob Service: This rule ensures
                  that storage logging is enabled for the Azure Storage Blob service.</li>
<li class="li">StorageAccounts-020: Enable Logging for Azure Storage Table Service: This rule ensures
                  that storage logging is enabled for the Azure Storage Table service.</li>
</ul><div class="p">AWS</div><ul class="ul" id="whatsnew_616_fb6_802__ul_73d_693">
<li class="li">EC2-078: Instances Scanned by Amazon Inspector: This rule ensures that all your Amazon
                  EC2 instances are included in at least one Inspector Classic assessment target to
                  make sure that Amazon Inspector Classic service can evaluate your EC2 instances for
                  potential security issues and common vulnerabilities during assessment runs.</li>
</ul><div class="p">GCP</div><ul class="ul" id="whatsnew_616_fb6_802__ul_b39_e9d">
<li class="li">CloudDNS-003: Check for DNSSEC Zone-Signing Algorithm in Use: This rule ensures that
                  DNSSEC key signing is not using RSASHA1 as a signature algorithm for the Zone-Signing
                  Key (ZSK) associated with your public DNS managed zone.</li>
</ul><ul class="ul" id="whatsnew_616_fb6_802__ul_7e4_c41">
<li class="li">CloudIAM-009: Configure Google Cloud Audit Logs to Track All Activities: This rule
                  ensures that the Audit Logs feature is configured to record all service and user activities.</li>
</ul><ul class="ul" id="whatsnew_616_fb6_802__ul_6d7_168">
<li class="li">CloudAPI-001: Google Cloud API Keys: This rule ensures that all the API keys created
                  for your Google Cloud Platform (GCP) projects are regularly rotated.</li>
</ul><div class="p">Rules Updates</div><ul class="ul" id="whatsnew_616_fb6_802__ul_e41_bcc">
<li class="li">ELBv2-003: ALB Security Policy</li>
<li class="li">ELBv2-009 Network Load Balancer Security Policy: Updated ELBv2-003 and ELBv2-009 to
                  use the latest and most secure security policies.</li>
</ul><ul class="ul" id="whatsnew_616_fb6_802__ul_9d9_4f6">
<li class="li">IAM-036: AWS IAM Users with Admin Privileges: Updated IAM-036 to show the policies
                  attached to privileged IAM Users.</li>
</ul>]]></description>
    <pubDate>Thu, 28 Apr 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-rules-an</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Intrusion Prevention and Windows Defender Compatibility in Latest Agent Version</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-intrusion-prevention-and</link>
    <description><![CDATA[<div class="p">April 28, 2022, Workload Security—Agent version 20.0.0-4416 has been released.</div><div class="p">Some highlights include:</div><ul class="ul" id="whatsnew_13c_e0e_726__ul_5a8_e4c">
<li class="li">Enhanced Intrusion Prevention performance with the "Bypass Network Scanner" rule applied.</li>
<li class="li">Improved compatibility for Deep Security Agent on systems running Windows Defender
                  in passive mode.</li>
<li class="li">Several resolved issues and security updates.</li>
</ul><div class="p">For detailed information on what's included in this version, see <a class="xref" href="https://help.deepsecurity.trendmicro.com/20_0/on-premise/release-notes-dsa.html" target="_blank">What's New in Deep Security Agent</a>.</div>]]></description>
    <pubDate>Thu, 28 Apr 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-intrusion-prevention-and</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Scan error events now visible in File Storage Security console</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scan-error-events-now-visible-in-f</link>
    <description><![CDATA[<div class="p">May 04, 2022, File Storage Security—The File Storage Security console now displays
               scan error events below the scan history chart.</div>]]></description>
    <pubDate>Wed, 04 May 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scan-error-events-now-visible-in-f</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced File Storage Security Console Display for AWS and Azure Tabs</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-storage-security-con</link>
    <description><![CDATA[<div class="p">May 11, 2022, File Storage Security—The storage stack table in the File Storage Security
               console now displays the header in the order of:</div><ul class="ul" id="whatsnew_28d_077_9c7__ul_e88_559">
<li class="li">under the AWS tab: Bucket Name, AWS Account, Storage Stack, and Stack Created.</li>
<li class="li">under the Azure tab: Storage Account Name, Subscription Name, Storage Stack, and Stack
                  Created.</li>
</ul>]]></description>
    <pubDate>Wed, 11 May 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-storage-security-con</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Updated Compliance Dashboard and New GCP and Azure Rules Available</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-compliance-dashboard-and-n</link>
    <description><![CDATA[<div class="p">May 17, 2022, Conformity—The following updates and features are now available with
               Conformity's latest release on 17 May 2022.</div><div class="p">What's New</div><ul class="ul" id="whatsnew_442_359_fbf__ul_25d_3e6">
<li class="li">Updated the note below the Compliance level Comparison section on the Main Dashboard
                  to clearly display the number of incomplete and onboarded accounts included in the
                  comparison.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_442_359_fbf__ul_9b0_ee6">
<li class="li">Fixed a bug in RTM, where the 'Read Only' users could view the Configure Rules button.
                  The button is now visible to the authorised users only.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_219_488">
<li class="li">Fixed a bug where suppressing an Azure check was returning errors after a successful
                  suppression.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.37.</div><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_442_359_fbf__ul_5ef_64e">
<li class="li">CloudSQL-017: Disable 'remote access' Flag for SQL Server Database Instances: This
                  rule ensures that the "remote access" SQL Server flag is set to "off".</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_d21_b8c">
<li class="li">CloudSQL-018: Disable 'log_statement_stats' Flag for PostgreSQL Database Instances:
                  This rule ensures that the 'log_statement_stats' PostgreSQL database flag is set to
                  `Off`.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_5ff_039">
<li class="li">CloudSQL-019: Disable 'external scripts enabled' Flag for SQL Server Database Instances:
                  This rule ensures that the "external scripts enabled" SQL Server flag is set to `Off`.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_89d_4cb">
<li class="li">BigQuery-002: Enable BigQuery Encryption with Customer-Managed Keys: This rule ensures
                  that BigQuery dataset tables are encrypted using Customer-Managed Keys (CMKs).</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_281_556">
<li class="li">ComputeEngine-009: Enable "Block Project-Wide SSH keys" Feature: This rule ensures
                  that the Block Project-Wide SSH keys feature is enabled for all your virtual machine
                  instances.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_d41_8f5">
<li class="li">CloudLogging-001: Enable Monitoring for Bucket Permission Changes: This rule ensures
                  that each Google Cloud Platform (GCP) project has configured a GPC alerting policy
                  that is triggered each time a Google Cloud Storage bucket permission change is made.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_fed_ef7">
<li class="li">CloudLogging-002: Enable VPC Network Changes Monitoring: This rule ensures that VPC
                  network route changes are being monitored using alerting policies.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_524_e1a">
<li class="li">CloudLogging-003: Enable VPC Network Changes Monitoring This rule ensures that Google
                  Cloud VPC network changes are being monitored using log metrics and alerting policies.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_854_5e9">
<li class="li">CloudLogging-004: Enable Monitoring for Custom Role Changes: This rule ensures that
                  custom IAM role changes are being monitored using alerting policies.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_d75_1dd">
<li class="li">CloudLogging-005: Enable Monitoring for SQL Instance Configuration Changes: This rule
                  ensures that SQL instance configuration changes are being monitored using alerting
                  policies.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_1ef_a54">
<li class="li">CloudLogging-006: Enable Monitoring for Firewall Rule Changes: This rule ensures that
                  each Google Cloud Platform (GCP) project has configured a GCP alerting policy that
                  is triggered every time a Virtual Private Cloud (VPC) network firewall rule change
                  is made.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_4f7_073">
<li class="li">CloudLogging-007: Enable Monitoring for Audit Configuration Changes: This rule ensures
                  that GCP project audit configuration changes are being monitored using alerting policies.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_c5b_24e">
<li class="li">CloudLogging-009: Export All Log Entries Using Sinks: This rule ensures that all the
                  log entries generated for your Google Cloud projects are exported using sinks.</li>
</ul><div class="p">Azure</div><ul class="ul" id="whatsnew_442_359_fbf__ul_2fa_899">
<li class="li">SecurityCenter-028: All Parameters for Microsoft Defender for Cloud Default Policy:
                  This rule ensures that all the parameters supported by Microsoft Defender for Cloud
                  default policy are enabled.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_fa5_c21">
<li class="li">SecurityCenter-030: Enable Defender for Endpoint Integration with Microsoft Defender
                  for cloud: This rule ensures that Defender for Endpoint – Defender for Cloud integration
                  is enabled.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_96a_af7">
<li class="li">SecurityCenter-031: Enable Defender Microsoft Defender for Cloud Apps Integration:
                  This rule ensures that Microsoft Defender for Cloud Apps integration is enabled.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_ce9_757">
<li class="li">SecurityCenter-032: Enable Azure Defender for Virtual Machine Servers: This rule ensures
                  that Azure Defender is enabled for Azure virtual machine (VM) servers.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_5b8_467">
<li class="li">SecurityCenter-033 Enable Microsoft Defender for Cloud for App Service Instances:
                  This rule ensures that Microsoft Defender for Cloud is enabled for Azure App Service
                  instances.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_8fc_c56">
<li class="li">SecurityCenter-034: Enable Microsoft Defender for Cloud for Key Vaults: This rule
                  ensures that Microsoft Defender for Cloud is enabled for Azure key vault resources.</li>
</ul><div class="p">Rule Updates</div><ul class="ul" id="whatsnew_442_359_fbf__ul_6a1_95e">
<li class="li">IAM-013: MFA For IAM Users With Console Password: The rule now supports MFA events.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_1e1_c0c">
<li class="li">VirtualMachine-001: Enable Encryption for Boot Disk Volumes, VirtualMachine-002: Enable
                  Encryption for Non-Boot Disk Volumes, VirtualMachine-003:Enable Encryption for Unattached
                  Disk Volumes:</li>
</ul><div class="p">Updated the rules' names to clarify encryption in Azure Disk Encryption and the risk
               level from `High` to `Medium`.</div><div class="p">Rule Bug Fixes</div><ul class="ul" id="whatsnew_442_359_fbf__ul_83e_024">
<li class="li">EC2-030: EC2 Instance Termination Protection: Fixed a bug where EC2-030 was returning
                  checks for EC2 instances that are part of Auto Scaling groups.</li>
</ul><ul class="ul" id="whatsnew_442_359_fbf__ul_817_bbc">
<li class="li">CT-002: CloudTrail S3 Bucket Logging Enabled, CT-003: CloudTrail Bucket Publicly Accessible,
                  CT-004: CloudTrail Bucket MFA Delete Enabled:</li>
</ul><div class="p">Fixed  how we handle AWS CloudTrail resource data to address incorrect check results
               with the AWS rules CT-002, CT-003, and CT-004. We also improved how we evaluate CT-002
               and CT-004, you may notice that old checks are removed and recreated.</div><ul class="ul" id="whatsnew_442_359_fbf__ul_e08_a5c">
<li class="li">Fixed a bug where Resource types were not displayed correctly in the View by Resource
                  tab for some resources.</li>
</ul>]]></description>
    <pubDate>Tue, 17 May 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-compliance-dashboard-and-n</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved event count display in Scan History chart</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-event-count-display-in-sc</link>
    <description><![CDATA[<div class="p">May 18, 2022, File Storage Security—The Scan History chart in the File Storage Security
               console now displays the event counts with the format numbers.</div>]]></description>
    <pubDate>Wed, 18 May 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-event-count-display-in-sc</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced Threat Assessment Walkthroughs in Network Security Demo</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-threat-assessment-walkthr</link>
    <description><![CDATA[<div class="p">May 18, 2022, Network Security—Enhanced Interactive demo experience: Network Security's
               Interactive demo experience now includes detailed walkthroughs of threat assessment
               features, to help you learn how to protect your cloud environment from threats such
               as log4j.</div>]]></description>
    <pubDate>Wed, 18 May 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-threat-assessment-walkthr</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Time display configuration added to File Storage Security console settings</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-time-display-configuration-added-t</link>
    <description><![CDATA[<div class="p">May 19, 2022, File Storage Security—You can now configure the File Storage Security
               console's time display on the User Setting page of the Cloud One console.</div>]]></description>
    <pubDate>Thu, 19 May 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-time-display-configuration-added-t</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced Container Security Events with Detailed Contextual Information</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-container-security-events</link>
    <description><![CDATA[<div class="p">May 24, 2022, Container Security—Trend Micro enhanced its events with additional meaningful
               context. Events now include the following new fields: pod ID, pod name, pod labels,
               namespace, container name, container ID, image name, image tag, image digest, event
               number, event catagory, process ID, process, executable, process arguments, process
               name, parent process, parent process ID, parent process name, and file number. Note
               that in some instances not all fields are necessarily available/applicable.</div>]]></description>
    <pubDate>Tue, 24 May 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-container-security-events</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Enhanced Runtime Rules feature MITRE ATT&amp;CK technique identifier links</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-runtime-rules-feature-mit</link>
    <description><![CDATA[<div class="p">May 26, 2022, Container Security—Many runtime rules contain a MITRE ATT&amp;CK technique
               identifier in the name. Trend Micro added a link in the rule description that leads
               to the page on the MITRE ATT&amp;CK website corresponding to the technique identifier.</div>]]></description>
    <pubDate>Thu, 26 May 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-runtime-rules-feature-mit</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Improved Lambda Function Python Runtime Update Process</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-lambda-function-python-ru</link>
    <description><![CDATA[<div class="p">May 27, 2022, File Storage Security—Fixed the issue where updating a stack to update
               Lambda function's Python runtime did not take effect and caused the Lambda function
               to lose the license and the latest pattern Lambda layer. This functionality requires
               a stack update.</div>]]></description>
    <pubDate>Fri, 27 May 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-lambda-function-python-ru</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced AWS Scanner Lambda for Larger File Scans</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-scanner-lambda-for-la</link>
    <description><![CDATA[<div class="p">May 31, 2022, File Storage Security—You can configure a larger ephemeral storage for
               the AWS Scanner Lambda to scan larger files in zip files.</div><div class="p">This functionality requires a stack update.</div>]]></description>
    <pubDate>Tue, 31 May 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-scanner-lambda-for-la</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced Deep Security Relay metrics and security updates in Agent version 20.0.0-472</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-deep-security-relay-metri</link>
    <description><![CDATA[<div class="p">May 31, 2022, Workload Security—Agent version 20.0.0-4726 has been released.</div><div class="p">This release includes:</div><ul class="ul" id="whatsnew_0f2_578_501__ul_1dd_50a">
<li class="li">Enhancements to Deep Security Relay that enable it to record its status and other
                  metrics for potential troubleshooting.</li>
<li class="li">Several resolved issues and security updates.</li>
</ul><div class="p">For detailed information on what's included in this version, see <a class="xref" href="https://help.deepsecurity.trendmicro.com/20_0/on-premise/release-notes-dsa.html" target="_blank">What's New in Deep Security Agent</a>.</div>]]></description>
    <pubDate>Tue, 31 May 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-deep-security-relay-metri</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity Enhancements: New Standards, Bug Fixes, Rules, and Policy Updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-new-standa</link>
    <description><![CDATA[<div class="p">June 06, 2022, Conformity—The following features and updates are now available with
               Conformity's latest release on 6 June 2022.</div><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_65e_808">
<li class="li">Updated the FedRAMP Rev 4 Compliance Standard to support the new AWS and Azure rules
                  released by Conformity.</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_312_f1c">
<li class="li">Updated the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Services-#paths-~1services-get" target="_blank">Get Services</a> API endpoint to display data for associated compliance standards.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_5d0_31a">
<li class="li">Fixed a bug to display the `resource type` in the View By Resource tab for some rules.</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_089_ec4">
<li class="li">Fixed a bug to disable the 'Configure' button for Power users in the Conformity Administration
                  &gt; Users tab.</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_af0_e39">
<li class="li">Fixed a bug to enable users to apply a profile to over 1000 accounts at once.</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_f91_d84">
<li class="li">Fixed a bug that incorrectly allowed suppression of checks via the Public API without
                  correctly setting one of the mandatory values in the request.</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_7b1_a68">
<li class="li">Fixed a bug to remove an outdated Knowledge Base page for the rule - Route53-008.</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_49a_61e">
<li class="li">Fixed a bug with the drop down email selection to load all the available emails when
                  configuring a scheduled report.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.37. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_d8a_8a3">
<li class="li">CloudSQL-020: Configure 'user connections' Flag for SQL Server Database Instances:
                  This rule ensures that SQL Server database instances have the appropriate configuration
                  set for the `user connections` flag.</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_dc5_b01">
<li class="li">CloudSQL-021: Disable 'user options' Flag for SQL Server Instances: This rule ensures
                  that the `user options` SQL Server flag is not configured.</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_796_a23">
<li class="li">ComputeEngine-011: Enable Confidential Computing for Virtual Machine Instances: This
                  rule ensures that Confidential Computing is enabled for virtual machine (VM) instances.</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_825_6cd">
<li class="li">ComputeEngine-010: Enable OS Login for GCP Projects: This rule ensures that the OS
                  Login feature is enabled at the GCP project level.</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_fe5_b54">
<li class="li">CloudLogging-008: Enable Project Ownership Assignments Monitoring: This rule ensures
                  that GCP project ownership changes are being monitored using alerting policies.</li>
</ul><div class="p">AWS</div><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_b46_04c">
<li class="li">CF-012: Cloudfront Content Distribution Network: This rule ensures that your websites/web
                  applications are using the Amazon CloudFront Content Distribution Network (CDN) to
                  secure the web content delivery (media files and static resource files e.g. html,
                  .css, .js).</li>
</ul><div class="p">Azure</div><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_070_118">
<li class="li">SQL-017: Enable Vulnerability Assessment for Microsoft SQL Servers: This rule ensures
                  that Vulnerability Assessment is enabled for Microsoft SQL database servers.</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_019_f1d">
<li class="li">Network-016: Check for Unrestricted CIFS Access:  This rule ensures that Microsoft
                  Azure Network Security Groups (NSGs) do not allow unrestricted access on TCP port
                  445 to protect against attackers that use brute force methods to gain access to Azure
                  virtual machines associated with these NSGs.</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_af3_d1d">
<li class="li">Network-017: Check for Unrestricted HTTP Access:  This rule ensures that Microsoft
                  Azure Network Security Groups (NSGs) do not allow unrestricted access on TCP port
                  80 to protect against attackers that use brute force methods to gain access to Azure
                  virtual machines associated with these NSGs.</li>
</ul><div class="p">Rule Updates</div><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_3d9_98d">
<li class="li">Improved the following rules to take the `resource region` into account when producing
                  check results:</li>
<li class="li">EC2-048: Reserved Instance Lease Expiration In The Next 7 Days</li>
<li class="li">EC2-049: Reserved Instance Lease Expiration In The Next 30 Days</li>
<li class="li">EC-004: ElastiCache Reserved Cache Node Lease Expiration In The Next 7 Days</li>
<li class="li">EC-005: ElastiCache Reserved Cache Node Lease Expiration In The Next 7 Days</li>
<li class="li">ES-015: ElasticSearch Node To Node Encryption</li>
<li class="li">ES-016: Elasticsearch Reserved Instance Lease Expiration in The Next 7 Days</li>
<li class="li">ES-017: Elasticsearch Reserved Instance Lease Expiration in The Next 7 Days</li>
<li class="li">RDS-010: RDS General Purpose SSD</li>
<li class="li">RDS-011: RDS Default Port</li>
<li class="li">RDS-014: RDS Reserved DB Instance Lease Expiration In The Next 7 Days</li>
<li class="li">RDS-015: RDS Reserved DB Instance Lease Expiration In The Next 30 Days</li>
<li class="li">S3-026: Enable S3 Block Public Access for S3 Buckets</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_bbc_b68">
<li class="li">Updated the following rules to check for additional unrestricted inbound access scenarios
                  on Azure Network Security Groups:</li>
<li class="li">Network-001: Check for Unrestricted RDP Access</li>
<li class="li">Network-002: Check for Unrestricted SSH Access</li>
<li class="li">Network-005: Check for Unrestricted FTP Access</li>
<li class="li">Network-006: Check for Unrestricted MySQL Database Access</li>
<li class="li">Network-007: Check for Unrestricted PostgreSQL Database Access</li>
<li class="li">Network-008: Check for Unrestricted MS SQL Database Access</li>
<li class="li">Network-009: Check for Unrestricted Oracle Database Access</li>
<li class="li">Network-010: Check for Unrestricted RPC Access</li>
</ul><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_33e_0c8">
<li class="li">CT-003: Publicly Accessible CloudTrail Buckets: We've improved how we evaluate the
                  CloudTrail target bucket and its access policies.</li>
</ul><div class="p">Rule Bug Fixes</div><ul class="ul" id="whatsnew_7fb_bb5_e42__ul_b34_c10">
<li class="li">SecurityCenter-001 "Enable Microsoft Defender Standard Pricing Tier: Fixed a bug to
                  take Microsoft's Defender (formerly Security Centre) service changes into account
                  preventing the remediation of failed checks.</li>
</ul>]]></description>
    <pubDate>Mon, 06 Jun 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-new-standa</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Container Security with New Admission Rule</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-container-security-with-n</link>
    <description><![CDATA[<div class="p">June 08, 2022, Container Security—Trend Micro has a new admission rule to protect
               users from containers with unnecessary capabilities. If these capabilities are exploited,
               they could cause greater damage than if they had been otherwise dropped. This new
               policy allows users to log or block containers based on the container capabilities
               and to continue following the best security practices from the CIS Kubernetes Benchmarks
               and Pod Security Standards.</div>]]></description>
    <pubDate>Wed, 08 Jun 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-container-security-with-n</guid>
    <category>Container Security</category>
</item>
<item>
    <title>AWS Security Hub integrated in Cloud One for enhanced security monitoring</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-security-hub-integrated-in-clo</link>
    <description><![CDATA[<div class="p">June 14, 2022, Integrations—AWS Security Hub Integration Preview Release: you can
               now configure AWS Security Hub with Cloud One using our API Endpoints in this <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-sentry-" target="_blank">Preview</a> release.</div>]]></description>
    <pubDate>Tue, 14 Jun 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-security-hub-integrated-in-clo</guid>
    <category>Integrations</category>
</item>
<item>
    <title>Retirement of Log4j Assessment as of June 15th 2022</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-retirement-of-log4j-assessment-as</link>
    <description><![CDATA[<div class="p">June 15, 2022, Workload Security—As of June 15th 2022, the Log4j Assessment has been
               retired.</div><div class="p">Please refer to Trend Micro's <a class="xref" href="https://success.trendmicro.com/en-us/solution/ka-0012637" target="_blank">Log4j security alert</a> for more information on Trend Micro's coverage of Log4j and resources to protect
               your environment.</div>]]></description>
    <pubDate>Wed, 15 Jun 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-retirement-of-log4j-assessment-as</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced User Visibility in System Events for Trend Cloud One Users</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-user-visibility-in-system</link>
    <description><![CDATA[<div class="p">June 16, 2022, Workload Security—When starting Trend Cloud One - Endpoint &amp; Workload
               Security, Trend Cloud One users will now have their username imported and displayed
               alongside the URN under System Events (Events &amp; Reports &gt; Events &gt; System Events).
               All system events generated after these changes were made will reflect this update.</div>]]></description>
    <pubDate>Thu, 16 Jun 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-user-visibility-in-system</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Account Closure for Expired Subscriptions after 60 Days Starting July 18, 2022</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-account-closure-for-expired-subscr</link>
    <description><![CDATA[<div class="p">June 20, 2022, Billing and Subscription Management—Starting July 18, 2022, Trend Micro
               Cloud One will start closing accounts whose subscriptions have been expired for over
               60 days. For more information please see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-billing-subscription-billing--billing-and-subscription-management-billing-pricing-#what-happens-when-my-subscription-expires" target="_blank">What happens when my subscription expires</a>.</div>]]></description>
    <pubDate>Mon, 20 Jun 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-account-closure-for-expired-subscr</guid>
    <category>Billing and Subscription Management</category>
</item>
<item>
    <title>Enhanced Multi-Factor Authentication Recovery Code Feature</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-multi-factor-authenticati</link>
    <description><![CDATA[<div class="p">June 20, 2022, General—You can now record a code that can be used to disable your
               multi-factor authentication if your device is lost, destroyed, or stops working. This
               applies to accounts created on or after August 4, 2021, or ones that have been updated
               to the new sign-in system introduced on that date. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central--identity-and-account-management-c1-user-update-#enable-mfa" target="_blank">Enable multi-factor authentication</a>.</div>]]></description>
    <pubDate>Mon, 20 Jun 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-multi-factor-authenticati</guid>
    <category>General</category>
</item>
<item>
    <title>File Storage Security console updates parameter from `objectId` to `id` in Azure CLI</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-console-upda</link>
    <description><![CDATA[<div class="p">June 22, 2022, File Storage Security—The File Storage Security console now replaces
               the parameter `objectId` of the Azure CLI with `id`.</div>]]></description>
    <pubDate>Wed, 22 Jun 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-console-upda</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Scheduled Maintenance for Trend Micro Cloud One on July 9th, 2022</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scheduled-maintenance-for-trend-mi</link>
    <description><![CDATA[<div class="p">June 24, 2022, General—System maintenance for Trend Micro Cloud One is scheduled for
               Saturday, July 9th, 2022. For US, EU and CA regions (us-1, gb-1, de-1, ca-1) between
               03:00 and 10:00 UTC.; for APAC regions (in-1, jp-1, sg-1, au-1) between 17:00 and
               21:00 UTC.  During the maintenance, console and API access for certain Cloud One services
               will be unavailable. For more information or to be notified of scheduled maintenance,
               see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central-" target="_blank">Trend Micro Cloud One Maintenance</a></div>]]></description>
    <pubDate>Fri, 24 Jun 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scheduled-maintenance-for-trend-mi</guid>
    <category>General</category>
</item>
<item>
    <title>Update AWS Scanner Stack for Python 3.8 Runtime by July 18, 2022</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-update-aws-scanner-stack-for-pytho</link>
    <description><![CDATA[<div class="p">June 28, 2022, File Storage Security—We would like to remind you to update the AWS
               Scanner Stack to update Scanner Lambda function's runtime to Python 3.8 before July
               18, 2022.</div><div class="p">The AWS Scanner Lambda is now running on Python 3.8 runtime. Python 3.6 runtime will
               be end of support by AWS at July 18, 2022. For more information, see <a class="xref" href="https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html#runtime-support-policy" target="_blank">Runtime deprecation policy</a>. We encourage you to update the runtime as soon as possible by updating the Scanner
               Stack.</div><div class="p">This functionality requires a stack update.</div>]]></description>
    <pubDate>Tue, 28 Jun 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-update-aws-scanner-stack-for-pytho</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>File Storage Security Enhances Support for Google Cloud Storage with File Scanning</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-enhances-sup</link>
    <description><![CDATA[<div class="p">June 30, 2022, File Storage Security—File Storage Security now supports the scanning
               of files uploaded to Google Cloud Storage bucket.</div><div class="p">For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-arch-overview-gcp-" target="_blank">GCP Architecture and flow</a>.</div><div class="p">The Scan Activity for GCP is coming soon.</div>]]></description>
    <pubDate>Thu, 30 Jun 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-enhances-sup</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Fixed issue with GCP deployment scripts for smoother stack deployment</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-issue-with-gcp-deployment-sc</link>
    <description><![CDATA[<div class="p">July 01, 2022, File Storage Security—Fixed the issue where GCP deployment scripts
               cannot deploy the stacks.</div>]]></description>
    <pubDate>Fri, 01 Jul 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-issue-with-gcp-deployment-sc</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced Compliance Monitoring and New Rules Added for Conformity Platform</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-compliance-monitoring-and</link>
    <description><![CDATA[<div class="p">July 04, 2022, Conformity—The following features and updates are now available with
               Conformity's latest release on 4 July 2022.</div><ul class="ul" id="whatsnew_0ab_344_ca0__ul_661_092">
<li class="li">Introducing in the new Evolution Chart summary widget under the Overview tab, which
                  enables you to view your overall compliance trends upto one year and the daily average
                  breakdown of your compliance score by Success, Failed, and Total checks. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-compliance-evolution-summary-" target="_blank">Read more&gt;</a></li>
</ul><div class="p"></div><ul class="ul" id="whatsnew_0ab_344_ca0__ul_24b_313">
<li class="li">Conformity now supports the following compliance standards:</li>
<li class="li">The ISO ISO 27001:2013 for GCP</li>
<li class="li">The PCI DSS V3.2.1 (updated to April 2022)for GCP</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_f22_85a">
<li class="li">Updated AWS and Azure rules mapping for APRA CPS 234 compliance standard.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_dbf_54c">
<li class="li">Added a new operator `isNullOrUndefined` for Custom Rules.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_0ab_344_ca0__ul_262_e45">
<li class="li">Fixed a bug where unassociated checks from other accounts were being shown inside
                  the Most critical failures section of the Group Dashboard and the Account Dashboard.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_032_c8a">
<li class="li">Fixed a bug where users were unable to connect to Jira OAuth via our Jira communications
                  channel using SSO into the conformity platform via Trend Micro Cloud One Console.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_4ae_fe1">
<li class="li">To ensure Microsoft Teams notifications are received promptly for all organizations,
                  Microsoft Teams communication channels are now limited to 100 notifications/hr per
                  channel.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_9e6_0a1">
<li class="li">Fixed a bug where unassociated checks were being displayed from other accounts in
                  the same organisation in View by Rule &amp; View by Standards &amp; Frameworks views.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_c75_be6">
<li class="li">Fixed a bug with the drop-down email selection to load all the available emails configuring
                  a scheduled report.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_ab1_b86">
<li class="li">Fixed a bug with Well Architected Tool notes not being generated at times and added
                  support for the Sustainability pillar.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.37. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">Conformity Bot Update</div><div class="p">Enhanced performance of Conformity Bot to only assess  by scanning or to only scan
               the minimum Active Directory data required to run Active Directory rules for Azure
               subscriptions.</div><div class="p">New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_0ab_344_ca0__ul_323_4de">
<li class="li">CloudSQL-022: Disable "log_planner_stats" Flag for PostgreSQL Database Instances:
                  The rule ensures that the `log_planner_stats` PostgreSQL database flag is set to "off"</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_fe4_67f">
<li class="li">CloudSQL-023: Disable 'log_parser_stats' Flag for PostgreSQL Database Instances: This
                  rule ensures that the `log_hostname` PostgreSQL database flag is set to "on".</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_d37_069">
<li class="li">CloudSQL-024: Enable "skip_show_database" Flag for MySQL Database Instances: This
                  rule ensures that the `skip_show_database` MySQL database flag is set to "on".</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_626_75f">
<li class="li">CloudSQL-025: Disable 'log_parser_stats' Flag for PostgreSQL Database Instances: This
                  rule ensures that the `log_parser_stats` PostgreSQL database flag is set to "off".</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_3bd_3d5">
<li class="li">CloudSQL-026: Disable 'log_executor_stats' Flag for PostgreSQL Database Instances:
                  Ensure that the `log_executor_stats` PostgreSQL database flag is set to Off.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_db6_d31">
<li class="li">CloudVPC-006: Cloud DNS logging for VPC Networks: This rule ensures that the Cloud
                  DNS logging is enabled for all your Virtual Private Cloud (VPC) networks using DNS
                  server policies.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_5d3_6b3">
<li class="li">CloudLoadBalancing-001: Check for Insecure SSL Cipher Suites: This rule ensures that
                  there are no HTTPS/SSL Proxy load balancers configured with insecure SSL policies.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_a03_1c3">
<li class="li">CloudStorage-003: Configure Retention Policies with Bucket Lock: This rule ensures
                  that the log bucket retention policies are using the Bucket Lock feature</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_9d7_344">
<li class="li">CloudIAM-010: Enforce Separation of Duties for KMS-Related Roles: This rule ensures
                  that separation of duties is implemented for all Google Cloud KMS-related roles.</li>
</ul><div class="p">Azure</div><ul class="ul" id="whatsnew_0ab_344_ca0__ul_c66_707">
<li class="li">Network-023: Check for Unrestricted DNS Access: This rule ensures that no network
                  security groups allow unrestricted inbound access on TCP and UDP port 53.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_9a6_cdf">
<li class="li">Network-020: Check for Unrestricted ICMP Access: This rule ensures that no network
                  security groups allow unrestricted inbound access using Internet Control Message Protocol
                  (ICMP).</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_3d2_3f9">
<li class="li">Network-018: Check for Unrestricted SMTP Access: This rule ensures that Microsoft
                  Azure network security groups (NSGs) do not allow unrestricted access on TCP port
                  25.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_a65_e43">
<li class="li">Network-019: Check for Unrestricted Telnet Access: This rule ensure that Microsoft
                  Azure network security groups (NSGs) do not allow unrestricted access on TCP port
                  23</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_6b9_ff2">
<li class="li">SecurityCenter-035: Microsoft Defender for Cloud for SQL Server Virtual Machines:
                  This rule ensures that Microsoft Defender for Cloud is enabled for SQL Server virtual
                  machines.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_0f6_8fe">
<li class="li">SecurityCenter-036: Enable Microsoft Defender for Cloud for Azure SQL Database Servers:
                  This rule ensures that Microsoft Defender for Cloud is enabled for your Azure SQL
                  database servers.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_ce9_e85">
<li class="li">SecurityCenter-037: Enable Microsoft Defender for Cloud for Azure Containers: This
                  rule ensures that Microsoft Defender for Cloud is enabled for Azure containers.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_a45_db4">
<li class="li">SecurityCenter-038: Enable Microsoft Defender for Cloud for Storage Accounts: This
                  rule ensures that Microsoft Defender for Cloud is enabled for Azure storage accounts.</li>
</ul><div class="p">Rule Updates</div><ul class="ul" id="whatsnew_0ab_344_ca0__ul_8fb_718">
<li class="li">Updated the following rules to enhance check result and improve the way exceptions
                  are handled:</li>
<li class="li">CloudVPC-004: Default VPC Network In Use</li>
<li class="li">CloudVPC-005: Check for Legacy Networks</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_1e1_256">
<li class="li">Updated the following rules check results with minor text changes:</li>
<li class="li">SecurityCenter-032: Enable Microsoft Defender for Cloud for Virtual Machines</li>
<li class="li">SecurityCenter-033: Enable Microsoft Defender for Cloud for App Service</li>
<li class="li">SecurityCenter-034: Enable Microsoft Defender for Cloud for Key Vaults</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_e2f_d8f">
<li class="li">The following rules will now have no checks for Google Kubernetes (GKE) clusters as
                  the best practices do not apply to GKE clusters:</li>
<li class="li">ComputeEngine-001: Check for Virtual Machine Instances with Public IP Addresses</li>
<li class="li">ComputeEngine-004: Disable IP Forwarding for Virtual Machine Instances</li>
<li class="li">ComputeEngine-006: Check for Instances Associated with Default Service Accounts</li>
<li class="li">ComputeEngine-008: Check for Instance-Associated Service Accounts with Full API Access</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_5a2_691">
<li class="li">VirtualMachines-023:Enable Accelerated Networking for Virtual Machines: Enabled a
                  feature to exclude checks by `tags` or `resourceId` for the rule.</li>
</ul><ul class="ul" id="whatsnew_0ab_344_ca0__ul_201_bc7">
<li class="li">ActiveDirectory-003: Check for Active Directory Guest Users: Updated Active-Directory
                  003 to evaluate 100 guest users instead of all the guest users.</li>
</ul>]]></description>
    <pubDate>Mon, 04 Jul 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-compliance-monitoring-and</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Device Control feature enhances security by managing access to USB and mobile devices</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-device-control-feature-enhances-se</link>
    <description><![CDATA[<div class="p">July 06, 2022, Workload Security—Device Control enables Trend Cloud One users to manage
               access to both USB mass storage and mobile devices on server and desktop machines.
               Administrators can use Device Control to set user permission levels (Full Access,
               Read-Only, or Blocked) to comply with their organization's security policy and avoid
               data loss, leakage, and security risk. Device Control is available for Deep Security
               Agent for Windows (version 20.0.0.4959+) and for macOS (version 20.0.0-158+).</div>]]></description>
    <pubDate>Wed, 06 Jul 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-device-control-feature-enhances-se</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity Full Access Users Can Create Custom Roles with Varied Permissions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-full-access-users-can-c</link>
    <description><![CDATA[<div class="p">July 08, 2022, Conformity—Cloud One Conformity Full Access users can now create Conformity
               Custom Roles that can be set up with the different levels of access permissions for
               different accounts. Follow <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-roles-and-permissions-#custom-role" target="_blank">these steps</a> to create a Custom Role and assign the access permissions i.e. Full Access, Read-Only,
               or No Access in Conformity and then map it to any Trend Micro Cloud One ™ role from
               User Management &gt;&gt; Administration &gt;&gt; Roles.</div>]]></description>
    <pubDate>Fri, 08 Jul 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-full-access-users-can-c</guid>
    <category>Conformity</category>
</item>
<item>
    <title>MacOS Support Added for Deep Security Agent Version 20.0.0-158</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-macos-support-added-for-deep-secur</link>
    <description><![CDATA[<div class="p">July 11, 2022, Workload Security—Deep Security Agent version 20.0.0-158 (20 LTS Update
               2022-07-11) is now available for macOS.</div><div class="p">This is currently available only for Trend Cloud One - Endpoint &amp; Workload Security
               customers. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-agent-release-notes-#2022-07-11" target="_blank">What's new in the agent</a>.</div>]]></description>
    <pubDate>Mon, 11 Jul 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-macos-support-added-for-deep-secur</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Public Usage API now available for all Cloud One subscribers</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-public-usage-api-now-available-for</link>
    <description><![CDATA[<div class="p">July 14, 2022, Billing and Subscription Management—Our public Usage API is officially
               available to all Cloud One subscribers. You can check your Cloud One usage records
               by using our public API. For more information, please see our <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-billing-subscription-billing--billing-and-subscription-management-api-reference" target="_blank">API Reference guide</a>.</div>]]></description>
    <pubDate>Thu, 14 Jul 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-public-usage-api-now-available-for</guid>
    <category>Billing and Subscription Management</category>
</item>
<item>
    <title>Conformity Enhancements: Enforce API Key Safe IP Ranges and New Rule Updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-enforce-ap</link>
    <description><![CDATA[<div class="p">July 18, 2022, Conformity—The following features and updates are now available with
               Conformity's latest release on 18 July 2022.</div><ul class="ul" id="whatsnew_98a_871_103__ul_599_a7f">
<li class="li">Conformity now allows admins to enforce API key safe IP ranges being used when creating
                  API keys.</li>
</ul><ul class="ul" id="whatsnew_98a_871_103__ul_277_825">
<li class="li">RTM-005: Users Signed into AWS from an Approved Country: Conformity now supports North
                  Macedonia previously known as Macedonia (Macedonia changed its name to North Macedonia).</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_98a_871_103__ul_61f_673">
<li class="li">Fixed a bug with the Jira communications channel to display only active users in the
                  channel's 'Assignee' list.</li>
</ul><ul class="ul" id="whatsnew_98a_871_103__ul_cbb_918">
<li class="li">Fixed a bug with the display of CSV Compliance Standard report data when importing
                  it in Excel format through the 'Import data' wizard.</li>
</ul><ul class="ul" id="whatsnew_98a_871_103__ul_d74_adf">
<li class="li">Fixed a bug where the 'Configure rule...' and 'Send rule to...' options became visible
                  for custom checks created along with the existing custom rules.</li>
</ul><ul class="ul" id="whatsnew_98a_871_103__ul_283_348">
<li class="li">Fixed a bug to enhance the performance of the RTM Event Monitoring dashboard section
                  to prevent screen performance issues for customers with a large number of RTM events.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.37. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_98a_871_103__ul_02f_487">
<li class="li">VirtualMachines-037: Server Side Encryption for Unattached Disk using CMK: This rule
                  ensures that unattached managed disk volumes are encrypted at rest using Customer-Managed
                  Keys (CMKs).</li>
</ul><ul class="ul" id="whatsnew_98a_871_103__ul_77f_89c">
<li class="li">Network-022: Check for Unrestricted HTTPS Access: This rule ensures that no network
                  security groups allow unrestricted inbound access on TCP port 443. *This rule was
                  released on 4th July 2022 and was missed out from our release communications. We apologise
                  for the miscommunication and the confusion.*</li>
</ul><div class="p">GCP</div><ul class="ul" id="whatsnew_98a_871_103__ul_17a_60d">
<li class="li">CloudIAM-011: Minimize the Use of Primitive Roles: This rule limits the use of primitive
                  roles, for example, `Owner`, `Editor`, and `Viewer` for Cloud IAM members in production
                  and security-critical cloud environments.</li>
</ul><div class="p">Rule Update</div><ul class="ul" id="whatsnew_98a_871_103__ul_57c_96e">
<li class="li">Network-015: Check for Unrestricted UDP Access: Updated the rule to prevent Conformity
                  Bot from generating false positive checks for some scenarios, for example, security
                  groups with `Access Deny` configurations.</li>
</ul>]]></description>
    <pubDate>Mon, 18 Jul 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-enforce-ap</guid>
    <category>Conformity</category>
</item>
<item>
    <title>File Storage Security introduces Scan Activity support for GCP</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-introduces-s</link>
    <description><![CDATA[<div class="p">July 21, 2022, File Storage Security—File Storage Security now supports Scan Activity
               for GCP.</div>]]></description>
    <pubDate>Thu, 21 Jul 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-introduces-s</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Deep Security Agents now require FQDNs for connectivity starting December 31, 2022</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agents-now-require-f</link>
    <description><![CDATA[<div class="p">July 21, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security accounts
               created prior to November 23, 2020 may still be allowing their Deep Security Agents
               access to Trend Cloud One - Endpoint &amp; Workload Security by using static IP addresses
               provided on the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-communication-ports-urls-ip-#Deep5" target="_blank">Port numbers, URLs, and IP addresses</a> documentation page. Starting on December 31, 2022, the Agent will connect only by
               using the fully-qualified domain names (FQDNs) and not by using IP addresses. To avoid
               service interruptions, customers filtering outbound traffic from their protected workloads
               to the outside internet must ensure they configured their firewall to add allowlist
               entries for the URLs listed at <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-communication-ports-urls-ip-#Deep5" target="_blank">Port numbers, URLs, and IP addresses</a> prior to December 31, 2022. If you do not filter outbound traffic or you are already
               using FQDNs, there is no action required.</div><div class="p">How do I know whether I need to change something in my environment?</div><div class="p">If your network is filtering outbound traffic to the internet using any static IP
               addresses listed <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-communication-ports-urls-ip-#Deep5" target="_blank">on this page</a>, you must update your firewall's allowlist to use the domain-name URLs instead of
               the IPs.</div>]]></description>
    <pubDate>Thu, 21 Jul 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agents-now-require-f</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Remote Custom Script Tasks Supported for Deep Security Agent 20.0.0-5137 and Later</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-remote-custom-script-tasks-support</link>
    <description><![CDATA[<div class="p">July 26, 2022, Workload Security—When registered with Trend Vision One, Trend Cloud
               One - Endpoint &amp; Workload Security can now <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-custom-script-" target="_blank">run remote custom script tasks</a> for customers using Deep Security Agent version 20.0.0-5137 or later for Linux or
               Windows.</div>]]></description>
    <pubDate>Tue, 26 Jul 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-remote-custom-script-tasks-support</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Agents can trigger all scheduled malware scans in Trend Cloud One - Endpoint &amp; Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agents-can-trigger-all-scheduled-m</link>
    <description><![CDATA[<div class="p">July 26, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security now
               allows agents to trigger all scheduled scans for malware. To enable this feature,
               select Anti-Malware &gt; General, then ensure that Enable agent to trigger scheduled
               scans for malware is selected. This feature is available for Trend Cloud One - Endpoint
               &amp; Workload Security customers in all regions.</div>]]></description>
    <pubDate>Tue, 26 Jul 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agents-can-trigger-all-scheduled-m</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Automatic Pattern Update for GCP enhances File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automatic-pattern-update-for-gcp-e</link>
    <description><![CDATA[<div class="p">July 29, 2022, File Storage Security—File Storage Security now supports Automatic
               Pattern Update for GCP.</div><div class="p">This functionality requires a stack update.</div>]]></description>
    <pubDate>Fri, 29 Jul 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automatic-pattern-update-for-gcp-e</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Deploy Network Security with Hosted Infrastructure for Streamlined Protection</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deploy-network-security-with-hoste</link>
    <description><![CDATA[<div class="p">August 02, 2022, Network Security—Network Security with hosted infrastructure: You
               can now deploy Network Security with hosted infrastructure to monitor traffic and
               assess threats in your environment. The streamlined, 2-step deployment process gives
               you the same advanced network protection without having to manage security infrastructure.
               <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-NSMS_intro-" target="_blank">Learn more</a> about the capabilities and benefits of deploying Network Security with hosted infrastructure.</div>]]></description>
    <pubDate>Tue, 02 Aug 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deploy-network-security-with-hoste</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Enhanced Agent Connectivity Options for Windows and macOS</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-agent-connectivity-option</link>
    <description><![CDATA[<div class="p">August 02, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               now allows agents to apply OS proxy or direct connect when the configured proxy is
               unavailable. To enable this option, open the Administration tab and go to System Settings
               &gt; Proxies. Ensure that Yes is selected for Allow agents to apply OS proxy or direct
               connect when the configured proxy is inaccessible. This feature supports Windows and
               macOS.</div>]]></description>
    <pubDate>Tue, 02 Aug 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-agent-connectivity-option</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced File Storage Security now supports additional GCP regions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-storage-security-now</link>
    <description><![CDATA[<div class="p">August 03, 2022, File Storage Security—Updated File Storage Security supported GCP
               regions. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-supported-gcp-#GCPRegion" target="_blank">what's supported in GCP</a>.</div>]]></description>
    <pubDate>Wed, 03 Aug 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-file-storage-security-now</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>New Container Security Feature Provides Real-Time Visibility into Running Container Vulnerabilities</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-container-security-feature-pro</link>
    <description><![CDATA[<div class="p">August 05, 2022, Container Security—Containers are key parts of most Cloud Native
               Applications and, as it is well known, these applications contain a lot of open source
               code. According to the Linux Foundation, approximately between 70% and 90% of all
               cloud-native code is open source. However, over 95% of organizations lack real-time
               visibility into vulnerabilities in their running containers.</div><div class="p">Coming soon to Cloud One - Container Security is a new feature that will enable organizations
               visibility of open source and operating system vulnerabilities running in their containers.
               This new view will provide actionable detections with context and enable teams to
               identify risky applications in production at a glance - all without having their images
               leaving their cluster.</div><div class="p">This feature will be available in private preview soon and Trend Micro is looking
               for customers that would like to be the first to have a chance to test it out and
               helps us shape the future of this feature.</div>]]></description>
    <pubDate>Fri, 05 Aug 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-container-security-feature-pro</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Runtime Security to Support AWS Bottlerocket OS V 5.10 on EKS</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-runtime-security-to-support-aws-bo</link>
    <description><![CDATA[<div class="p">August 08, 2022, Container Security—Runtime Security will soon support AWS Bottlerocket
               OS V 5.10 on EKS.</div>]]></description>
    <pubDate>Mon, 08 Aug 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-runtime-security-to-support-aws-bo</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Cost Optimization Feature Deprecated to Focus on Cloud Security Posture Management</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cost-optimization-feature-deprecat</link>
    <description><![CDATA[<div class="p">August 09, 2022, Conformity—End of Life - Conformity Cost Optimization Feature</div><div class="p">In *April 2020*, we decided to deprecate the Cost Optimization feature, which has
               helped Standalone Conformity customers manage their AWS costs. It has been deprecated
               as of *July 2022* and will reach the end of life on 10th September 2022.</div><div class="p">Why are we doing this?</div><div class="p">The Cost Optimization feature used data from the deprecated AWS ‘Detailed Billing
               Report’. AWS strongly recommends that all customers move away from this report and
               migrate to the newer <a class="xref" href="https://docs.aws.amazon.com/cur/latest/userguide/detailed-billing-migrate.html" target="_blank">Cost and Usage Report</a>.</div><div class="p">We have decided to discontinue all support for Cost Analysis as our strategic focus
               as Trend Micro Cloud One ™ Conformity is on core Cloud Security Posture management
               (CSPM) features.</div><div class="p">What does it mean for you?</div><div class="p">No Cost Optimization widget - you will stop seeing the Cost Optimization widget on
               your Organizations’ Main Dashboard.</div><div class="p">What happens to the Cost Rules?</div><div class="p">All Cost category rules except for the following Rules will still be available to
               all customers. We’re deprecating these four Rules because their AWS data source is
               a deprecated AWS billing report.</div><ul class="ul" id="whatsnew_6af_c9b_83e__ul_514_8fb">
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Budgets/budget-overrun.html" target="_blank">Budgets- 001: Budget Overrun</a></li>
</ul><ul class="ul" id="whatsnew_6af_c9b_83e__ul_47b_735">
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Budgets/cost-fluctuation.html" target="_blank">Budgets -002: Cost Fluctuation</a></li>
</ul><ul class="ul" id="whatsnew_6af_c9b_83e__ul_61c_e64">
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Budgets/budget-overrun-forecast.html" target="_blank">Budgets-003: Budgets Overrun Forecast</a></li>
</ul><ul class="ul" id="whatsnew_6af_c9b_83e__ul_a69_64a">
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Budgets/cost-fluctuation-forecast.html" target="_blank">Budgets-004: Cost Fluctuation Forecast</a></li>
</ul><div class="p">What do I need to do?</div><div class="p">You don't need to do anything at your end. If you wish, you can turn off the AWS Billing
               report used by Conformity. If you have any concerns or queries regarding the end of
               life for the Cost Optimization feature, please reach out to your account managers.</div><div class="p">*This feature is unavailable to our Trend Micro Cloud One ™ Conformity customers.*</div>]]></description>
    <pubDate>Tue, 09 Aug 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cost-optimization-feature-deprecat</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity introduces new Azure network security rules and bug fixes</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-azure-ne</link>
    <description><![CDATA[<div class="p">August 10, 2022, Conformity—The following features and updates are now available with
               Conformity's latest release on 10 August 2022.</div><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_0ac_21d_b9f__ul_e1e_32a">
<li class="li">Fixed a timeout bug happening when adding an AWS account vis Public API.</li>
<li class="li">Fixed a bug with SNS notifications being triggered for excluded resources in any rule
                  for AWS, Azure and GCP bots.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.37. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_0ac_21d_b9f__ul_124_a4b">
<li class="li">Network-021: Check for Unrestricted MongoDB Access: This rule ensures that no network
                  security groups allow unrestricted inbound access on TCP ports 27017, 27018 and 27019.</li>
</ul><ul class="ul" id="whatsnew_0ac_21d_b9f__ul_4f0_c80">
<li class="li">Azure: Network-024: Check for Unrestricted NetBIOS Access: This rule ensures that
                  no network security groups allow unrestricted inbound access on TCP port 139 and UDP
                  ports 137 and 138 (NetBIOS).</li>
</ul><ul class="ul" id="whatsnew_0ac_21d_b9f__ul_d5c_1b2">
<li class="li">Azure: VirtualMachines-039: Server Side Encryption for Boot Disk using CMK: This rule
                  ensures that Azure VM managed disk boot volumes are encrypted at rest using customer-managed
                  keys (CMKs).</li>
</ul>]]></description>
    <pubDate>Wed, 10 Aug 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-azure-ne</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Web Reputation Coverage for Port 443 in Trend Cloud One Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-web-reputation-coverage-f</link>
    <description><![CDATA[<div class="p">August 15, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               now includes port 443 by default in the values for the setting "Ports to monitor for
               potentially harmful web pages" (Computer or Policy editor &gt; Web Reputation &gt; Advanced).
               Port 443 is included by default _in addition to_ the existing default ports 80 and
               8080. When using Trend Cloud One - Endpoint &amp; Workload Security with Deep Security
               Agent version 20.0.0.5137 or later, the Web Reputation feature can now protect all
               default ports, including 443, on both Linux and Windows when native TLS libraries
               or communication channels are being used.</div>]]></description>
    <pubDate>Mon, 15 Aug 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-web-reputation-coverage-f</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>File Storage Security adds support for AWS Hong Kong region</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-adds-support</link>
    <description><![CDATA[<div class="p">August 22, 2022, File Storage Security—File Storage Security now supports Hong Kong
               (ap-east-1) region on AWS. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-supported-aws-#AWSRegion" target="_blank">what's supported in AWS</a>.</div>]]></description>
    <pubDate>Mon, 22 Aug 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-adds-support</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity Enhancements: Expanded GCP Project Onboarding, Updated Compliance Standards, and New Rules</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-expanded-g</link>
    <description><![CDATA[<div class="p">August 23, 2022, Conformity—The following features and updates are now available with
               Conformity's latest release on 23 August 2022.</div><ul class="ul" id="whatsnew_839_cd6_5c0__ul_925_470">
<li class="li">You can now search and add GCP projects while onboarding your GCP accounts to Conformity.</li>
</ul><ul class="ul" id="whatsnew_839_cd6_5c0__ul_cf1_e03">
<li class="li">You can also view and onboard all GCP projects as we've eliminated the 100 projects
                  limit.</li>
</ul><ul class="ul" id="whatsnew_839_cd6_5c0__ul_679_117">
<li class="li">Uninstall <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-real-time-threat-monitoring-#uninstall-real-time-threat-monitoring" target="_blank">Azure RTM script</a> is now available.</li>
</ul><ul class="ul" id="whatsnew_839_cd6_5c0__ul_baa_733">
<li class="li">Updated the following Compliance Standards and Reports to include newly release rules:</li>
</ul><ul class="ul" id="whatsnew_839_cd6_5c0__ul_731_08e">
<li class="li">HITRUST CSF v9.3</li>
<li class="li">HIPAA 45CFR164</li>
<li class="li">NIST 800-53 Rev4</li>
<li class="li">FedRAMP rev4</li>
<li class="li">SOC 2 Nov 2019</li>
</ul><ul class="ul" id="whatsnew_839_cd6_5c0__ul_1ac_61c">
<li class="li">Updated the following Compliance &amp; Conformity Reports to include newly released rules:</li>
</ul><ul class="ul" id="whatsnew_839_cd6_5c0__ul_d79_cf1">
<li class="li">ISO 27001:2013 - updated May 2022</li>
<li class="li">NIST 800-53 Rev5 - updated June 2022, also available to GCP accounts now</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_839_cd6_5c0__ul_938_425">
<li class="li">Fixed a bug to improve CSV compliance and generic reports generation with a huge number
                  of checks.</li>
</ul><ul class="ul" id="whatsnew_839_cd6_5c0__ul_8cb_2f9">
<li class="li">Fixed a bug to change the API response from status code `200` to `422` when a custom
                  rule is run with wrong configuration.</li>
</ul><ul class="ul" id="whatsnew_839_cd6_5c0__ul_9b0_8fc">
<li class="li">Fixed a bug where account level rule setting exceptions were deleted on applying a
                  profile with no configured exceptions AND “include exceptions” unchecked.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">We've updated the custom policy as a result of the new deployment. The new custom
               policy version is 1.38. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">And the new permissions added are:</div><ul class="ul" id="whatsnew_839_cd6_5c0__ul_10a_eb0">
<li class="li">`appflow:DescribeFlow`</li>
</ul><ul class="ul" id="whatsnew_839_cd6_5c0__ul_f32_2f0">
<li class="li">`appflow:ListFlows`</li>
</ul><div class="p">New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_839_cd6_5c0__ul_184_c97">
<li class="li">Network-025: Check for Unrestricted Inbound TCP or UDP Access on Selected Ports: This
                  rule ensures that no network security groups allow unrestricted inbound access via
                  TCP or UDP on selected ports.</li>
</ul><div class="p">AWS</div><ul class="ul" id="whatsnew_839_cd6_5c0__ul_3d4_e94">
<li class="li">AppFlow-001: Enable Data Encryption with KMS Customer Master Keys: This rule ensures
                  that Amazon AppFlow flows are encrypted with KMS Customer Master Keys (CMKs).</li>
</ul><div class="p">GCP</div><ul class="ul" id="whatsnew_839_cd6_5c0__ul_109_7cb">
<li class="li">CloudLoadBalancing-002: Check for Cloud SQL Database Instances with Public IPs: This
                  rule ensures that Cloud SQL database instances don't have any public IP addresses
                  assigned.</li>
</ul><div class="p">Rule Bug Fix</div><ul class="ul" id="whatsnew_839_cd6_5c0__ul_3ae_f14">
<li class="li">CT-002 CloudTrail S3 Bucket Logging Enabled: Fixed a bug where the rule did not correctly
                  exclude the relevant S3 resource using exceptions via tags.</li>
</ul>]]></description>
    <pubDate>Tue, 23 Aug 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-expanded-g</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Automatic Function Code Update for GCP in File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automatic-function-code-update-for</link>
    <description><![CDATA[<div class="p">August 23, 2022, File Storage Security—File Storage Security now supports automatic
               function code update for GCP.</div><div class="p">This functionality requires a stack update.</div>]]></description>
    <pubDate>Tue, 23 Aug 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automatic-function-code-update-for</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Support for Ubuntu 22.04 (AWS ARM) and AIX 7.3 added in</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-ubuntu-2204-aws-arm-an</link>
    <description><![CDATA[<div class="p">August 29, 2022, Workload Security—Agent version 20.0.0-5394 has been released.</div><div class="p">This release includes:</div><ul class="ul" id="whatsnew_53f_6b4_98e__ul_884_f78">
<li class="li">Support for Ubuntu 22.04 (AWS ARM-based Graviton 2) and AIX 7.3. These platforms require
                  Deep Security Manager version 20.0.677 or later.</li>
<li class="li">Several enhancements and resolved issues</li>
</ul><div class="p">For detailed information on what's included in this version, see <a class="xref" href="https://help.deepsecurity.trendmicro.com/20_0/on-premise/release-notes-dsa.html" target="_blank">What's New in Deep Security Agent</a>.</div>]]></description>
    <pubDate>Mon, 29 Aug 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-ubuntu-2204-aws-arm-an</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Remote Shell feature added for macOS agents in Trend Cloud One - Endpoint &amp; Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-remote-shell-feature-added-for-mac</link>
    <description><![CDATA[<div class="p">August 29, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               customers running Deep Security Agent for macOS (version 20.0.0-173 or later) can
               now use Remote Shell through the Trend Vision One Portal. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-remote-shell-" target="_blank">Trend Vision One (XDR) Remote Shell</a>.</div>]]></description>
    <pubDate>Mon, 29 Aug 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-remote-shell-feature-added-for-mac</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved AWS Scanner Lambda function configuration stability</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-scanner-lambda-functi</link>
    <description><![CDATA[<div class="p">September 06, 2022, File Storage Security—Fixed the issue where the AWS Scanner Lambda
               function would lose the environment variable configuration in some situations when
               updating stack parameters.</div>]]></description>
    <pubDate>Tue, 06 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-scanner-lambda-functi</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity Enhancements: New Compliance Standards, Bug Fixes, and Azure Rule Updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-new-compli</link>
    <description><![CDATA[<div class="p">September 07, 2022, Conformity—The following features and updates are now available
               with Conformity's latest release on 7 September 2022.</div><ul class="ul" id="whatsnew_b5a_926_f49__ul_d2e_1e5">
<li class="li">Updated the following Compliance Standards and Reports to include newly released rules:</li>
</ul><ul class="ul" id="whatsnew_b5a_926_f49__ul_982_aad">
<li class="li">Monetary Authority of Singapore MAS-TRM 2021</li>
<li class="li">NIST CyberSecurity Framework</li>
<li class="li">AusGov ISM</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_b5a_926_f49__ul_969_d94">
<li class="li">Fixed a bug that was preventing users from successfully updating the CQL filter for
                  an existing saved report.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.38. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_b5a_926_f49__ul_ac9_513">
<li class="li">StorageAccounts-021: Configure Minimum TLS Version: This rule ensures that the "Minimum
                  TLS version" setting is set to "Version 1.2" for all Azure Storage accounts.</li>
</ul><div class="p">Rule Update</div><ul class="ul" id="whatsnew_b5a_926_f49__ul_cca_033">
<li class="li">EKS-001: EKS Cluster Endpoint Public Access: Added an optional rule configuration
                  to Safelist source IP addresses from the EKS cluster "Public access source allowlist".
                  If all the source IP addresses in the EKS "Public access source allowlist" are in
                  the configured Safelist, the rule will succeed.</li>
</ul><div class="p">Rule Bug Fix</div><ul class="ul" id="whatsnew_b5a_926_f49__ul_319_b23">
<li class="li">VirtualMachines-013: Enable Backups for Azure Virtual Machines: Fixed a bug where
                  an incorrect failure check was generated for a re-created VM instance using a previously
                  used name.</li>
</ul>]]></description>
    <pubDate>Wed, 07 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-new-compli</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved display of metadata in GCP PU scan results</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-display-of-metadata-in-gc</link>
    <description><![CDATA[<div class="p">September 07, 2022, File Storage Security—Fix the issue where GCP PU displays the
               `fss-error-message` metadata even if the scan success.</div>]]></description>
    <pubDate>Wed, 07 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-display-of-metadata-in-gc</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>GCP General Availability with Marketplace Consumption Pricing for Cloud One Conformity Customers</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-general-availability-with-mark</link>
    <description><![CDATA[<div class="p">September 13, 2022, Conformity—Announcing the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-sentry-#ga" target="_blank">General Availability</a>- GA of GCP for Cloud One Conformity Customers.</div><div class="p">What does it mean for you?</div><ul class="ul" id="whatsnew_cbb_4c2_d42__ul_7f8_797">
<li class="li">If you are currently subscribing through AWS or Azure marketplace, the metered billing
                  for your GCP accounts using Cloud One - Conformity will start on September 13th, 2022.</li>
</ul><ul class="ul" id="whatsnew_cbb_4c2_d42__ul_8eb_011">
<li class="li">If you are currently using the 30-day free trial, the metered billing won’t start
                  until your trial period is over and you subscribe to the service.</li>
</ul><div class="table" id="whatsnew_cbb_4c2_d42__table_dt3_2qh_pfc">
<h4 class="table-title">Marketplace Consumption Pricing for Cloud One Conformity</h4>
<table border="1" class="tgroup">
<colgroup class="colspec" style="width: 50%;"></colgroup>
<colgroup class="colspec" style="width: 50%;"></colgroup>
<thead class="thead table-header-style">
<tr class="row">
<td class="entry">
<div class="p">Cloud Account Resource Count</div>
</td>
<td class="entry">
<div class="p">Pricing</div>
</td>
</tr>
</thead>
<tbody class="tbody">
<tr class="row">
<td class="entry">
<div class="p">Accounts with &lt; 250 resources</div>
</td>
<td class="entry">
<div class="p">$0.00/hr</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">Per cloud account with 250-1,000 resources</div>
</td>
<td class="entry">
<div class="p">$0.07/hr</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">Accounts with 1001-5,000 resources</div>
</td>
<td class="entry">
<div class="p">$0.29/hr</div>
</td>
</tr>
<tr class="row">
<td class="entry">
<div class="p">account 5,001+ resources</div>
</td>
<td class="entry">
<div class="p">$0.35/hr</div>
</td>
</tr>
</tbody>
</table>
</div><div class="p">For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity--billing-and-subscription-management-billing-pricing-" target="_blank">Cloud One billing</a>.</div><div class="p">The following rules, standards and enhancements are already available for all GCP
               customers:</div><ul class="ul" id="whatsnew_cbb_4c2_d42__ul_66b_3ba">
<li class="li">90+ cloud security configuration rules</li>
<li class="li">PCI-DSS-V3.2.1 standard</li>
<li class="li">ISO-27001:2013 standard</li>
<li class="li">APRA CPS 234</li>
<li class="li">NIST 800-53 Rev5</li>
<li class="li">Ability to search for projects while onboarding</li>
<li class="li">While onboarding GCP projects on Conformity via UI, the customer could only see 100
                  projects at a time due to a project cap in Conformity. This project cap is now removed,
                  and users will be able to view &amp; onboard all GCP projects within a service account.</li>
</ul>]]></description>
    <pubDate>Tue, 13 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-general-availability-with-mark</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Cloud One Audit Log now includes sign-in and sign-out events for improved tracking</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloud-one-audit-log-now-includes-s</link>
    <description><![CDATA[<div class="p">September 21, 2022, Billing and Subscription Management—Account sign-in and sign-out
               events will soon be available in the Cloud One Audit Log. As part of this enhancement,
               the following audit logs will be changed:</div><ul class="ul" id="whatsnew_849_dfc_bd3__ul_f6a_ef5">
<li class="li">The "Token Created" event will be changed to "User Signed In"</li>
<li class="li">The "Token Created" event type will be changed to "audit.user-signed-in.v1" from "audit.token-creation.v1"</li>
<li class="li">The "Token Revoked" event will be changed to "User Signed Out"</li>
<li class="li">The "Token Revoked" event type will be changed to "audit.user-signed-out.v1" from
                  "audit.token-revocation.v1".</li>
</ul>]]></description>
    <pubDate>Wed, 21 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloud-one-audit-log-now-includes-s</guid>
    <category>Billing and Subscription Management</category>
</item>
<item>
    <title>Improved Azure Scanner function now scans files without timing out</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-azure-scanner-function-no</link>
    <description><![CDATA[<div class="p">September 21, 2022, File Storage Security—Fixed the issue that the Azure Scanner function
               would time out when scanning certain files.</div>]]></description>
    <pubDate>Wed, 21 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-azure-scanner-function-no</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Azure Scanner now supports scanning larger files within zip files</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-scanner-now-supports-scannin</link>
    <description><![CDATA[<div class="p">September 21, 2022, File Storage Security—Azure Scanner now supports scanning larger
               files in zip files.</div>]]></description>
    <pubDate>Wed, 21 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-scanner-now-supports-scannin</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Agents can now trigger or cancel manual scans from the Trend Micro notifier</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agents-can-now-trigger-or-cancel-m</link>
    <description><![CDATA[<div class="p">September 21, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               now supports having agents trigger or cancel a manual scan from the Trend Micro notifier
               application (Computer or Policy editor &gt; Anti-Malware &gt; General) Once the checkbox
               Allow agent to trigger or cancel a manual scan from Trend Micro's notifier application
               has been selected, the notifier application will display the Scan section. Available
               for Windows and macOS agents.</div>]]></description>
    <pubDate>Wed, 21 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agents-can-now-trigger-or-cancel-m</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Linux/Unix Agent Scanning with Multi-thread Support and Additional Host Details</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-linuxunix-agent-scanning</link>
    <description><![CDATA[<div class="p">September 22, 2022, Workload Security—Agent version 20.0.0-5512 has been released.</div><div class="p">This release includes:</div><ul class="ul" id="whatsnew_145_c9e_bcf__ul_626_ddd">
<li class="li">Multi-thread support for On-demand and Scheduled Scans on agents for Linux and Unix.</li>
<li class="li">Additional host metadata and installed software details reported by agents for Linux.</li>
<li class="li">Several resolved issues and security updates.</li>
</ul><div class="p">For detailed information on what's included in this version, see <a class="xref" href="https://help.deepsecurity.trendmicro.com/20_0/on-premise/release-notes-dsa.html" target="_blank">What's New in Deep Security Agent</a>.</div>]]></description>
    <pubDate>Thu, 22 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-linuxunix-agent-scanning</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Workload Security now supports Memory Dump Remote Shell on Trend Vision One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-workload-security-now-supports-mem</link>
    <description><![CDATA[<div class="p">September 22, 2022, Workload Security—When registered with Trend Vision One, Workload
               Security now supports the process memory dump Remote Shell command on Deep Security
               Agent version 20.0.0-5512 or later for Windows. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-remote-shell-" target="_blank">Trend Vision One (XDR) Remote Shell</a>.</div>]]></description>
    <pubDate>Thu, 22 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-workload-security-now-supports-mem</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Forward Device Control events to Trend Vision One for enhanced visibility</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-forward-device-control-events-to-t</link>
    <description><![CDATA[<div class="p">September 23, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               now supports forwarding Device Control events to Trend Vision One. Customers must
               be registered with Trend Vision One to support this feature. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-xdr-" target="_blank">Integrate Trend Cloud One - Endpoint &amp; Workload Security with Trend Vision One</a>.</div>]]></description>
    <pubDate>Fri, 23 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-forward-device-control-events-to-t</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved Identity Provider Integration for Trend Cloud One Accounts</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-identity-provider-integra</link>
    <description><![CDATA[<div class="p">September 23, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               accounts that sign in to Trend Cloud One are now redirected to the Identity Providers
               page. This page allows users to connect to an identity provider from Trend Cloud One
               rather than connecting through Trend Cloud One - Endpoint &amp; Workload Security. For
               accounts already using the workload-only SAML, the login page will be unchanged.</div>]]></description>
    <pubDate>Fri, 23 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-identity-provider-integra</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>AWS Security Hub Integration User Interface Now Configurable in Cloud One Management Console</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-security-hub-integration-user</link>
    <description><![CDATA[<div class="p">September 26, 2022, Integrations—AWS Security Hub Integration User Interface Release:
               you can now configure AWS Security Hub with Cloud One using the management console.
               For more information and instructions, <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-integrations-security-hub-" target="_blank">click here</a>.</div>]]></description>
    <pubDate>Mon, 26 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-security-hub-integration-user</guid>
    <category>Integrations</category>
</item>
<item>
    <title>Conformity introduces new GCP and Azure rules, Compliance Standards updates, and bug fixes</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-gcp-and</link>
    <description><![CDATA[<div class="p">September 28, 2022, Conformity—The following features and updates are now available
               with Conformity's latest release on 28 September 2022.</div><ul class="ul" id="whatsnew_d16_296_7b2__ul_be5_e1d">
<li class="li">Updated the following Compliance Standards and Reports to include the newly released
                  rules:</li>
</ul><ul class="ul" id="whatsnew_d16_296_7b2__ul_d9e_073">
<li class="li">Azure Well-Architected Framework</li>
<li class="li">AWS Well-Architected Framework</li>
<li class="li">NIS Europe OES-2019</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_d16_296_7b2__ul_67e_88b">
<li class="li">Fixed a bug where the Lambda rules displayed only 50 checks per region.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.38. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_d16_296_7b2__ul_4cc_a2b">
<li class="li">GKE-001: Enable GKE Cluster Node Encryption with Customer-Managed Keys:  This rule
                  ensures that boot disk encryption with Customer-Managed Keys is enabled for GKE cluster
                  nodes.</li>
</ul><ul class="ul" id="whatsnew_d16_296_7b2__ul_d16_632">
<li class="li">BigQuery-003: Enable BigQuery Dataset Encryption with Customer-Managed Encryption
                  Keys: This rule ensures that all your Google Cloud BigQuery datasets are encrypted
                  using Customer-Managed Encryption Keys (CMEKs).</li>
</ul><ul class="ul" id="whatsnew_d16_296_7b2__ul_c69_847">
<li class="li">CloudSQL-027: Enable 'cloudsql.enable_pgaudit' and 'pgaudit.log' Flags for PostgreSQL
                  Database Instances: This rule ensures that `cloudsql.enable_pgaudit` and `pgaudit.log`
                  flags are enabled for Google Cloud PostgreSQL server instances.</li>
</ul><ul class="ul" id="whatsnew_d16_296_7b2__ul_aec_31e">
<li class="li">CloudSQL-028: Disable '3625' Trace Flag for SQL Server Database Instances: This rule
                  ensures that the `3625` trace flag for SQL database servers is set to `off`.</li>
</ul><ul class="ul" id="whatsnew_d16_296_7b2__ul_9b3_7e6">
<li class="li">CloudIAM-012: Enable Access Approval: This rule ensures that `Access Approval` is
                  enabled for your Google Cloud account.</li>
</ul><ul class="ul" id="whatsnew_d16_296_7b2__ul_e57_f70">
<li class="li">CloudAPI-004: Enable Cloud Asset Inventory This rule ensures that `Google Cloud Asset
                  Inventory` is enabled for your GCP projects.</li>
</ul><div class="p">Azure</div><ul class="ul" id="whatsnew_d16_296_7b2__ul_591_efb">
<li class="li">PostgreSQL-012: Enable Infrastructure Double Encryption: This rule ensures that infrastructure
                  double encryption is enabled for all Azure PostgreSQL database servers.</li>
</ul><ul class="ul" id="whatsnew_d16_296_7b2__ul_774_f07">
<li class="li">PostgreSQL-013: log_checkpoints" Parameter for PostgreSQL Flexible Servers: This rule
                  ensures that the `log_checkpoints` parameter for your Microsoft Azure PostgreSQL flexible
                  database servers is set to `ON`.</li>
</ul><div class="p">Rule Bug Fix</div><ul class="ul" id="whatsnew_d16_296_7b2__ul_dbe_c48">
<li class="li">ELB-007: ELB Security Group: Fixed a bug where the rule did not generate checks for
                  some regions with access permissions to Conformity.</li>
</ul>]]></description>
    <pubDate>Wed, 28 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-gcp-and</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Outage in Oregon Region Impacting Conformity Application Access and Workflows</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-outage-in-oregon-region-impact</link>
    <description><![CDATA[<div class="p">September 30, 2022, Conformity—From 2022-09-28 16:20 UTC - 20:43 UTC (9:20 AM PDT
               - 1:43 PM PDT)</div><div class="p">AWS experienced a service outage in the us-west-2 (Oregon) region, which affected
               the Conformity application. This outage affected the API Gateway service, which made
               the Conformity application inaccessible during the time window. The service has fully
               recovered now, and Conformity has returned to normal.</div><div class="p">Affected regions</div><div class="p">Oregon service region (us-west-2) and Cloud One US-1</div><div class="p">P.S: No other Conformity regions were impacted.</div><div class="p">Impact</div><div class="p">The customers could not access the Conformity application via the UI or API or successfully
               scan their accounts. Any automated workflows relying on Conformity, for example, the
               API workflows using the Template Scanner, may also have been impacted.</div><div class="p">Resolution</div><div class="p">The service health of Amazon API Gateway has now fully recovered and can be tracked
               here. Conformity also has service returned to normal.</div>]]></description>
    <pubDate>Fri, 30 Sep 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-outage-in-oregon-region-impact</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity Enhancements: New Features, Bug Fixes, and GCP Rules Introduced</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-new-featur</link>
    <description><![CDATA[<div class="p">October 12, 2022, Conformity—The following features and updates are now available
               with Conformity's latest release on 12 October 2022.</div><ul class="ul" id="whatsnew_cb8_060_039__ul_602_14b">
<li class="li">Added the `skipUpdatingEnabledSuppression` attribute to prevent updating the `suppressed`
                  and `suppressed-until` attributes on suppressed checks using the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Checks-" target="_blank">Checks API</a>.</li>
</ul><ul class="ul" id="whatsnew_cb8_060_039__ul_1ef_90c">
<li class="li">Improved our compliance score calculation logic to prevent the score of greater than
                  95% being rounded off to 100%.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_cb8_060_039__ul_e0d_6d6">
<li class="li">Fixed a bug where the Conformity Bot reported stale checks with a large number of
                  EC2 resources.</li>
</ul><ul class="ul" id="whatsnew_cb8_060_039__ul_bbc_108">
<li class="li">Fixed a bug that prevented getting the list of excluded resources in the UI and the
                  public API by making some performance enhancements.</li>
</ul><ul class="ul" id="whatsnew_cb8_060_039__ul_3fb_fc0">
<li class="li">Fixed a bug with the Custom Rules engine that returned an `HTTP 500` error for resources
                  without data.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.38. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_cb8_060_039__ul_b73_e6f">
<li class="li">CloudIAM-013: Essential Contacts for Organizations (Not Scored):  This rule ensures
                  that the Essential Contacts are defined for your Google Cloud organization.</li>
</ul><ul class="ul" id="whatsnew_cb8_060_039__ul_fa0_50b">
<li class="li">ResourceManager-001: Disable User-Managed Key Creation for Service Accounts: This
                  rule ensures that the `Disable Service Account Key Creation` policy is enforced.</li>
</ul><div class="p">Rule Bug Fixes</div><ul class="ul" id="whatsnew_cb8_060_039__ul_f12_b24">
<li class="li">Config-002: AWS Config Referencing Missing S3 Bucket: Fixed a bug where the rule did
                  not return a success check for compliant Config resources on the Provider level.</li>
</ul><ul class="ul" id="whatsnew_cb8_060_039__ul_e40_498">
<li class="li">Fixed an issue where the check region for the following rules incorrectly returned
                  as `ALL`:</li>
</ul><ul class="ul" id="whatsnew_cb8_060_039__ul_b43_00e">
<li class="li">Monitor-002: Activity Log Retention</li>
<li class="li">Monitor-003: Activity Log All Activities</li>
<li class="li">Monitor-004: Activity Log All Regions</li>
<li class="li">Monitor-005: Check for Publicly Accessible Activity Log Storage Container</li>
<li class="li">Monitor-006: Use BYOK for Activity Log Storage Container Encryption</li>
<li class="li">Resources-001: Tags</li>
</ul>]]></description>
    <pubDate>Wed, 12 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-new-featur</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Runtime Security now supports AWS Bottlerocket OS V 5.10 on EKS</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-runtime-security-now-supports-aws</link>
    <description><![CDATA[<div class="p">October 12, 2022, Container Security—Runtime Security now supports AWS Bottlerocket
               OS V 5.10 on EKS.</div>]]></description>
    <pubDate>Wed, 12 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-runtime-security-now-supports-aws</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Public Preview of Vulnerability View enhances container security with real-time visibility</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-public-preview-of-vulnerability-vi</link>
    <description><![CDATA[<div class="p">October 12, 2022, Container Security—Containers are key parts of most Cloud Native
               Applications and these applications contain open source code. According to the Linux
               Foundation, between approximately 70% and 90% of all cloud-native code is made of
               open source. However, over 95% of organizations lack real-time visibility into vulnerabilities
               in their running containers.</div><div class="p">Trend Micro is announcing the Public Preview of Vulnerability View, a new feature
               that enables organizations to have visibility of open source and operating system
               vulnerabilities that are part of their containers in runtime. This new view provides
               actionable detections with context, while enabling teams to identify risky applications
               in production at a glance - all without having their images leaving their cluster.</div>]]></description>
    <pubDate>Wed, 12 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-public-preview-of-vulnerability-vi</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Active Directory Connector now integrated for structured security management</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-active-directory-connector-now-int</link>
    <description><![CDATA[<div class="p">October 14, 2022, Workload Security—The Active Directory Connector allows Trend Cloud
               One - Endpoint &amp; Workload Security to use your Active Directory structure. This feature
               synchronizes AD computer objects, creates grouping structure, and relocates systems
               to use their AD Organizational Unit structure. Please note that this connector requires
               a <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-data-center-gateway-" target="_blank">Cloud One Data Center Gateway</a>. For more details see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-computers-add-active-directory-" target="_blank">AD connector documentation</a>.</div>]]></description>
    <pubDate>Fri, 14 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-active-directory-connector-now-int</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Update Azure Scanner and Storage Stack to Version 4.x by Dec 3, 2022</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-update-azure-scanner-and-storage-s</link>
    <description><![CDATA[<div class="p">October 19, 2022, File Storage Security—You need to update your Azure Scanner Stack
               and Storage Stack to update the function app's runtime to version 4.x before Dec 3,
               2022.</div><div class="p">Beginning on December 3, 2022, function apps running on versions 2.x and 3.x of the
               Azure Functions runtime can no longer be supported.</div><div class="p">This functionality requires a stack update.</div>]]></description>
    <pubDate>Wed, 19 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-update-azure-scanner-and-storage-s</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced software reporting and SAP Scanner support in Deep Security Agent 20.0.0</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-software-reporting-and-sa</link>
    <description><![CDATA[<div class="p">October 21, 2022, Workload Security—Deep Security Agent version 20.0.0-5761 has been
               released.</div><div class="p">This release includes:</div><ul class="ul" id="whatsnew_fc6_e8b_0c0__ul_92f_237">
<li class="li">Improved installed software reporting on agents for Windows.</li>
<li class="li">SAP Scanner support for Oracle Linux 7.</li>
<li class="li">Several enhancements and resolved issues.</li>
</ul><div class="p">For detailed information on what's included in this version, see <a class="xref" href="https://help.deepsecurity.trendmicro.com/20_0/on-premise/release-notes-dsa.html" target="_blank">What's New in Deep Security Agent</a>.</div>]]></description>
    <pubDate>Fri, 21 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-software-reporting-and-sa</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Windows OS proxy exclusion now supported in Trend Cloud One - Endpoint &amp; Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-windows-os-proxy-exclusion-now-sup</link>
    <description><![CDATA[<div class="p">October 21, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               now supports Windows OS proxy exclusion when OS proxy is applied. For details, see
               <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-proxy-os-enable-" target="_blank">Enable OS proxy</a>. This feature is currently only supported on Windows platforms and is available for
               Trend Cloud One - Endpoint &amp; Workload Security customers in all regions.</div>]]></description>
    <pubDate>Fri, 21 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-windows-os-proxy-exclusion-now-sup</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Remote Shell Commands for macOS in Trend Cloud One Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-remote-shell-commands-for</link>
    <description><![CDATA[<div class="p">October 21, 2022, Workload Security—When registered with Trend Vision One, Trend Cloud
               One - Endpoint &amp; Workload Security now supports additional Remote Shell commands on
               Deep Security Agent version 20.0.0-182 and later for macOS. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-remote-shell-#supported-commands" target="_blank">Trend Vision One (XDR) Remote Shell - Supported Commands</a>.</div>]]></description>
    <pubDate>Fri, 21 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-remote-shell-commands-for</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Register for Trend Cloud One and Single Sign One from Trend Vision One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-register-for-trend-cloud-one-and-s</link>
    <description><![CDATA[<div class="p">October 21, 2022, Workload Security—You can now register for Trend Cloud One and sign
               up for Single Sign One from Trend Vision One. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-integrations-xdr-" target="_blank">Integrate Trend Cloud One - Endpoint &amp; Workload Security with Trend Vision One</a>.</div>]]></description>
    <pubDate>Fri, 21 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-register-for-trend-cloud-one-and-s</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Resolved GCP Scanner timeout issue for scanning certain files</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-resolved-gcp-scanner-timeout-issue</link>
    <description><![CDATA[<div class="p">October 24, 2022, File Storage Security—Fixed the issue that the GCP Scanner function
               would time out when scanning certain files.</div>]]></description>
    <pubDate>Mon, 24 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-resolved-gcp-scanner-timeout-issue</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>GCP Scanner now supports scanning larger files in zip files</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-scanner-now-supports-scanning</link>
    <description><![CDATA[<div class="p">October 24, 2022, File Storage Security—GCP Scanner now supports scanning larger files
               in zip files.</div>]]></description>
    <pubDate>Mon, 24 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-scanner-now-supports-scanning</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity introduces new compliance features, bug fixes, and expanded rule support</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-complian</link>
    <description><![CDATA[<div class="p">October 26, 2022, Conformity—The following features and updates are now available
               with Conformity's latest release on 26 October 2022.</div><ul class="ul" id="whatsnew_297_89a_823__ul_03d_80d">
<li class="li">Introducing the 'skipUpdatingEnabledSuppression' attribute in the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Checks" target="_blank">Check API</a> allowing you to prevent updating suppressed checks until you reach your 'suppressed-until'
                  date.</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_173_c55">
<li class="li">You can now add tags when onboarding AWS, Azure or GCP accounts using the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Accounts" target="_blank">Accounts API</a>.</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_94a_794">
<li class="li">The CSV reports now include cost and savings data for the checks related to the cost
                  rules.</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_66c_08a">
<li class="li">Added support for PCI DSS v4 and CIS Controls Version 8 across Conformity compliance
                  features for AWS, Azure and GCP.</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_8e2_3f5">
<li class="li">Added support for CIS GCP Foundation Benchmark Version 1.2.0 in Conformity compliance
                  features.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_297_89a_823__ul_579_3de">
<li class="li">Fixed a bug preventing CSV reports from being generated when compliance reports had
                  0 checks.</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_01c_e71">
<li class="li">Fixed a bug to make notes mandatory while updating the suppressed or unsuppressed
                  property in the Check API regardless of whether the underlying rule is custom or standard.</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_5dc_330">
<li class="li">Fixed a bug where reports generation failed due to a large amount of data.</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_ee3_f5c">
<li class="li">Fixed a bug with the public API `Events get` to strip all html tags (syntax to enclose
                  username, api keys or similar data in a strong tag) from `event.attributes.description`
                  property of the response object.</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_785_4f5">
<li class="li">Fixed a bug to make the `Note` field mandatory when suppressing or un-suppressing
                  a check the UI.</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_2c9_e8c">
<li class="li">Fixed a bug to allow the users to go back to the Project selection from the Confirmation
                  page when onboarding GCP projects.</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_aad_8f8">
<li class="li">Fixed a bug where users weren't receiving the 'Welcome' email after signing up.</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_f96_f85">
<li class="li">Fixed a bug to display a warning icon indicating the rule exception state for Tags
                  case insensitive, Tags case sensitive, and resource id filters in all 3 rule list
                  views (Account, Organisational profile and Custom Profile).</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_ef7_f2c">
<li class="li">Fixed a bug to increase the size limit of an Organisation Profile allowing you to
                  save and apply multiple rule configurations to many accounts.</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_d59_529">
<li class="li">Fixed a bug where the Profile API was timing out when a profile with multiple rule
                  configurations was applied to a large number of accounts.</li>
</ul><ul class="ul" id="whatsnew_297_89a_823__ul_ca4_424">
<li class="li">WS-005: WorkSpaces Storage Encryption: Fixed a bug for the rule to generate checks
                  for all Workspace checks on an AWS account instead of 25 workspaces.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.38. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_297_89a_823__ul_d5e_ddc">
<li class="li">MySQL-002 (Configure TLS Version for MySQL Flexible Database Servers): This rule ensures
                  that the `tls_version` parameter is set to a minimum of `TLSv1.2` for all MySQL flexible
                  database servers.</li>
</ul><div class="p">Rule Update</div><ul class="ul" id="whatsnew_297_89a_823__ul_e8e_36b">
<li class="li">CF-006: CloudFront Security Policy: Updated the rule to include the latest Security
                  policies.</li>
</ul>]]></description>
    <pubDate>Wed, 26 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-complian</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Deep Security Agent Windows Upgrade Requires Reboot to Prevent System Crashes</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-windows-upgrad</link>
    <description><![CDATA[<div class="p">October 27, 2022, Workload Security—After upgrading the Deep Security Agent package
               for Windows from version 20.0.0-5761 to 20.0.0-5810, a reboot is required to solve
               an issue causing systems to crash. This issue affects agents for all Windows platforms.</div><div class="p">For more information, including steps detailing an upgrade and reboot, please see
               <a class="xref" href="https://success.trendmicro.com/en-us/solution/ka-0013489" target="_blank">BSOD Encountered During Uninstall of Deep Security Agent 20.0.0-5761</a>.</div>]]></description>
    <pubDate>Thu, 27 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-windows-upgrad</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>View Summary of Disabled Cloud Accounts on Main Dashboard with Latest Conformity Update</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-view-summary-of-disabled-cloud-acc</link>
    <description><![CDATA[<div class="p">October 31, 2022, Conformity—The following features and updates are now available
               with Conformity's latest release on 31 October 2022.</div><ul class="ul" id="whatsnew_ade_bea_a2f__ul_7c0_3c6">
<li class="li">You can now view a summary of your cloud accounts with disabled Conformity Bot on
                  the Main Dashboard by clicking on the View Accounts button.</li>
</ul><div class="p">Bug Fix</div><ul class="ul" id="whatsnew_ade_bea_a2f__ul_57d_6f5">
<li class="li">Fixed a bug happening due to the updated AZ CLI Version, where the users weren't able
                  to generate the password for the created App Registration manually. We've updated
                  the script to generate the Password &amp; Client_secret_key automatically. Please ensure
                  that the AZ CLI version is higher than `2.40.0` for the new script to work.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.38. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div>]]></description>
    <pubDate>Mon, 31 Oct 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-view-summary-of-disabled-cloud-acc</guid>
    <category>Conformity</category>
</item>
<item>
    <title>GCP Scanner DLT Function Issue Resolved</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-scanner-dlt-function-issue-res</link>
    <description><![CDATA[<div class="p">November 01, 2022, File Storage Security—Fixed the issue that caused the GCP Scanner
               DLT function to fail.</div>]]></description>
    <pubDate>Tue, 01 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-scanner-dlt-function-issue-res</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity discontinues pre-release notices for faster rule deployment</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-discontinues-pre-releas</link>
    <description><![CDATA[<div class="p">November 03, 2022, Conformity—Discontinuing Rules Pre-Release Notice: The 48-hour
               pre-release notice to be discontinued with effect from 10 January 2023</div><div class="p">From 10 January 2023, Trend Micro Cloud OneTM - Conformity will no longer send a Pre-release
               Notice 48 hours prior to releasing new rules and rule updates. You will be receiving
               all the release updates including rules through a post deployment update on the What’s
               New page.</div><div class="p">Important: As a part of our new communication strategy, we will no longer be sending
               release emails effective 10th January 2023.  We highly recommend that you subscribe
               to the Trend Micro Cloud One TM Updates RSS Feed using an RSS Feed Reader to get notified
               about the latest releases and news for Conformity.</div><div class="p">Why?</div><ul class="ul" id="whatsnew_550_e54_c31__ul_b99_3d2">
<li class="li">This change is a part of Conformity’s strategy to deliver you new rules, features
                  and, fixes faster.</li>
<li class="li">In 2023, Conformity aims to deploy multiple times per week and we can only do this
                  if we remove the 48 hour pre-release rules notice and manual release emails.</li>
</ul><div class="p">Impact</div><div class="p">We acknowledge that some of you are under strict SLAs that require monitoring of new
               rules impacting your compliance scores.</div><ul class="ul" id="whatsnew_550_e54_c31__ul_bc3_d32">
<li class="li">If you’re affected by the release of new rules, we recommend configuring the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-new-rules-behaviour-" target="_blank">New Rules Behaviour</a> settings `Manually` so your compliance scores are not impacted by newly released
                  rules and you can enable them as required.</li>
</ul><ul class="ul" id="whatsnew_550_e54_c31__ul_9fd_d18">
<li class="li">If you have already configured the setting to automatically enable newly released
                  rules, no further action is required.</li>
</ul>]]></description>
    <pubDate>Thu, 03 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-discontinues-pre-releas</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Role-Based Access Control for Anti-Malware Common Objects</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-role-based-access-control</link>
    <description><![CDATA[<div class="p">November 04, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               now allows administrators to control which anti-malware related common objects each
               role can access. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-rbac" target="_blank">Manage role-based access control for common objects</a>.</div>]]></description>
    <pubDate>Fri, 04 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-role-based-access-control</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity Enhancements: Bug Fixes and Azure Storage Account Limit Update</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-bug-fixes</link>
    <description><![CDATA[<div class="p">November 07, 2022, Conformity—The following updates are now available with Conformity's
               latest release on 07 November 2022.</div><div class="p">Bug Fixes with Rule Updates</div><ul class="ul" id="whatsnew_69f_e04_ca6__ul_e1b_71c">
<li class="li">Fixed a bug to prevent Conformity from generating checks for the backup vault with
                  different types of protected item(s) for a number of Virtual Machine rules.</li>
</ul><ul class="ul" id="whatsnew_69f_e04_ca6__ul_39e_6be">
<li class="li">Fixed a bug to prevent the throttling of Azure Storage Accounts service due to numerous
                  storage accounts and blob containers by implementing a hard limit of 100 storage accounts.</li>
<li class="li">This implies that Conformity will now scan only the first 100 Azure storage accounts
                  with an unlimited number of blob containers for the rules listed below:</li>
<li class="li">StorageAccounts-006 - Disable Anonymous Access to Blob Containers</li>
<li class="li">StorageAccounts-012 - Enable Immutable Blob Storage</li>
<li class="li">StorageAccounts-016 - Check for Publicly Accessible Web Containers</li>
<li class="li">StorageAccounts-017 - Review Storage Accounts with Static Website Configuration</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.38. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div>]]></description>
    <pubDate>Mon, 07 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-bug-fixes</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Automatic Assignment of Trend Cloud One Rules on Rule Update</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automatic-assignment-of-trend-clou</link>
    <description><![CDATA[<div class="p">November 07, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               can now be set to automatically assign all core Trend Cloud One - Endpoint &amp; Workload
               Rules to your policy when a Rule Update occurs. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-getting-started-endpoint" target="_blank">Configure Trend Cloud One - Endpoint Security</a>.</div>]]></description>
    <pubDate>Mon, 07 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automatic-assignment-of-trend-clou</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Support for Mobile (MTP/PTP) Read Only protocol on Windows 11</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-mobile-mtpptp-read-onl</link>
    <description><![CDATA[<div class="p">November 07, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               now supports the Mobile (MTP/PTP) Read Only protocol of Device Control for Windows
               11. This requires Deep Security Agent version 20.0.0-5810 or later.</div>]]></description>
    <pubDate>Mon, 07 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-mobile-mtpptp-read-onl</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Limit introduced to prevent SNS service throttling for scanning AWS topics</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-limit-introduced-to-prevent-sns-se</link>
    <description><![CDATA[<div class="p">November 08, 2022, Conformity—Fixed an issue to prevent SNS service throttling by
               introducing a limit to scan upto 4000 AWS SNS topics for the following rules:</div><ul class="ul" id="whatsnew_962_d6e_f94__ul_6df_01f">
<li class="li">SNS-001 Topic Exposed</li>
<li class="li">SNS-002 Cross Account Access</li>
<li class="li">SNS-003 SNS Appropriate Subscribers</li>
<li class="li">SNS-004 Topic Accessible For Publishing</li>
<li class="li">SNS-005 Topic Accessible For Subscription</li>
<li class="li">SNS-006 Topic Encrypted</li>
<li class="li">SNS-007 Topic Encrypted With KMS Customer Master Keys</li>
</ul>]]></description>
    <pubDate>Tue, 08 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-limit-introduced-to-prevent-sns-se</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved Cloud Account Onboarding and Bug Fix in Conformity&#x27;s Latest Release</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-cloud-account-onboarding</link>
    <description><![CDATA[<div class="p">November 14, 2022, Conformity—The following updates are now available with Conformity's
               latest release on 14 November 2022.</div><ul class="ul" id="whatsnew_305_89f_aa5__ul_590_b33">
<li class="li">To improve Conformity Bot's reliability, cloud accounts onboarded to Conformity via
                  the Public API will be queued to run with in the next 10 minutes of the API call.</li>
</ul><div class="p">Bug Fix</div><ul class="ul" id="whatsnew_305_89f_aa5__ul_e8f_6a5">
<li class="li">Fixed the broken 'Add and Manage Users' link on the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Users" target="_blank">Public API</a> page linking to Cloud One help documentation.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.38. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div>]]></description>
    <pubDate>Mon, 14 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-cloud-account-onboarding</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Domain filtering now supported in Network Security deployments with hosted infrastructure</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-domain-filtering-now-supported-in</link>
    <description><![CDATA[<div class="p">November 16, 2022, Network Security—Domain filtering support: Domain filtering is
               now supported on deployments using Network Security with hosted infrastructure. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-Domain_Filtering-" target="_blank">Learn more</a> about domain filtering.</div>]]></description>
    <pubDate>Wed, 16 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-domain-filtering-now-supported-in</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Conformity Enhancements for AWS and Azure Compliance Standards</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-for-aws-an</link>
    <description><![CDATA[<div class="p">November 21, 2022, Conformity—The following features and updates are now available
               with Conformity's latest release on 21 November 2022.</div><ul class="ul" id="whatsnew_373_be4_59b__ul_55d_487">
<li class="li">The FISC Security Guidelines v9 compliance standard mapping now supports the latest
                  AWS and Azure rules released in Conformity.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_373_be4_59b__ul_66b_05e">
<li class="li">Enhanced the scanning of all AWS RDS Instances to reduce throttling.</li>
<li class="li">Fixed a bug where the note for 'number of checks included' indicated an incorrect
                  count while configuring a report for individual checks.</li>
<li class="li">Fixed a bug where the 'Account rule settings' notes were not being saved correctly
                  for the Custom Role Full Access Users.</li>
<li class="li">KMS-002:Key Rotation Enabled: Fixed a bug where checks were generated incorrectly
                  if the KMS key did not support key rotation.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.38. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">Rules</div><div class="p">Azure</div><div class="p">SecurityCenter-039: Enable Automatic Provisioning of Vulnerability Assessment for
               Virtual Machines: This rule advises users to manually check that automatic provisioning
               of vulnerability assessment solutions is `Enabled` for virtual machines.</div><div class="p">Rule Updates</div><div class="p">Fixed an issue with the following rules handling AWS regions with restricted permissions
               in Conformity:</div><ul class="ul" id="whatsnew_373_be4_59b__ul_063_96e">
<li class="li">EBS-010: EBS Volumes Attached to Stopped EC2 Instances</li>
</ul><ul class="ul" id="whatsnew_373_be4_59b__ul_877_81d">
<li class="li">VPC-016: VPC Endpoints in Use</li>
</ul><ul class="ul" id="whatsnew_373_be4_59b__ul_8dd_668">
<li class="li">S3-025: S3 Buckets Encrypted with Customer-Provided CMKs</li>
</ul><ul class="ul" id="whatsnew_373_be4_59b__ul_43a_2dd">
<li class="li">CT-003: Publicly Accessible CloudTrail Buckets</li>
</ul><ul class="ul" id="whatsnew_373_be4_59b__ul_33e_60a">
<li class="li">RDS-027: Instance Level Events Subscriptions</li>
</ul><ul class="ul" id="whatsnew_373_be4_59b__ul_4cd_6ef">
<li class="li">RDS-028: Security Groups Events Subscriptions</li>
</ul><ul class="ul" id="whatsnew_373_be4_59b__ul_fd9_d0a">
<li class="li">RDS-029: RDS Event Notifications</li>
</ul><ul class="ul" id="whatsnew_373_be4_59b__ul_948_556">
<li class="li">RDS-039: RDS Instance Not in Public Subnet</li>
</ul><div class="p">End of Life - Conformity Cost Optimization Feature</div><div class="p">*The Conformity Cost Optimization feature will reach end of life with the upcoming
               release on 21 November 2022. If you've missed our advance notice, please read through
               the details below.*</div><div class="p">Why are we doing this?</div><div class="p">The Cost Optimization feature used data from the deprecated AWS ‘Detailed Billing
               Report’. AWS strongly recommends that all customers move away from this report and
               migrate to the newer <a class="xref" href="https://docs.aws.amazon.com/cur/latest/userguide/detailed-billing-migrate.html" target="_blank">Cost and Usage Report</a>.</div><div class="p">We have decided to discontinue all support for Cost Analysis as our strategic focus
               as Trend Micro Cloud One ™ Conformity is on core Cloud Security Posture management
               (CSPM) features.</div><div class="p">What does it mean for you?</div><div class="p">No Cost Optimization widget - you will stop seeing the Cost Optimization widget on
               your Organizations’ Main Dashboard.</div><div class="p">What happens to the Cost Rules?</div><div class="p">All Cost category rules except for the following Rules will still be available to
               all customers. We’re deprecating these four Rules because their AWS data source is
               a deprecated AWS billing report.</div><ul class="ul" id="whatsnew_373_be4_59b__ul_6ae_f74">
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Budgets/budget-overrun.html" target="_blank">Budgets- 001: Budget Overrun</a></li>
</ul><ul class="ul" id="whatsnew_373_be4_59b__ul_eb3_b87">
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Budgets/cost-fluctuation.html" target="_blank">Budgets -002: Cost Fluctuation</a></li>
</ul><ul class="ul" id="whatsnew_373_be4_59b__ul_f70_925">
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Budgets/budget-overrun-forecast.html" target="_blank">Budgets-003: Budgets Overrun Forecast</a></li>
</ul><ul class="ul" id="whatsnew_373_be4_59b__ul_238_017">
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Budgets/cost-fluctuation-forecast.html" target="_blank">Budgets-004: Cost Fluctuation Forecast</a></li>
</ul><div class="p">What do I need to do?</div><div class="p">You don't need to do anything at your end. If you wish, you can turn off the AWS Billing
               report used by Conformity. If you have any concerns or queries regarding the end of
               life for the Cost Optimization feature, please reach out to your account managers.</div><div class="p">*The Cost Optimization feature is unavailable to our Trend Micro Cloud One ™ Conformity
               customers.*</div>]]></description>
    <pubDate>Mon, 21 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-for-aws-an</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Security and Resilience for Conformity Platform with Elasticsearch Upgrade</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-and-resilience-f</link>
    <description><![CDATA[<div class="p">November 24, 2022, Conformity—On 23 November 2022, we upgraded the Elasticsearch clusters
               to improve your experience with the Conformity platform, providing you with a more
               resilient and secure cloud infrastructure by applying the security best practices.</div>]]></description>
    <pubDate>Thu, 24 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-and-resilience-f</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Cloud One Central introduces preview release for enhanced application visibility</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloud-one-central-introduces-previ</link>
    <description><![CDATA[<div class="p">November 28, 2022, Cloud One Central—Cloud One Central is now in <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-sentry-" target="_blank">Preview</a> release. It helps you gain visibility across your applications. At launch, it lists
               your cloud workloads (EC2 instances), container image repositories (ECR), and serverless
               functions (Lambda functions), along with security findings grouped by cloud account.
               For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central--cloud-one-central-about-central-" target="_blank">About Cloud One Central</a>.</div>]]></description>
    <pubDate>Mon, 28 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloud-one-central-introduces-previ</guid>
    <category>Cloud One Central</category>
</item>
<item>
    <title>Cloud Sentry available in preview release deployment as serverless application</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloud-sentry-available-in-preview</link>
    <description><![CDATA[<div class="p">November 28, 2022, Cloud Sentry—Cloud Sentry is now available in <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-sentry-" target="_blank">Preview</a> release. It deploys as a serverless application in your cloud account to scan your
               resources for threats. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-sentry-about-sentry" target="_blank">About Cloud Sentry</a>.</div>]]></description>
    <pubDate>Mon, 28 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloud-sentry-available-in-preview</guid>
    <category>Cloud Sentry</category>
</item>
<item>
    <title>Windows agents can trigger manual scans for specific folders in Trend Cloud One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-windows-agents-can-trigger-manual</link>
    <description><![CDATA[<div class="p">November 28, 2022, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               now allows agents for Windows platforms to trigger a manual scan from the Trend Micro
               notifier application for specified folders only. This requires Deep Security Agent
               version 20.0.0-5995 or later.</div>]]></description>
    <pubDate>Mon, 28 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-windows-agents-can-trigger-manual</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity introduces Chinese character support, extended GCP regions, and bug fixes</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-chinese-char</link>
    <description><![CDATA[<div class="p">November 29, 2022, Conformity—The following features and updates are now available
               with Conformity's latest release on 29 November 2022.</div><ul class="ul" id="whatsnew_351_4b9_46a__ul_320_d5b">
<li class="li">Added a new <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Checks#paths-~1checks~1communication~1replay-post" target="_blank">Replay</a> endpoint to the Checks API allowing you to send checks history into newly created
                  Communication Channels. For details see: <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-communication-checks-rerun-" target="_blank">Re-run Historical Check Notifications</a>.</li>
</ul><ul class="ul" id="whatsnew_351_4b9_46a__ul_ae2_7b2">
<li class="li">You can now add Chinese characters in the Account Tags via the UI and the public API.</li>
</ul><ul class="ul" id="whatsnew_351_4b9_46a__ul_0fc_0c5">
<li class="li">GCP Conformity Bot now supports the following regions:</li>
<li class="li">asia-south2</li>
<li class="li">australia-southeast2</li>
<li class="li">europe-southwest1</li>
<li class="li">europe-west8</li>
<li class="li">europe-west9</li>
<li class="li">northamerica-northeast2</li>
<li class="li">us-east5</li>
<li class="li">us-south1</li>
<li class="li">southamerica-west1</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_351_4b9_46a__ul_b28_741">
<li class="li">Fixed a bug where the Real Time Threat Monitoring notifications were not being sent
                  when a check status changed from `Failure`, to `Success`, and then back to `Failure`
                  in quick succession.</li>
</ul><ul class="ul" id="whatsnew_351_4b9_46a__ul_68f_42e">
<li class="li">Fixed a bug where the Power Users and the Read Only users were able to view users'
                  activity on the Main Dashboard. User activities can only be viewed by a Full Access
                  user and a Custom Role user with appropriate permissions.</li>
</ul><ul class="ul" id="whatsnew_351_4b9_46a__ul_713_04c">
<li class="li">Fixed a bug where the Azure Real Time Monitoring install script failed to install
                  monitoring resources correctly.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.38. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_351_4b9_46a__ul_115_289">
<li class="li">SecurityCenter-040: Enable Automatic Provisioning of Microsoft Defender for Containers
                  Components [Not scored]: This rule recommends that automatic provisioning of security
                  components is enabled for Azure containers.</li>
</ul><ul class="ul" id="whatsnew_351_4b9_46a__ul_221_7e5">
<li class="li">StorageAccounts-022: Disable public access to storage accounts with blob containers:
                  This rule ensures that public access to blob containers is disabled for your Azure
                  storage accounts. The recommended setting overrides any alternative configurations
                  allowing public blob access.</li>
</ul><div class="p">GCP</div><ul class="ul" id="whatsnew_351_4b9_46a__ul_ce0_2d7">
<li class="li">GKE-002: Enable Encryption for Application-Layer Secrets for GKE Clusters: This rule
                  ensures that GKE Clusters have Application-Layer Secrets Encryption enabled.</li>
</ul><div class="p">Rule Updates</div><ul class="ul" id="whatsnew_351_4b9_46a__ul_e99_bae">
<li class="li">Updated the following AWS EC2 Non-Security-Group service level rules to fix an error-handling
                  issue and generate accurate checks for all regions.</li>
</ul><ul class="ul" id="whatsnew_351_4b9_46a__ul_9a1_a1b">
<li class="li">EC2-009: EC2-Classic Elastic IP Address Limit</li>
<li class="li">EC2-010: EC2-VPC Elastic IP Address Limit</li>
<li class="li">EC2-011: Account Instance Limit</li>
<li class="li">EC2-024: Unassociated Elastic IP Addresses</li>
<li class="li">EC2-026: Unused AMI</li>
<li class="li">EC2-056: Unused AWS EC2 Key Pairs</li>
<li class="li">EC2-072: EC2 Instance Not in Public Subnet</li>
<li class="li">EC2-078: EC2 Instances Scanned by Amazon Inspector Classic</li>
</ul>]]></description>
    <pubDate>Tue, 29 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-chinese-char</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Vulnerability View for Container Security Available</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-vulnerability-view-for-co</link>
    <description><![CDATA[<div class="p">November 29, 2022, Container Security—Vulnerability view is now available for Container
               Security, detailing any vulnerabilities found in open source code and operating system
               code running in your clusters. This feature allows you to search vulnerabilities by
               name and filter results by severity level or CVE score. For details on how vulnerability
               view integrates with runtime vulnerability scanning, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-runtime-scanning-" target="_blank">Configure runtime vulnerability scanning</a>.</div>]]></description>
    <pubDate>Tue, 29 Nov 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-vulnerability-view-for-co</guid>
    <category>Container Security</category>
</item>
<item>
    <title>New Azure rule, bug fixes, and rule updates in Conformity&#x27;s latest release</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-rule-bug-fixes-and-rule</link>
    <description><![CDATA[<div class="p">December 08, 2022, Conformity—The following features and updates are now available
               with Conformity's latest release on 08 December 2022.</div><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_ff6_3b1_824__ul_e19_e90">
<li class="li">Fixed a bug to prevent Azure RTM events from being created intermittently by improving
                  the logic of detecting duplicate events.</li>
</ul><ul class="ul" id="whatsnew_ff6_3b1_824__ul_bbc_f8c">
<li class="li">Fixed a bug with the Security Group rules scanning by ignoring them if the Ingress
                  or Egress rules cannot be extracted from the IaC template.</li>
</ul><ul class="ul" id="whatsnew_ff6_3b1_824__ul_767_0b9">
<li class="li">Fixed a bug to return the error response of `200 with {data: []}` instead of `403`
                  for service group API for an organisation without any account.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.38. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the current custom policy.</div><div class="p">New Rule</div><div class="p">Azure</div><div class="p">ActivityLog-029: Create Alert for "Delete Public IP Address" Events: This rule ensures
               that an Azure activity log alert is used to detect "Delete Public IP Address" events.</div><div class="p">Rule Updates</div><div class="p">Updated the following rules to fix an issue with their handling of AWS regions with
               restricted permissions for Conformity:</div><ul class="ul" id="whatsnew_ff6_3b1_824__ul_9f7_cc1">
<li class="li">IAM-060: Attach Policy to IAM Roles Associated with APP-Tier EC2</li>
</ul><ul class="ul" id="whatsnew_ff6_3b1_824__ul_c25_cb5">
<li class="li">IAM-064: Attach Policy to IAM Roles Associated with Web-Tier EC2</li>
</ul><ul class="ul" id="whatsnew_ff6_3b1_824__ul_316_d38">
<li class="li">ASG-004: Same Availability Zones in ASG and ELB</li>
</ul><ul class="ul" id="whatsnew_ff6_3b1_824__ul_d7b_398">
<li class="li">Inspector-001: Amazon Inspector Findings</li>
</ul><ul class="ul" id="whatsnew_ff6_3b1_824__ul_ed3_233">
<li class="li">Inspector-002: Days since last Amazon Inspector run</li>
</ul><ul class="ul" id="whatsnew_ff6_3b1_824__ul_529_7a5">
<li class="li">Inspector-003: Check for Amazon Inspector Exclusions</li>
</ul><div class="p">SQL-010: Check for Unrestricted SQL Database Access: Updated the rule to return a
               SUCCESS check when the ‘Deny public network access’ toggle is checked. The rule continues
               to ensure firewalls associated with your Microsoft Azure SQL servers are not configured
               to allow unrestricted inbound access.</div><div class="p">SQS-004 : Queue Server Side Encryption: Updated the rule to cover the latest SQS encryption
               options in AWS and prevent false negative checks</div>]]></description>
    <pubDate>Thu, 08 Dec 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-rule-bug-fixes-and-rule</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity Enhancements for AWS EventBridge Cross-Account IAM Role Changes</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-for-aws-ev</link>
    <description><![CDATA[<div class="p">December 08, 2022, Conformity—Impact of AWS EventBridge Cross-Account IAM Role Changes
               on Conformity</div><div class="p">The following features and updates are now available with Conformity's latest release
               on 08 December 2022.</div><div class="p">From 16 February 2023, all new AWS EventBridge Cross-account event bus targets will
               require an IAM role. This change will affect new Conformity Real Time Monitoring (RTM)
               EventBridge configurations but does not immediately affect the existing Conformity
               customers.</div><div class="p">What is the change?</div><div class="p">To increase security, AWS will soon require creating an IAM role for new Cross-account
               event bus targets. Consequently, Conformity will update the RTM installation process
               for new accounts to comply with the new requirement.</div><ul class="ul" id="whatsnew_527_a95_771__ul_b05_e51">
<li class="li">Fixed a bug to prevent Azure RTM events from being created intermittently by improving
                  the logic of detecting duplicate events.</li>
</ul><ul class="ul" id="whatsnew_527_a95_771__ul_b3c_98e">
<li class="li">Fixed a bug with the Security Group rules scanning by ignoring them if the Ingress
                  or Egress rules cannot be extracted from the IaC template.</li>
</ul><ul class="ul" id="whatsnew_527_a95_771__ul_cfa_576">
<li class="li">Fixed a bug to return the error response of `200 with {data: []}` instead of `403`
                  for service group API for an organisation without any account.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">User Impact</div><div class="p">AWS has confirmed that there will be no immediate impact on existing customers. If
               you are an existing Conformity customer using RTM, there is no deadline and you will
               be able to update your RTM resources after 16 February 2023 at your own pace.</div><div class="p">Resolution</div><div class="p">We are working on updating the authentication method and installation script for RTM.
               The new script will allow you to install or update RTM in your AWS accounts in line
               with the new IAM role requirements from AWS.</div>]]></description>
    <pubDate>Thu, 08 Dec 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-for-aws-ev</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Trend Micro Cloud One APAC Maintenance Completed, Services Coming Online Soon</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-cloud-one-apac-mainten</link>
    <description><![CDATA[<div class="p">December 10, 2022, General—System maintenance for Trend Micro Cloud One - Workload
               Security is complete for APAC regions. Affected Trend Micro Cloud One services will
               be online shortly. For more information or to be notified of scheduled maintenance,
               see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central-" target="_blank">Trend Micro Cloud One Maintenance</a>.</div>]]></description>
    <pubDate>Sat, 10 Dec 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-cloud-one-apac-mainten</guid>
    <category>General</category>
</item>
<item>
    <title>Sentry scanner log volume reduced in CloudWatch integration</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-sentry-scanner-log-volume-reduced</link>
    <description><![CDATA[<div class="p">December 15, 2022, Cloud Sentry—Fixed the issue that caused the Sentry scanner to
               write large amount of logs to CloudWatch.</div>]]></description>
    <pubDate>Thu, 15 Dec 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-sentry-scanner-log-volume-reduced</guid>
    <category>Cloud Sentry</category>
</item>
<item>
    <title>Enhanced AWS Security Rules and Custom Policies in Conformity&#x27;s Latest Update</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-security-rules-and-cu</link>
    <description><![CDATA[<div class="p">December 15, 2022, Conformity—The following rules and updates are now available with
               Conformity's latest release on 15 December 2022.</div><div class="p">Custom Policy Updates</div><div class="p">The custom policy has been updated as a result of the new deployment. The new custom
               policy version is 1.39 and the permission added is:</div><ul class="ul" id="whatsnew_f3f_45b_814__ul_689_530">
<li class="li">`securityhub:DescribeHub`</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div><div class="p">New Rule</div><div class="p">AWS</div><div class="p">SecurityHub-002: Security Hub Enabled: This rule ensures Amazon Security Hub service
               is enabled for your AWS accounts.</div><div class="p">Rule Updates</div><ul class="ul" id="whatsnew_f3f_45b_814__ul_88e_5cf">
<li class="li">Updated the following rules to improve error-handling and ensure that the checks are
                  only generated in regions with security groups:</li>
<li class="li">EC2-012: Security Group Excessive Counts</li>
<li class="li">EC2-013: Security Group Large Counts</li>
</ul><ul class="ul" id="whatsnew_f3f_45b_814__ul_b31_3d9">
<li class="li">SQS-005: SQS Encrypted With KMS Customer Master Keys: Updated the rule to return a
                  failure when the ‘Amazon SQS key (SSE-SQS)’ is selected as encryption key type. The
                  rule continues to ensure that your SQS queues are using KMS CMK customer-managed keys
                  instead of AWS managed-keys (i.e. default keys used in absence of defined customer
                  keys) to benefit from a more granular control over the queues data encryption/decryption
                  process.</li>
</ul><ul class="ul" id="whatsnew_f3f_45b_814__ul_0ae_809">
<li class="li">Monitor-006: Activity Log Storage Encryption with Customer-Managed Key: Updated the
                  rule to check storage container encryption for diagnostic settings in addition to
                  log profiles. The rule ensure that your Microsoft Azure activity log storage container
                  is encrypted with a Customer-Managed Key (CMK) to protect your activity log data at
                  rest with a key from your own Azure key vault.</li>
</ul><ul class="ul" id="whatsnew_f3f_45b_814__ul_2ef_32f">
<li class="li">Updated the following AWS service-level rules to fix an error-handling issue and generate
                  accurate checks when Conformity's permissions to certain AWS regions is restricted:</li>
</ul><ul class="ul" id="whatsnew_f3f_45b_814__ul_3a2_67a">
<li class="li">Lambda-005: Lambda Function With Admin Privileges</li>
<li class="li">Lambda-006: Using An IAM Role For More Than One Lambda Function</li>
<li class="li">SSM-003: Check for SSM Managed Instances</li>
<li class="li">EC2-002: Unrestricted SSH Access</li>
<li class="li">EC2-003: Unrestricted RDP Access</li>
<li class="li">EC2-004: Unrestricted Oracle Access</li>
<li class="li">EC2-005: Unrestricted MySQL Access</li>
<li class="li">EC2-006: Unrestricted PostgreSQL Access</li>
<li class="li">EC2-007: Unrestricted DNS Access</li>
<li class="li">EC2-008: Unrestricted MsSQL Access</li>
<li class="li">EC2-015: EC2 Instance Security Group Rules Counts</li>
<li class="li">EC2-038: Unrestricted Telnet Access</li>
<li class="li">EC2-039: Unrestricted SMTP Access</li>
<li class="li">EC2-040: Unrestricted RPC Access</li>
<li class="li">EC2-041: Unrestricted NetBIOS Access</li>
<li class="li">EC2-042: Unrestricted FTP Access</li>
<li class="li">EC2-043: Unrestricted CIFS Access</li>
<li class="li">EC2-045: Unrestricted MongoDB Access</li>
<li class="li">EC2-063: Unrestricted Elasticsearch Access</li>
<li class="li">EC2-064: Unrestricted HTTP Access</li>
<li class="li">EC2-065: Unrestricted HTTPS Access</li>
<li class="li">EC2-074: Check for Unrestricted Redis Access</li>
<li class="li">EC2-075: Check for Unrestricted Memcached Access</li>
</ul>]]></description>
    <pubDate>Thu, 15 Dec 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-security-rules-and-cu</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug Fixes and Custom Policy Status Update in Conformity&#x27;s Latest Release</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fixes-and-custom-policy-status</link>
    <description><![CDATA[<div class="p">December 20, 2022, Conformity—The following bug fixes are now available with Conformity's
               latest release on 20 December 2022.</div><ul class="ul" id="whatsnew_d20_bfd_1df__ul_d7d_a6a">
<li class="li">Fixed a bug to prevent Power User and Read Only from accessing all event activities
                  through public API.</li>
</ul><ul class="ul" id="whatsnew_d20_bfd_1df__ul_6cf_f14">
<li class="li">Fixed a bug with CQL to now validate the query length and also display an error message
                  for queries exceeding 5000 characters.</li>
</ul><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.39. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div>]]></description>
    <pubDate>Tue, 20 Dec 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fixes-and-custom-policy-status</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Advanced Threat Scan Engine now available for AWS, Azure, and GCP scanners</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-advanced-threat-scan-engine-now-av</link>
    <description><![CDATA[<div class="p">December 23, 2022, File Storage Security—The AWS, Azure, and GCP scanners with Advanced
               Threat Scan Engine (ATSE) 21.600.1005 are now available for use.</div>]]></description>
    <pubDate>Fri, 23 Dec 2022 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-advanced-threat-scan-engine-now-av</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>File Storage Security Enhances Deployment Capabilities with Terraform Support</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-enhances-dep</link>
    <description><![CDATA[<div class="p">January 09, 2023, File Storage Security—File Storage Security now supports deploying
               GCP stacks by using Terraform.</div>]]></description>
    <pubDate>Mon, 09 Jan 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-enhances-dep</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity Introduces New Azure and GCP Rules, Expanded GCP Region Support, and</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-azure-an</link>
    <description><![CDATA[<div class="p">January 12, 2023, Conformity—The following updates are now available with Conformity's
               latest release on 12 January 2023.</div><div class="p">Custom Policy Updates</div><div class="p">There is no change to the custom policy as a result of the new deployment. The current
               custom policy version is 1.39. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the current custom policy</a>.</div><div class="p">New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_adc_8ab_c12__ul_c1d_462">
<li class="li">Monitor-010: Enable Subscription Activity Log Diagnostic Settings: This rule ensures
                  that Azure Monitor Activity Logs for your subscription are exported to an appropriate
                  data store using diagnostic settings. This rule also replaces the rule: `Monitor-001
                  - Azure Activity Log Profile in Use` which will be deprecated soon.</li>
</ul><ul class="ul" id="whatsnew_adc_8ab_c12__ul_56e_5de">
<li class="li">ActivityLog-028: Create Alert for `Create or Update Public IP Address` Events: This
                  rule ensures that activity log alerts are created for the `Create or Update Public
                  IP Address` events.</li>
</ul><div class="p">GCP</div><ul class="ul" id="whatsnew_adc_8ab_c12__ul_987_7fc">
<li class="li">ResourceManager-003: Enforce Uniform Bucket-Level Access: This rule ensures that `Enforce
                  Uniform bucket-level access organization` policy is enabled at the Google Cloud Platform
                  (GCP) organization level, and that the project inherits the parent's policy.</li>
</ul><ul class="ul" id="whatsnew_adc_8ab_c12__ul_0db_d63">
<li class="li">ResourceManager-002: Disable Automatic IAM Role Grants for Default Service Accounts:
                  This rule ensures that `Disable Automatic IAM Grants for Default Service Accounts`
                  policy is enforced.</li>
</ul><ul class="ul" id="whatsnew_adc_8ab_c12__ul_291_fa6">
<li class="li">Dataproc-001: Enable Dataproc Cluster Encryption with Customer-Managed Keys: This
                  rule ensures that your Dataproc Clusters on Compute Engine are encrypted using Customer-Managed
                  Keys (CMKs).</li>
</ul><div class="p">Platform Updates</div><ul class="ul" id="whatsnew_adc_8ab_c12__ul_7b1_27d">
<li class="li">We've now empowered the Conformity Bot with the following 10 additional regions to
                  support GCP:</li>
<li class="li">eur4</li>
<li class="li">eur6</li>
<li class="li">nam4</li>
<li class="li">nam7</li>
<li class="li">nam8</li>
<li class="li">nam10</li>
<li class="li">nam11</li>
<li class="li">nam12</li>
<li class="li">nam13</li>
<li class="li">nam-eur-asia1</li>
</ul><ul class="ul" id="whatsnew_adc_8ab_c12__ul_ab2_cc4">
<li class="li">We've also improved our PDF report engine to generate reports with up to 5,000 checks.</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_adc_8ab_c12__ul_286_a75">
<li class="li">Fixed a bug where checks for CloudStorage Buckets resources returned incorrect region
                  value i.e. `global` for a region with hosted resources.</li>
</ul><ul class="ul" id="whatsnew_adc_8ab_c12__ul_b83_75d">
<li class="li">Fixed a bug where the Deprecated Rules were being enabled on clicking the 'Reset to
                  Default' button.</li>
</ul>]]></description>
    <pubDate>Thu, 12 Jan 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-new-azure-an</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Real-Time Monitoring now supports EventBridge Cross-Account IAM Role for enhanced security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-real-time-monitoring-now-suppo</link>
    <description><![CDATA[<div class="p">January 19, 2023, Conformity—The following update is available with Conformity's latest
               release on 19 January 2023.</div><div class="p">AWS Real-Time Monitoring installation now supports EventBridge Cross-Account IAM Role</div><div class="p">We have updated the AWS Real-Time Monitoring installation template to include an IAM
               role for cross-account access to increase security and adhere to the latest AWS EventBridge
               cross-account access requirements.</div><div class="p">For more information see the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-real-time-threat-monitoring-settings-" target="_blank">RTM Settings</a>. While there is no firm deadline from AWS, we recommended that you update your EventBridge
               configuration to follow the best practice.</div><div class="p">For more information about sending and receiving Amazon EventBridge events between
               AWS accounts, see the <a class="xref" href="https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-cross-account.html" target="_blank">AWS documentation</a>.</div>]]></description>
    <pubDate>Thu, 19 Jan 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-real-time-monitoring-now-suppo</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New AWS regions in Europe and Canada for Network Security deployment</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-regions-in-europe-and-cana</link>
    <description><![CDATA[<div class="p">January 27, 2023, Network Security—New regions available for deployment: You can now
               deploy Network Security with hosted infrastructure deployments in several new AWS
               regions in Europe and Canada. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-NSMS_review_environment-" target="_blank">View all supported regions</a>.</div>]]></description>
    <pubDate>Fri, 27 Jan 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-regions-in-europe-and-cana</guid>
    <category>Network Security</category>
</item>
<item>
    <title>New AWS CloudShell script for route changes in Network Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-cloudshell-script-for-rout</link>
    <description><![CDATA[<div class="p">January 27, 2023, Network Security—New deployment routing script: Network Security
               now provides a script that enables you to make route changes using AWS CloudShell
               for Network Security with hosted infrastructure deployments. This script provides
               step-by-step instructions to create the required route tables for hosted infrastructure
               deployments in your particular AWS environment. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-NSMS_modify_routes-#make-route-changes-using-a-script" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Fri, 27 Jan 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-cloudshell-script-for-rout</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Updated Compliance Standards and ISO 27001:2022 Support for Cloud Environments</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-compliance-standards-and-i</link>
    <description><![CDATA[<div class="p">January 31, 2023, Conformity—Updated Compliance Standards: CIS Foundations Benchmarks</div><div class="p">We've updated our compliance standards to meet the Center of Internet Security (CIS)
               Foundations Benchmarks for AWS, Azure and GCP. You can now filter Checks and download
               Compliance Reports to ensure your cloud environment complies with the latest CIS Foundations
               Benchmarks.</div><ul class="ul" id="whatsnew_bdb_8d5_0fb__ul_607_744">
<li class="li">CIS Amazon Web Services Foundations Benchmark, v1.5.0</li>
<li class="li">CIS Microsoft Azure Foundations Benchmark v1.5.0</li>
<li class="li">CIS Google Cloud Platform Foundation Benchmark v1.3.0</li>
</ul><div class="p">You can view the CIS certifications awarded to Trend Micro Cloud One - Conformity
               on the <a class="xref" href="https://www.cisecurity.org/partner/trend-micro" target="_blank">CIS partner website</a> and find out more about <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-compliance-and-conformity-" target="_blank">Compliance and Conformity</a> in our documentation.</div><div class="p">ISO 27001:2022 Support for AWS, Azure and GCP</div><div class="p">We now support ISO 27001:2022 across compliance features for AWS, Azure and GCP.</div><div class="p">Custom Policy Updates</div><div class="p">We've updated the custom policy to version - 1.40. The added permission is:</div><ul class="ul" id="whatsnew_bdb_8d5_0fb__ul_fef_35f">
<li class="li">`lambda:ListFunctionUrlConfigs`</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the new custom policy</a>.</div>]]></description>
    <pubDate>Tue, 31 Jan 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-compliance-standards-and-i</guid>
    <category>Conformity</category>
</item>
<item>
    <title>No Deadline for Switching to FQDNs for Trend Cloud One Access</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-no-deadline-for-switching-to-fqdns</link>
    <description><![CDATA[<div class="p">January 31, 2023, Workload Security—There is no longer a deadline to switch from Static
               Ips to FQDNs to access Trend Cloud One - Endpoint &amp; Workload Security. This means
               that Trend Cloud One - Endpoint &amp; Workload Security accounts created prior to November
               23, 2020 can continue to use their Deep Security Agents to access Trend Cloud One
               - Endpoint &amp; Workload Security by using the static IP addresses provided in <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-communication-ports-urls-ip-#Deep5" target="_blank">Port numbers, URLs, and IP addresses</a>.</div>]]></description>
    <pubDate>Tue, 31 Jan 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-no-deadline-for-switching-to-fqdns</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Windows Server Device Control now supported in Trend Cloud One - Endpoint &amp; Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-windows-server-device-control-now</link>
    <description><![CDATA[<div class="p">January 31, 2023, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security
               now supports the Windows Server platform for Device Control. This requires Deep Security
               Agent 20.0.0-6313 or later. See <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security-supported-features-by-platform" target="_blank">Supported features by platform
                  </a> for the supported list.</div>]]></description>
    <pubDate>Tue, 31 Jan 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-windows-server-device-control-now</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Resource Details and Links in Tags Rule</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-resource-details-and-link</link>
    <description><![CDATA[<div class="p">February 01, 2023, Conformity—Rule Update</div><ul class="ul" id="whatsnew_286_59d_748__ul_193_8a9">
<li class="li">Resources-001: Tags: Improved this rule to return more resource details in the check
                  including service and resource names and a link to the resource.</li>
</ul>]]></description>
    <pubDate>Wed, 01 Feb 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-resource-details-and-link</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Severity Update for RTM Configuration Change Rules to Improve Alert Fatigue</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-severity-update-for-rtm-configurat</link>
    <description><![CDATA[<div class="p">February 02, 2023, Conformity—Rule Update</div><ul class="ul" id="whatsnew_fb5_1e2_3a4__ul_22d_b5c">
<li class="li">Updated the Severity for the following RTM Configuration Change Rules from `HIGH`
                  to `LOW` to improve alert fatigue as these rules do not ideally represent a security
                  vulnerability. These rules are more of events prompting you to review your severity
                  and change it as required.</li>
</ul><div class="p">Azure</div><ul class="ul" id="whatsnew_fb5_1e2_3a4__ul_864_877">
<li class="li">Network-014: Monitor Network Security Group Configuration Changes</li>
</ul><div class="p">AWS</div><ul class="ul" id="whatsnew_fb5_1e2_3a4__ul_d14_10c">
<li class="li">Config-005: AWS Config Configuration Changes</li>
<li class="li">CT-013: AWS CloudTrail Configuration Changes</li>
<li class="li">ECS-001: Monitor Amazon ECS Configuration Changes</li>
<li class="li">GD-003: AWS GuardDuty Configuration Changes</li>
<li class="li">IAM-054: IAM Configuration Changes</li>
<li class="li">KMS-007: Monitor AWS KMS Configuration Changes</li>
<li class="li">Organizations-003: AWS Organizations Configuration Changes</li>
<li class="li">RDS-036: Amazon RDS Configuration Changes</li>
<li class="li">Route53-009: Amazon Route 53 Configuration Changes</li>
<li class="li">Route53Domains-001: Amazon Route 53 Domains Configuration Changes</li>
<li class="li">RTM-009: Network configuration change detected</li>
<li class="li">S3-022: S3 Configuration Changes</li>
<li class="li">SecurityHub-001: Detect AWS Security Hub Configuration Changes</li>
</ul>]]></description>
    <pubDate>Thu, 02 Feb 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-severity-update-for-rtm-configurat</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity Bot enhanced to scan large numbers of SNS resources efficiently</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-bot-enhanced-to-scan-la</link>
    <description><![CDATA[<div class="p">February 02, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_f36_a46_9f1__ul_2d2_dac">
<li class="li">Improved Conformity Bot to scan a large numbers of SNS resources and produce checks
                  successfully.</li>
</ul>]]></description>
    <pubDate>Thu, 02 Feb 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-bot-enhanced-to-scan-la</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved AWS Config rule for referencing missing S3 bucket enhances scanning and reduces false positives</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-config-rule-for-refer</link>
    <description><![CDATA[<div class="p">February 06, 2023, Conformity—Rule Update</div><ul class="ul" id="whatsnew_4cb_531_b52__ul_fea_ab5">
<li class="li">Config-002: AWS Config Referencing Missing S3 Bucket: Improved this rule to simplify
                  account scanning, improve reliability and reduce false positive checks.</li>
</ul>]]></description>
    <pubDate>Mon, 06 Feb 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-config-rule-for-refer</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved AWS Kinesis resource scanning for enhanced performance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-kinesis-resource-scan</link>
    <description><![CDATA[<div class="p">February 07, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_98d_b93_a02__ul_74b_129">
<li class="li">Improved the way Conformity scans AWS Kinesis resources to reduce API throttling and
                  improve performance.</li>
</ul>]]></description>
    <pubDate>Tue, 07 Feb 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-kinesis-resource-scan</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Three new runtime rules added to Container Security for enhanced threat detection</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-three-new-runtime-rules-added-to-c</link>
    <description><![CDATA[<div class="p">February 08, 2023, Container Security—Container Security has three new runtime rules.
               They are:</div><ul class="ul" id="whatsnew_fae_662_880__ul_c6a_fbf">
<li class="li">Detect file execution from the /dev/shm directory, a common tactic for threat actors
                  to stash their files. (T1059.004)Execution from /dev/shm.</li>
</ul><ul class="ul" id="whatsnew_fae_662_880__ul_2d5_eae">
<li class="li">Detect usage of find or grep trying to access AWS credentials. (T1552.001)Find AWS
                  Credentials.</li>
</ul><ul class="ul" id="whatsnew_fae_662_880__ul_66c_b20">
<li class="li">Detect attempts to inject code into a process using PTRACE. (T1055.008)PTRACE attached
                  to process.</li>
</ul><div class="p">You need to update your cluster's Runtime Rulesets in order to benefit from these
               new rules as per the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-runtime-security-#create-a-runtime-ruleset" target="_blank">documentation</a>.</div>]]></description>
    <pubDate>Wed, 08 Feb 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-three-new-runtime-rules-added-to-c</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Improved accuracy and account restriction in CloudTrail Bucket MFA Delete rule</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-accuracy-and-account-rest</link>
    <description><![CDATA[<div class="p">February 13, 2023, Conformity—Rule Update</div><ul class="ul" id="whatsnew_987_722_131__ul_586_302">
<li class="li">CT-004: CloudTrail Bucket MFA Delete Enabled: Updated the rule to improve check accuracy
                  and remove duplicate checks. This rule will no longer produce checks if the CloudTrail
                  S3 bucket is located in another account.</li>
</ul>]]></description>
    <pubDate>Mon, 13 Feb 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-accuracy-and-account-rest</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved accuracy and elimination of duplicate checks in CloudTrail S3 Bucket Logging</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-accuracy-and-elimination</link>
    <description><![CDATA[<div class="p">February 16, 2023, Conformity—Rule Update</div><ul class="ul" id="whatsnew_d94_121_7a6__ul_c7e_6ad">
<li class="li">CT-002: CloudTrail S3 Bucket Logging Enabled: Updated the rule to improve check accuracy
                  and remove duplicate checks. This rule will no longer produce checks if the CloudTrail
                  S3 bucket is located in another account.</li>
</ul>]]></description>
    <pubDate>Thu, 16 Feb 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-accuracy-and-elimination</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhancement: Improved Rule Management for Trend Cloud One - Endpoint &amp; Workload</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhancement-improved-rule-manageme</link>
    <description><![CDATA[<div class="p">February 20, 2023, Workload Security—A change has been made to the way core Trend
               Cloud One - Endpoint &amp; Workload rules are updated. Core Trend Cloud One - Endpoint
               &amp; Workload rules that were unassigned by users now remain unassigned after rule updates.</div>]]></description>
    <pubDate>Mon, 20 Feb 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhancement-improved-rule-manageme</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity now excludes TTL checks from compliance score calculation for accuracy</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-now-excludes-ttl-checks</link>
    <description><![CDATA[<ul class="ul" id="whatsnew_3b0_b1e_06f__ul_fad_f54">
<li class="li">Checks with Time to Live <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-rule-configuration-#time-to-live" target="_blank">(TTL)</a> attribute have now been excluded from the compliance score calculation to produce
                  more accurate percentage scores. This update will affect the scores displayed under:</li>
</ul><ul class="ul" id="whatsnew_3b0_b1e_06f__ul_9f7_8c2">
<li class="li">Conformity compliance status</li>
<li class="li">Compliance level comparison</li>
<li class="li">Compliance level evolution</li>
</ul><ul class="ul" id="whatsnew_3b0_b1e_06f__ul_379_f4e">
<li class="li">Updated the following Compliance Standards and Reports to include newly released rules:</li>
</ul><ul class="ul" id="whatsnew_3b0_b1e_06f__ul_718_384">
<li class="li">PCI DSS v3.2.1</li>
<li class="li">AWS Well-Architected Framework</li>
</ul>]]></description>
    <pubDate>Wed, 22 Feb 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-now-excludes-ttl-checks</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS S3 bucket and file name included in File Storage Security scan results topic</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-s3-bucket-and-file-name-includ</link>
    <description><![CDATA[<div class="p">February 22, 2023, File Storage Security—File Storage Security now supports AWS S3
               bucket and file name in the message of SNS scan result topic.</div>]]></description>
    <pubDate>Wed, 22 Feb 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-s3-bucket-and-file-name-includ</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Bug Fix: Event Rule now successfully creates CloudWatch Alarm without errors</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-event-rule-now-successfull</link>
    <description><![CDATA[<div class="p">February 27, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_947_4ac_419__ul_12b_d04">
<li class="li">Fixed a bug with "!Ref" on the Event Rule to create a CloudWatch Alarm successfully
                  without an error.</li>
</ul>]]></description>
    <pubDate>Mon, 27 Feb 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-event-rule-now-successfull</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity Template Scanner now supports additional AWS regions for CloudFormation templates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-template-scanner-now-su</link>
    <description><![CDATA[<div class="p">March 02, 2023, Conformity—Conformity Template Scanner API now supports scanning CloudFormation
               templates for additional AWS regions (`me-central-1`, `ap-south-2`, `ap-southeast-3`,
               `ap-southeast-4`, `eu-central-2`, `eu-south-2`, `us-gov-west-1`, `us-gov-east-1`).</div>]]></description>
    <pubDate>Thu, 02 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-template-scanner-now-su</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated resource links for Azure Console access in SecurityCenter rules</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-resource-links-for-azure-c</link>
    <description><![CDATA[<div class="p">March 03, 2023, Conformity—March 03, 2023 Updated the resource link for following
               rules to incorporate the new Azure functionality allowing users to access the resource
               directly on the Azure Console.</div><ul class="ul" id="whatsnew_978_b0a_349__ul_d79_8f5">
<li class="li">SecurityCenter-002</li>
<li class="li">SecurityCenter-003</li>
<li class="li">SecurityCenter-004</li>
<li class="li">SecurityCenter-005</li>
<li class="li">SecurityCenter-006</li>
<li class="li">SecurityCenter-007</li>
<li class="li">SecurityCenter-008</li>
<li class="li">SecurityCenter-009</li>
<li class="li">SecurityCenter-010</li>
<li class="li">SecurityCenter-011</li>
<li class="li">SecurityCenter-012</li>
<li class="li">SecurityCenter-013</li>
<li class="li">SecurityCenter-014</li>
<li class="li">SecurityCenter-015</li>
<li class="li">SecurityCenter-020</li>
<li class="li">SecurityCenter-021</li>
<li class="li">SecurityCenter-022</li>
<li class="li">SecurityCenter-023</li>
<li class="li">SecurityCenter-024</li>
<li class="li">SecurityCenter-025</li>
</ul>]]></description>
    <pubDate>Fri, 03 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-resource-links-for-azure-c</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug fix enables onboarding new Azure subscriptions via public APIs</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-enables-onboarding-new-azu</link>
    <description><![CDATA[<ul class="ul" id="whatsnew_495_507_695__ul_9d8_7f2">
<li class="li">Fixed a bug that prevented users from onboarding new Azure subscriptions via public
                  APIs.</li>
</ul>]]></description>
    <pubDate>Mon, 06 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-enables-onboarding-new-azu</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Administration User screen removed for Cloud One Users in Conformity Feature</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-administration-user-screen-removed</link>
    <description><![CDATA[<ul class="ul" id="whatsnew_523_5d5_580__ul_066_dc0">
<li class="li">Remove Administration User screen for Cloud One Users as Cloud One Users are managed
                  by Cloud One</li>
</ul>]]></description>
    <pubDate>Mon, 06 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-administration-user-screen-removed</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Cloud Sentry now available for General Availability</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloud-sentry-now-available-for-gen</link>
    <description><![CDATA[<div class="p">March 07, 2023, Cloud Sentry—We are pleased to announce the General Availability of
               Cloud Sentry. It deploys as a serverless application in your cloud account to scan
               your resources for threats. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-sentry-about-sentry" target="_blank">About Cloud Sentry</a>.</div>]]></description>
    <pubDate>Tue, 07 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloud-sentry-now-available-for-gen</guid>
    <category>Cloud Sentry</category>
</item>
<item>
    <title>Enhanced SQS-004 Rule Logic for Latest AWS Encryption Options</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-sqs-004-rule-logic-for-la</link>
    <description><![CDATA[<div class="p">March 09, 2023, Conformity—SQS-004 : Queue Server Side Encryption:</div><ul class="ul" id="whatsnew_aeb_b38_14e__ul_4be_d54">
<li class="li">Updated the rule logic to cover the latest SQS encryption options in AWS and prevent
                  false negative checks.</li>
</ul>]]></description>
    <pubDate>Thu, 09 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-sqs-004-rule-logic-for-la</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Azure Storage Accounts Default to Disallowing Public Blob Access</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-storage-accounts-default-to</link>
    <description><![CDATA[<div class="p">March 14, 2023, File Storage Security—For all Azure storage accounts created in the
               stacks, the `allowBlobPublicAccess` property is set to `false`.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Tue, 14 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-storage-accounts-default-to</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved EBS resource scanning and resolved logout bug in Cloud One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-ebs-resource-scanning-and</link>
    <description><![CDATA[<div class="p">March 15, 2023, Conformity—Enhanced the scanning of EBS resources to improve performance
               and reduce API throttling by updating the following Rules:</div><ul class="ul" id="whatsnew_ac3_a63_093__ul_635_741">
<li class="li">EBS-004: EBS Volume Recent Snapshots</li>
<li class="li">EBS-005: EBS Volumes Too Old Snapshots</li>
</ul><div class="p">Bug Fixes</div><ul class="ul" id="whatsnew_ac3_a63_093__ul_996_ba5">
<li class="li">Fixed a bug where users were being logged out of the Cloud One console while actively
                  working in Conformity.</li>
</ul>]]></description>
    <pubDate>Wed, 15 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-ebs-resource-scanning-and</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug Fix: Improved Template Scanner Results for S3 Bucket Keys Compliance Checks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-improved-template-scanner</link>
    <description><![CDATA[<div class="p">March 20, 2023, Conformity—Bug Fix</div><div class="p">S3-028: Enable S3 Bucket Keys:  Fixed a bug where the Template Scanner results displayed
               an error message `cannot read properties of undefined (reading 'filter')` on scanning
               the rule.</div><div class="p">Fixed a bug where the Template Scanner returned checks for the following rules on
               scanning a Cloud Formation template without the required number of `instances`:</div><ul class="ul" id="whatsnew_a87_a2c_a2a__ul_6c5_24a">
<li class="li">ELB-001: Unused Elastic Load Balancers</li>
<li class="li">ELB-010: ELB Minimum Number of EC2 Instances</li>
</ul>]]></description>
    <pubDate>Mon, 20 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-improved-template-scanner</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced support for AWS S3 and GCP Cloud Storage in scan results</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-support-for-aws-s3-and-gc</link>
    <description><![CDATA[<div class="p">March 22, 2023, File Storage Security—File Storage Security now supports AWS S3 object
               eTag and GCP Cloud Storage CRC32C in the message of the scan result.</div>]]></description>
    <pubDate>Wed, 22 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-support-for-aws-s3-and-gc</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Deep Security Agent 20.0.0-6658 for Linux and Unix Release with Oracle Linux</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-2000-6658-for</link>
    <description><![CDATA[<div class="p">March 22, 2023, Workload Security—Deep Security Agent 20.0.0-6658 for Linux and Unix
               has been released.</div><div class="p">This release includes:</div><ul class="ul" id="whatsnew_89a_7f0_7bf__ul_90f_466">
<li class="li">Oracle Linux 9 support, including FIPS mode and Secure Boot support.</li>
<li class="li">Logging system improvements to help debug customer issues.</li>
<li class="li">OS platform metadata for Web Reputation Service.</li>
<li class="li">Several resolved issues.</li>
</ul><div class="p">For detailed information on what's included in this version, see <a class="xref" href="https://help.deepsecurity.trendmicro.com/20_0/on-premise/release-notes-dsa.html" target="_blank">What's New in Deep Security Agent</a>.</div>]]></description>
    <pubDate>Wed, 22 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-2000-6658-for</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Changes to AWS IAM Scanning Require Updated Permissions and Custom Policy</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-changes-to-aws-iam-scanning-requir</link>
    <description><![CDATA[<div class="p">March 23, 2023, Conformity—Upcoming changes to AWS IAM Scanning</div><div class="p">We will soon change how Conformity scans AWS IAM resources. In preparation, you will
               need to update your Conformity Custom Policy and ensure you have the permission `iam:GetAccountAuthorizationDetails`.
               This permission was first added on 19 January 2022 as part of v1.35. If you are missing
               the permission, you may lose IAM checks.</div><div class="p">Reminder: Update Conformity AWS Custom Policy</div><div class="p">The latest Conformity Custom Policy is v1.40. <a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here to access the new custom policy</a>.</div><div class="p">Conformity requires up-to-date permissions to properly scan your AWS account. Please
               refer to our documentation on <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-aws-custom-policy-#keeping-your-aws-custom-policy-up-to-date" target="_blank">keeping your aws custom policy up to date</a>.</div><div class="p">To be notified of out of date permissions, you can also refer to the following rules:</div><ul class="ul" id="whatsnew_8c9_63e_f57__ul_448_cf0">
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/cloudconformity/custom-policy-version.html" target="_blank">CC-001: Conformity Custom Policy Version</a></li>
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/cloudconformity/insufficient-access-permissions.html" target="_blank">CC-003: Conformity Insufficient Access Permissions</a>.</li>
</ul>]]></description>
    <pubDate>Thu, 23 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-changes-to-aws-iam-scanning-requir</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Amazon SNS Integration UI Preview Release: Configure with Cloud One using API Endpoints</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-amazon-sns-integration-ui-preview</link>
    <description><![CDATA[<div class="p">March 27, 2023, Integrations—Amazon SNS Integration User Interface Preview Release:
               you can now <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-integrations-sns" target="_blank">configure Amazon SNS with Cloud One</a> using our API Endpoints in this <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-sentry-" target="_blank">Preview</a> release.</div>]]></description>
    <pubDate>Mon, 27 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-amazon-sns-integration-ui-preview</guid>
    <category>Integrations</category>
</item>
<item>
    <title>Fixed false positive checks for enabling system-assigned managed identities</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-false-positive-checks-for-en</link>
    <description><![CDATA[<div class="p">March 28, 2023, Conformity—Bug Fix</div><div class="p">VirtualMachines-015: Enable System-Assigned Managed Identities: Fixed a bug where
               the rule generated false positive checks while configuring both the system-assigned
               managed identities and user-assigned identities simultaneously.</div>]]></description>
    <pubDate>Tue, 28 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-false-positive-checks-for-en</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Network Security now integrated with Cloud One for simplified Cloud Account Management</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-network-security-now-integrated-wi</link>
    <description><![CDATA[<div class="p">March 29, 2023, Network Security—Create new Cloud One accounts: Network Security is
               now integrated with Cloud One Cloud Account Management, which allows you to use a
               single Cloud Account connection across the Cloud One platform. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-add_cloud_accounts_appliances-" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Wed, 29 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-network-security-now-integrated-wi</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Enhanced Event Count Accuracy in Dashboard Widgets and Reports</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-event-count-accuracy-in-d</link>
    <description><![CDATA[<div class="p">March 29, 2023, Workload Security—Improvements have been made to more accurately count
               security events that are used in dashboard widgets and reports. Duplicate events are
               no longer being counted and may result in event count total disparity after the upgrade.
               This is a staged release and may not be immediately available in your region.</div>]]></description>
    <pubDate>Wed, 29 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-event-count-accuracy-in-d</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved Deployment Stability with Existing Log Groups Fix</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-deployment-stability-with</link>
    <description><![CDATA[<div class="p">March 30, 2023, Cloud Sentry—Fixed the issue that deployment might fail if there are
               already some existing log groups created by Sentry.</div>]]></description>
    <pubDate>Thu, 30 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-deployment-stability-with</guid>
    <category>Cloud Sentry</category>
</item>
<item>
    <title>Updated AWS IAM Scanning Requires `iam:GetAccountAuthorizationDetails` Permission</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-iam-scanning-requires</link>
    <description><![CDATA[<div class="p">March 30, 2023, Conformity—Changes to AWS IAM Scanning</div><div class="p">We have changed how Conformity scans AWS IAM resources. Please ensure you have the
               permission `iam:GetAccountAuthorizationDetails`. This permission was first added on
               19 January 2022 as part of v1.35 of the AWS custom policy. The latest version of the
               AWS custom policy is v.1.40. If you are missing the permission, you may lose IAM checks.</div>]]></description>
    <pubDate>Thu, 30 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-iam-scanning-requires</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Scanner DLQ Function Fix for February-March 2023 Deployments</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-scanner-dlq-function-fix-for-f</link>
    <description><![CDATA[<div class="p">March 31, 2023, File Storage Security—Fixed the issue that caused the AWS Scanner
               DLQ function to fail. This issue only impacts scanner stacks deployed from February
               22, 2023 to March 31, 2023. It requires a manually-updated Lambda code to fix. For
               instructions on manually updating the Lambda code, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-component-update-aws-#manualupdatecode" target="_blank">Update AWS components</a></div>]]></description>
    <pubDate>Fri, 31 Mar 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-scanner-dlq-function-fix-for-f</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved Logo Upload and Organisation Details Management for Cloud One Users</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-logo-upload-and-organisat</link>
    <description><![CDATA[<div class="p">April 05, 2023, Conformity—Bug Fixes and Enhancements</div><ul class="ul" id="whatsnew_ca7_f72_e01__ul_a8e_c69">
<li class="li">Fixed a bug that prevented users from uploading their organisation logo.</li>
<li class="li">Removed Organisation Details from the Administration screen for Cloud One Users, as
                  these details are managed at the Cloud One level.</li>
</ul>]]></description>
    <pubDate>Wed, 05 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-logo-upload-and-organisat</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity introduces Custom Policy Update with new permission for AWS users</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-custom-polic</link>
    <description><![CDATA[<div class="p">April 11, 2023, Conformity—The following update is now available with Conformity's
               latest release on 11 April 2023.</div><div class="p">Custom Policy Update</div><div class="p">The Conformity AWS custom policy has been updated. The new custom policy version is
               1.41 and the permission added is:</div><ul class="ul" id="whatsnew_367_1c1_b31__ul_8ed_05c">
<li class="li">`rds:DescribeDBParameterGroups`</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Tue, 11 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-custom-polic</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Trend Cloud One integrates with AWS Security Hub for simplified findings publication</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-cloud-one-integrates-with-aw</link>
    <description><![CDATA[<div class="p">April 11, 2023, Integrations—Trend Cloud One is now available as an AWS Security Hub
               partner product integration.</div><div class="p">You can now more easily allow Trend Cloud One to publish findings to your specified
               AWS Security Hub by accepting findings inside the AWS console.</div><div class="p">For more information and instructions, <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-integrations-security-hub-" target="_blank">click here</a>.</div>]]></description>
    <pubDate>Tue, 11 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-cloud-one-integrates-with-aw</guid>
    <category>Integrations</category>
</item>
<item>
    <title>Enhanced Compliance Standards and New Rule for AWS Lambda Authentication</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-compliance-standards-and</link>
    <description><![CDATA[<div class="p">April 13, 2023, Conformity—The following compliance standards now support GCP and
               have been updated for AWS and Azure:</div><ul class="ul" id="whatsnew_0c7_e6f_e67__ul_892_3b6">
<li class="li">NIST Cyber Security Framework v1.1</li>
<li class="li">Update System and Organization Controls 2 (SOC 2)</li>
</ul><div class="p">New Rule</div><div class="p">AWS</div><div class="p">Lambda-010: Enable IAM Authentication for Lambda Function URLs: This rule ensures
               that your function URLs are secured with IAM authentication (AWS_IAM) allowing only
               authenticated IAM users and roles to invoke your Amazon Lambda functions via function
               URLs.</div>]]></description>
    <pubDate>Thu, 13 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-compliance-standards-and</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Minimum TLS 1.2 Requirement for Azure Functions and Service Buses in Azure Stacks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-minimum-tls-12-requirement-for-azu</link>
    <description><![CDATA[<div class="p">April 13, 2023, File Storage Security—TLS 1.2 is now the minimum version required
               for Azure functions and Azure service buses deployed in the Azure stacks.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Thu, 13 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-minimum-tls-12-requirement-for-azu</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>New AWS Lambda Rule: Function URL Security Check and Resource ID Exceptions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-lambda-rule-function-url-s</link>
    <description><![CDATA[<div class="p">April 14, 2023, Conformity—New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_8e4_796_e90__ul_477_d85">
<li class="li">Lambda-011: Lambda Function URL Not in Use: Check whether your Amazon Lambda functions
                  are configured with function URLs for HTTP(S) endpoints. A function URL creates a
                  direct HTTP(S) endpoint to your function and this may pose a security risk depending
                  on the security configuration and intention of the function.</li>
</ul><ul class="ul" id="whatsnew_8e4_796_e90__ul_183_981">
<li class="li">You can now configure a rule's setting to allow exceptions based on Resource IDs up
                  to 256 characters.</li>
</ul>]]></description>
    <pubDate>Fri, 14 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-lambda-rule-function-url-s</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced AWS Bucket Listener Lambda Generates Regional Presigned URLs</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-bucket-listener-lambd</link>
    <description><![CDATA[<div class="p">April 14, 2023, File Storage Security—The AWS Bucket Listener Lambda function now
               generates presigned URLs by regional S3 endpoint to prevent a URL temporary redirect
               when scanning a newly created scanning bucket. For more information, see <a class="xref" href="https://repost.aws/knowledge-center/s3-http-307-response" target="_blank">Why am I getting an HTTP 307 Temporary Redirect response from Amazon S3?</a></div>]]></description>
    <pubDate>Fri, 14 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-bucket-listener-lambd</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Bug Fix for Template Scanner bypassing Account settings for KMS Cross Account Access</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-template-scanner-bypas</link>
    <description><![CDATA[<div class="p">April 19, 2023, Conformity—Bug Fix</div><div class="p">KMS-006: KMS Cross Account Access: Fixed a bug where the Template Scanner bypassed
               the Account settings - Include as friendly AWS accounts &gt; All within this AWS Organization
               and All within this Conformity organization.</div>]]></description>
    <pubDate>Wed, 19 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-template-scanner-bypas</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug fix for Conformity Template Scanner handling default behaviors of parameter</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-conformity-template-sc</link>
    <description><![CDATA[<div class="p">April 19, 2023, Conformity—Bug Fix</div><div class="p">Fixed a bug to ensure that the Conformity Template Scanner can handle default behaviours
               of the parameter `SqsManagedSseEnabled` for the following rules:</div><ul class="ul" id="whatsnew_ea9_9f0_cbf__ul_e68_9bc">
<li class="li">SQS-004: Queue Unprocessed Messages</li>
</ul><ul class="ul" id="whatsnew_ea9_9f0_cbf__ul_ad5_458">
<li class="li">SQS-005: SQS Encrypted With KMS Customer Master Keys</li>
</ul>]]></description>
    <pubDate>Wed, 19 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-conformity-template-sc</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity deprecates multiple AWS and Azure rules for enhanced compliance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-deprecates-multiple-aws</link>
    <description><![CDATA[<div class="p">April 20, 2023, Conformity—Rule Deprecation Notice</div><div class="p">As of 20 April 2023, Conformity has deprecated the following rules:</div><div class="p">AWS</div><ul class="ul" id="whatsnew_eb3_b6f_74b__ul_6c8_1f3">
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/SageMaker/notebook-data-encrypted.html" target="_blank">Sagemaker-003: Notebook Data Encrypted</a></li>
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/IAM/master-and-manager-role.html" target="_blank">IAM-047: Master and Manager Roles</a></li>
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/EC2/security-group-rules-counts.html" target="_blank">EC2-014: Security Group Rules Count</a></li>
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/S3/bucket-default-encryption.html" target="_blank">S3-021: S3 Bucket Default Encryption</a></li>
</ul><div class="p">Azure</div><ul class="ul" id="whatsnew_eb3_b6f_74b__ul_4aa_ae0">
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/azure/Monitor/log-profiles-exist.html" target="_blank">Monitor-001: Azure Activity Log Profile in Use</a></li>
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/azure/Monitor/activity-log-retention.html" target="_blank">Monitor-002: Activity Log Retention</a></li>
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/azure/Monitor/activity-log-all-regions.html" target="_blank">Monitor-004: Activity Log All Regions</a></li>
</ul><div class="p">You can find summaries of the reasons we deprecated each rule via the knowledge base
               articles linked above.</div><div class="p"><a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-rules-#deprecated-rules" target="_blank">Click here</a> to learn more about rule deprecation.</div>]]></description>
    <pubDate>Thu, 20 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-deprecates-multiple-aws</guid>
    <category>Conformity</category>
</item>
<item>
    <title>File Storage Security expands AWS region support to Milan and Bahrain</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-expands-aws</link>
    <description><![CDATA[<div class="p">April 20, 2023, File Storage Security—File Storage Security now supports Milan (eu-south-1)
               and Bahrain (me-south-1) regions on AWS. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-supported-aws-#AWSRegion" target="_blank">What's supported in AWS</a>.</div>]]></description>
    <pubDate>Thu, 20 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-expands-aws</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Fixed bug causing users to be logged out of Conformity console while working</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-bug-causing-users-to-be-logg</link>
    <description><![CDATA[<div class="p">April 21, 2023, Conformity—Bug Fixes</div><ul class="ul" id="whatsnew_5f8_00c_f22__ul_2a1_df3">
<li class="li">Fixed a bug where users were being logged out of the Cloud One console while actively
                  working in Conformity.</li>
</ul>]]></description>
    <pubDate>Fri, 21 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-bug-causing-users-to-be-logg</guid>
    <category>Conformity</category>
</item>
<item>
    <title>File Storage Security now supports Cloud Functions and GCP stack updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-supportGCP</link>
    <description><![CDATA[<div class="p">April 25, 2023, File Storage Security—Fixed the issue that caused File Storage Security
               to fail to update Cloud Functions, scanner license, and patterns in GCP stacks. If
               you are deploying File Storage Security via GCP (Deployment Manager), run the following
               commands in the Cloud Shell of the GCP console:</div><pre class="codeblock" id="whatsnew_c25_dc3_159__codeblock_qyb_ksh_pfc">```
gcloud iam roles update trend-micro-fss-service-account-management-role --project=&lt;PROJECT_ID&gt; --add-permissions=iam.serviceAccounts.actAs
```
```
gcloud iam service-accounts add-iam-policy-binding &lt;BUCKET_LISTENER_SERVICE_ACCOUNT&gt;@&lt;STORAGE_STACK_PROJECT_ID&gt;.iam.gserviceaccount.com --member="serviceAccount:&lt;MANAGEMENT_SERVICE_ACCOUNT_ID&gt;@&lt;MANAGEMENT_SERVICE_ACCOUNT_PROJECT_ID&gt;.iam.gserviceaccount.com" --role="projects/
PROJECT_ID&gt;/roles/trend_micro_fss_service_account_management_role"
```
```
gcloud iam service-accounts add-iam-policy-binding &lt;POST_SCAN_ACTION_TAG_SERVICE_ACCOUNT&gt;@&lt;STORAGE_STACK_PROJECT_ID&gt;.iam.gserviceaccount.com --member="serviceAccount:&lt;MANAGEMENT_SERVICE_ACCOUNT_ID&gt;@&lt;MANAGEMENT_SERVICE_ACCOUNT_PROJECT_ID&gt;.iam.gserviceaccount.com" --role="projects/&lt;PROJECT_ID&gt;/roles/trend_micro_fss_service_account_management_role"
```</pre><div class="p">If you are deploying File Storage Security via GCP (Terraform), this requires a stack
               update.</div>]]></description>
    <pubDate>Tue, 25 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-supportGCP</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced Security with Azure VNet Integration</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-with-azure-vnet</link>
    <description><![CDATA[<div class="p">April 27, 2023, File Storage Security—Azure VNet integration is now available for
               enhanced security and network isolation, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-azure-vnet-deployment" target="_blank">Deploy in Azure VNet</a>.</div>]]></description>
    <pubDate>Thu, 27 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-with-azure-vnet</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Bug Fix for Exception Support in Rules RDS-023 and RDS-040</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-exception-support-in-r</link>
    <description><![CDATA[<div class="p">April 28, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_8d3_eed_b0a__ul_592_ed7">
<li class="li">Fixed a bug to support exceptions via tags while generating checks for the following
                  Rules:</li>
</ul><ul class="ul" id="whatsnew_8d3_eed_b0a__ul_bf3_eab">
<li class="li">RDS-023: Amazon RDS Public Snapshots</li>
</ul><ul class="ul" id="whatsnew_8d3_eed_b0a__ul_19f_2a4">
<li class="li">RDS-040: Enable RDS Snapshot Encryption</li>
</ul>]]></description>
    <pubDate>Fri, 28 Apr 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-exception-support-in-r</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Event Filtering now available in preview release</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-event-filtering-now-available-in-p</link>
    <description><![CDATA[<div class="p">May 01, 2023, Integrations—Event Filtering Preview Release: You can now configure
               Event Filters when creating a new integration or updating an existing integration
               in Trend Cloud One using the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-integrations-api-reference-tag-Outbound-Integrations-" target="_blank">API endpoints</a>.</div>]]></description>
    <pubDate>Mon, 01 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-event-filtering-now-available-in-p</guid>
    <category>Integrations</category>
</item>
<item>
    <title>Proxy Auto-Configuration (PAC) support added to Trend Cloud One - Endpoint &amp; Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-proxy-auto-configuration-pac-suppo</link>
    <description><![CDATA[<div class="p">May 01, 2023, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security now
               supports adding Proxy Auto-Configuration (PAC) for the proxy server. This requires
               Deep Security Agent 20.0.0.6860 or later. </div><div class="p">For information on how to add a PAC proxy, see the "Connect to Workload Security and
               Relays via Proxy Auto_Configuration (PAC) proxy" section in <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security-proxy-set-up" target="_blank">Configure proxies</a>.</div><div class="p">This is supported on Windows and macOS.</div>]]></description>
    <pubDate>Mon, 01 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-proxy-auto-configuration-pac-suppo</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Updated rule logic for Storage Account access permissions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-logic-for-storage-acc</link>
    <description><![CDATA[<div class="p">May 02, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_3e4_3dd_939__ul_bc1_23d">
<li class="li">StorageAccounts-008: Enable Trusted Microsoft Services for Storage Account Access:
                  Updated the rule logic to ensure accurate checks.</li>
</ul>]]></description>
    <pubDate>Tue, 02 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-logic-for-storage-acc</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New LTS update for Deep Security Agent on Red Hat Enterprise Linux Workstation 7</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-lts-update-for-deep-security-a</link>
    <description><![CDATA[<div class="p">May 02, 2023, Workload Security—Deep Security Agent 20.0.0-6912 (20 LTS Update 2023-05-02)
               is available for Red Hat Enterprise Linux Workstation 7.</div>]]></description>
    <pubDate>Tue, 02 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-lts-update-for-deep-security-a</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Deep Security Agent 20.0.0-6912 now supports AlmaLinux 9</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-2000-6912-now</link>
    <description><![CDATA[<div class="p">May 02, 2023, Workload Security—Deep Security Agent 20.0.0-6912 (20 LTS Update 2023-05-02)
               is available for AlmaLinux 9.</div>]]></description>
    <pubDate>Tue, 02 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-2000-6912-now</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>New API Endpoints for Custom Access Control Roles Introduced</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-api-endpoints-for-custom-acces</link>
    <description><![CDATA[<div class="p">May 04, 2023, Conformity—Introducing New API Endpoints for Access Control (Conformity
               Custom Roles:)</div><ul class="ul" id="whatsnew_170_777_b1f__ul_d19_71a">
<li class="li">Create a role: `POST /access-control/roles/`</li>
<li class="li">Update a role: `PATCH /access-control/roles/{roleId}`</li>
<li class="li">List all roles: `GET /access-control/roles`</li>
<li class="li">Describe a role: `PATCH /access-control/roles/{roleId}`</li>
</ul>]]></description>
    <pubDate>Thu, 04 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-api-endpoints-for-custom-acces</guid>
    <category>Conformity</category>
</item>
<item>
    <title>RBAC Enabled for Kubernetes Cluster with Fixed Bug AKS-001</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rbac-enabled-for-kubernetes-cluste</link>
    <description><![CDATA[<div class="p">May 04, 2023, Conformity—Bug Fix</div><div class="p">AKS-001: Enable Kubernetes Role-Based Access Control: Fixed a bug where the rule generated
               failure checks for a cluster with RBAC enabled.</div>]]></description>
    <pubDate>Thu, 04 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rbac-enabled-for-kubernetes-cluste</guid>
    <category>Conformity</category>
</item>
<item>
    <title>GCP Bucket listener now supports objectFilterPrefix for enhanced file storage security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-bucket-listener-now-supports-o</link>
    <description><![CDATA[<div class="p">May 04, 2023, File Storage Security—The GCP Bucket listener now support `objectFilterPrefix`.
               For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-stack-add-gcp" target="_blank">Add GCP stack</a>.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Thu, 04 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-bucket-listener-now-supports-o</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced Azure Advisor Recommendations Integration for Improved Functionality</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azure-advisor-recommendat</link>
    <description><![CDATA[<div class="p">May 08, 2023, Conformity—Rule Update</div><div class="p">Advisor-001: Check for Azure Advisor Recommendations: Updated the scanning and display
               of Azure Advisor Findings to accurately reflect the latest functionality in the Azure
               Advisor service.</div>]]></description>
    <pubDate>Mon, 08 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azure-advisor-recommendat</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved CSV Report Tag Handling with New TagObjects Column</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-csv-report-tag-handling-w</link>
    <description><![CDATA[<div class="p">May 08, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_7c9_7e3_4ff__ul_490_84a">
<li class="li">Fixed a bug where the `Tags` column in the CSV report replaced `::` with `=`. In addition,
                  we have introduced a new column i.e. `TagObjects` to avoid any ambiguity of Key Value
                  pairs in the `Tags` column.</li>
</ul>]]></description>
    <pubDate>Mon, 08 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-csv-report-tag-handling-w</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Access Control API validation for Cloud One Admin users</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-access-control-api-valida</link>
    <description><![CDATA[<div class="p">May 09, 2023, Conformity—We've improved the access validation for following Access
               Control Public APIs to be called by Cloud One Admin users only:</div><ul class="ul" id="whatsnew_16b_7be_fe3__ul_47c_392">
<li class="li"><a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Access-Control#paths-~1access-control~1roles-post" target="_blank">Create a Role</a></li>
<li class="li"><a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Access-Control#paths-~1access-control~1roles~1%7Bid%7D-patch" target="_blank">Update a Role</a></li>
<li class="li"><a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Access-Control#paths-~1access-control~1roles-get" target="_blank">Get all Roles</a></li>
<li class="li"><a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Access-Control#paths-~1access-control~1roles~1%7Bid%7D-get" target="_blank">Describe a Role</a></li>
</ul>]]></description>
    <pubDate>Tue, 09 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-access-control-api-valida</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Real-Time Threat Monitoring now available for Google Cloud Platform (GCP)</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-real-time-threat-monitoring-now-av</link>
    <description><![CDATA[<div class="p">May 09, 2023, Conformity—RTM for Google Cloud Platform (GCP)</div><div class="p">You can now set up Real-Time Threat Monitoring and monitor events on your Google Cloud
               Platform (GCP) accounts in Trend Cloud One - Conformity. For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-real-time-threat-monitoring-settings-#rtm-for-gcp" target="_blank">Real-time Monitoring Settings</a>.</div><div class="p"> </div>]]></description>
    <pubDate>Tue, 09 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-real-time-threat-monitoring-now-av</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Azure Scanner Performance and Fixed Timeout Issue</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azure-scanner-performance</link>
    <description><![CDATA[<div class="p">May 09, 2023, File Storage Security—Fixed the timeout issue when the Azure scanner
               function scaled out instances during a large scan and enhanced the performance of
               the Azure scanner.</div>]]></description>
    <pubDate>Tue, 09 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azure-scanner-performance</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved Template Scanner now remediates resources for specific naming conventions and tags</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-template-scanner-now-reme</link>
    <description><![CDATA[<div class="p">May 10, 2023, Conformity—Bug Fix</div><div class="p">Updated the Template Scanner where several resources were not being remediated for
               the following rules:</div><ul class="ul" id="whatsnew_e20_2f7_869__ul_086_c1e">
<li class="li">RG-001: Tags</li>
<li class="li">EBS-006: EBS Volume Naming Conventions</li>
<li class="li">EC2-035: EC2 Instance Naming Conventions</li>
<li class="li">EC2-036: Security Group Naming Conventions</li>
</ul>]]></description>
    <pubDate>Wed, 10 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-template-scanner-now-reme</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New API Endpoint for Deleting Custom Roles in Access Control</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-api-endpoint-for-deleting-cust</link>
    <description><![CDATA[<div class="p">May 10, 2023, Conformity—Introducing A new API Endpoint for Access Control (Conformity
               Custom Roles:)</div><ul class="ul" id="whatsnew_928_dde_f82__ul_192_477">
<li class="li">Delete a role: `DELETE /access-control/roles/{roleId}`</li>
</ul>]]></description>
    <pubDate>Wed, 10 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-api-endpoint-for-deleting-cust</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated SecurityCenter rule for Microsoft Defender for Cloud recommendations</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-securitycenter-rule-for-mi</link>
    <description><![CDATA[<div class="p">May 10, 2023, Conformity—Rule Update</div><div class="p">SecurityCenter-020 : Microsoft Defender for Cloud Recommendations:</div><ul class="ul" id="whatsnew_85a_252_445__ul_c42_ce5">
<li class="li">Updated the rule logic to reflect the latest Assessments in Microsoft Defender for
                  Cloud.</li>
</ul>]]></description>
    <pubDate>Wed, 10 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-securitycenter-rule-for-mi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug fixes for accurate GCP Cloud Logging rule checks added</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fixes-for-accurate-gcp-cloud-l</link>
    <description><![CDATA[<div class="p">May 10, 2023, Conformity—Bug Fixes</div><div class="p">Fixed a bug to produce accurate checks for the following GCP Cloud Logging rules:</div><ul class="ul" id="whatsnew_a84_1f7_71d__ul_bbc_9c0">
<li class="li">CloudLogging-001: Enable Monitoring for Bucket Permission Changes</li>
<li class="li">CloudLogging-002: Enable VPC Network Route Changes Monitoring</li>
<li class="li">CloudLogging-003: Enable VPC Network Changes Monitoring</li>
<li class="li">CloudLogging-004: Enable Monitoring for Custom Role Changes</li>
<li class="li">CloudLogging-007: Enable Monitoring for Audit Configuration Changes</li>
</ul>]]></description>
    <pubDate>Wed, 10 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fixes-for-accurate-gcp-cloud-l</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated Rule to Monitor Public Access to Azure Diagnostic Logs</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-to-monitor-public-acc</link>
    <description><![CDATA[<div class="p">May 12, 2023, Conformity—Rule Update</div><div class="p">Monitor-005 : Check for Publicly Accessible Activity Log Storage Container:</div><ul class="ul" id="whatsnew_c84_b96_69e__ul_5ac_d0d">
<li class="li">Updated the rule to support Azure diagnostic settings. Diagnostic settings are the
                  preferred way to capture Azure Monitor logs and it's recommended to ensure the target
                  storage container for diagnostic settings logs is not publicly accessible.</li>
</ul>]]></description>
    <pubDate>Fri, 12 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-to-monitor-public-acc</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Scanner Stack Scaling Issue Resolved for Private Network Deployments</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanner-stack-scaling-issue-resolv</link>
    <description><![CDATA[<div class="p">May 12, 2023, File Storage Security—Fixed an issue where the Scanner Stack function
               application could not be scaled out when deploying your Azure stacks into a private
               network using VNet integration.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Fri, 12 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanner-stack-scaling-issue-resolv</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>SNI Support for TLS Inspection with Up to 30 Certificates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-sni-support-for-tls-inspection-wit</link>
    <description><![CDATA[<div class="p">May 12, 2023, Network Security—SNI support for TLS: You can now use SNI to support
               up to 30 certificates for TLS inspection in AWS. Enable using the API. Appliance version
               number of 2023.4.0.12159 or higher is required. <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-network-security--network-security-api-reference-tag-TLS-Inspection-Configuration" target="_blank">Learn more</a>.</div>]]></description>
    <pubDate>Fri, 12 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-sni-support-for-tls-inspection-wit</guid>
    <category>Network Security</category>
</item>
<item>
    <title>Fixed bug enabling/disabling AWS GovCloud in Conformity Bot settings</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-bug-enablingdisabling-aws-go</link>
    <description><![CDATA[<div class="p">May 15, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_329_d23_8b2__ul_baf_2a0">
<li class="li">Fixed a bug where AWS GovCloud could not be enabled or disabled in the Conformity
                  Bot settings.</li>
</ul>]]></description>
    <pubDate>Mon, 15 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-bug-enablingdisabling-aws-go</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug Fix: Improved Accuracy in AWS IAM Access Key Rotation Checks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-improved-accuracy-in-aws-i</link>
    <description><![CDATA[<div class="p">May 18, 2023, Conformity—Bug Fix</div><div class="p">Fixed a bug to produce accurate checks for the following AWS IAM rules:</div><ul class="ul" id="whatsnew_2ae_76e_3a0__ul_0dc_7cb">
<li class="li">IAM-001: Access Keys Rotated 30 Days</li>
<li class="li">IAM-002: Access Keys Rotated 45 Days</li>
<li class="li">IAM-038: Access Keys Rotated 90 Days</li>
</ul>]]></description>
    <pubDate>Thu, 18 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-improved-accuracy-in-aws-i</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced scan customization options for directories, files, and extensions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-scan-customization-option</link>
    <description><![CDATA[<div class="p">May 18, 2023, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security enables
               adding multiple scan directory lists, scan file lists, and scan file extension lists
               (Computer or Policy &gt; Details &gt; Anti-Malware &gt; Inclusions or Policy &gt; Details &gt; Anti-Malware
               &gt; Exclusions).</div>]]></description>
    <pubDate>Thu, 18 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-scan-customization-option</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Azure scanners now successfully scan files after license verification fix</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-scanners-now-successfully-sc</link>
    <description><![CDATA[<div class="p">May 19, 2023, File Storage Security—Fixed an issue where some Azure scanners could
               not scan files and sent scan results containing "failed to verify license" in the
               error message.</div>]]></description>
    <pubDate>Fri, 19 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-scanners-now-successfully-sc</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Osaka region now supports S3 object lambda for file scanning</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-osaka-region-now-supports-s3-objec</link>
    <description><![CDATA[<div class="p">May 19, 2023, File Storage Security—Osaka region now supports S3 object lambda to
               scan files. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-scan-existing-file-" target="_blank">Scan existing files in the S3 bucket to scan</a>.</div>]]></description>
    <pubDate>Fri, 19 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-osaka-region-now-supports-s3-objec</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Rule EC2-033 now supports allowlist for unconfigurable Security Groups</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-ec2-033-now-supports-allowlis</link>
    <description><![CDATA[<div class="p">May 22, 2023, Conformity—Rule Update</div><div class="p">EC2-033 : Unrestricted Outbound Access:</div><ul class="ul" id="whatsnew_cab_53e_f3b__ul_87d_06d">
<li class="li">Updated the rule to support an allowlist for the unconfigurable Security Groups.</li>
</ul>]]></description>
    <pubDate>Mon, 22 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-ec2-033-now-supports-allowlis</guid>
    <category>Conformity</category>
</item>
<item>
    <title>ServiceNow Integration now allows setup without delete permissions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-servicenow-integration-now-allows</link>
    <description><![CDATA[<ul class="ul" id="whatsnew_ea3_13f_9a0__ul_473_ee0">
<li class="li">Servicenow Integration Update: We've updated the settings to allow users to set up
                  a ServiceNow integration without delete permissions.</li>
</ul>]]></description>
    <pubDate>Tue, 23 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-servicenow-integration-now-allows</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Open Source Vulnerability Scans Integrated with Trend Micro Artifact Scanner (TMAS) CLI</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-open-source-vulnerability-scans-in</link>
    <description><![CDATA[<div class="p">May 23, 2023, Container Security—Open source vulnerability scans can now be performed
               using Trend Micro's managed <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-tmas-about-" target="_blank">Trend Micro Artifact Scanner (TMAS) CLI</a>. The TMAS CLI can be easily integrated into your continuous integration (CI) or continuous
               delivery (CD) pipelines. This managed service allows you to scan your container images
               for open source vulnerabilities before their deployment. The scan results are automatically
               integrated into Container Security, allowing you to define admission control policies
               that enforce requirements based on the vulnerabilities found in your images.</div>]]></description>
    <pubDate>Tue, 23 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-open-source-vulnerability-scans-in</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Bug fix for accurate AWS IAM rule checks for Credentials Last Used</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-accurate-aws-iam-rule</link>
    <description><![CDATA[<div class="p">May 29, 2023, Conformity—Bug Fix</div><div class="p">Fixed a bug to produce accurate checks for the following AWS IAM rules:</div><ul class="ul" id="whatsnew_914_b03_52a__ul_25a_767">
<li class="li">IAM-003: Credentials Last Used</li>
</ul>]]></description>
    <pubDate>Mon, 29 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-accurate-aws-iam-rule</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced AWS Resource and Rule Support in Template Scanner Github App</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-resource-and-rule-sup</link>
    <description><![CDATA[<div class="p">May 29, 2023, Conformity—Trend Cloud One™ - Template Scanner Github app</div><div class="p">* Cloudformation Templates *</div><div class="p">We have increased support to 35 AWS resource types scanned (previously 8 supported),
               and increased rules coverage to  over 250 rules ( previously 45 were supported).</div><div class="p">* Terraform *</div><div class="p">We have increased rules coverage to over 85 rules ( previously 45 were supported).</div><div class="p">For more information, please refer to <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-template-scanner-github-app-#supported-infrastructure-as-code" target="_blank">the documentation</a>.</div>]]></description>
    <pubDate>Mon, 29 May 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-resource-and-rule-sup</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug fix for S3 Object Lock template scanner returning incorrect checks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-s3-object-lock-templat</link>
    <description><![CDATA[<div class="p">June 05, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_e9f_29c_415__ul_79c_8fe">
<li class="li">S3-023: S3 Object Lock: Fixed a bug to return no checks by Template Scanner when both
                  the `Days` and the `Years` are set to `ObjectLockConfiguration`.</li>
</ul>]]></description>
    <pubDate>Mon, 05 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-s3-object-lock-templat</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Feature: Disable Specific Regions in Rule Configuration Settings</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-feature-disable-specific-regio</link>
    <description><![CDATA[<div class="p">June 06, 2023, Conformity—Rule Update</div><div class="p">You can now disable specific regions from the Rule configuration settings and exclude
               them from generating checks for the following AWS rules:</div><ul class="ul" id="whatsnew_c18_4ab_145__ul_7ee_8d0">
<li class="li">Config-001: AWS Config Enabled</li>
<li class="li">CT-001: CloudTrail Enabled</li>
<li class="li">GD-001: GuardDuty Enabled</li>
</ul>]]></description>
    <pubDate>Tue, 06 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-feature-disable-specific-regio</guid>
    <category>Conformity</category>
</item>
<item>
    <title>HIPAA compliance standard updated to latest version and added support for GCP rules</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-hipaa-compliance-standard-updated</link>
    <description><![CDATA[<div class="p">June 06, 2023, Conformity—We've added the HIPAA compliance standard to support GCP
               rules and also updated the standard to the latest version i.e. HIPAA Feb-2023 for
               AWS and Azure rules.</div>]]></description>
    <pubDate>Tue, 06 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-hipaa-compliance-standard-updated</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity Billing Incident Leads to Reduced Usage Charges for Customers</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-billing-incident-leads</link>
    <description><![CDATA[<div class="p">June 07, 2023, Conformity—Incident Update: Trend Cloud One Conformity Recorded Reduced
               Usage for Customers with Metered Consumption Billing</div><div class="p">An incident affecting Conformity consumption billing reduced the expected billing
               charges for some accounts with S3, IAM, EC2, and Azure Monitor resources.</div><div class="p">This led to incorrectly excluding resource counts during the incident. As a result,
               account consumption tiers may have been temporarily changed to a lower tier.</div><div class="p">Affected Regions</div><div class="p">All</div><div class="p">Impact</div><div class="p">Intermittent reduction in usage charges between  21 August 2021 to 7 June 2023 for
               some customers using consumption billing.</div><div class="p">Resolution</div><div class="p">We’re working on deploying a fix for the bug that caused the drop in usage. As a result,
               you may see an increase in your Conformity consumption and, consequently, your charges
               once we deploy the bug fix. Watch out for the bug fix update on our What’s New page.</div>]]></description>
    <pubDate>Wed, 07 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-billing-incident-leads</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP rule ensures SSL certificates are renewed within validity period</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rule-ensures-ssl-certifica</link>
    <description><![CDATA[<div class="p">June 07, 2023, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_15b_e3c_414__ul_47c_1ff">
<li class="li">CertificateManager-001: SSL certificates validity period: This rule ensures that the
                  SSL certificates are renewed within the appropriate validity period.</li>
</ul>]]></description>
    <pubDate>Wed, 07 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rule-ensures-ssl-certifica</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Efficient Cloud Account Scanning for Conformity Bot Introduced</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-efficient-cloud-account-scanning-f</link>
    <description><![CDATA[<div class="p">June 08, 2023, Conformity—Introduced a system improvement to increase the efficiency
               of scanning cloud accounts with large numbers of resources.</div><div class="p">Please note: some accounts with large number of resources may experience a brief disruption
               in scheduled Conformity Bot scans while the change is being rolled out. The system
               will recover and return to normal within 2 hours.</div>]]></description>
    <pubDate>Thu, 08 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-efficient-cloud-account-scanning-f</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug Fix: Increased Conformity consumption billing for certain resources</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-increased-conformity-consu</link>
    <description><![CDATA[<div class="p">June 08, 2023, Conformity—Bug Fix</div><div class="p">Reduced Consumption Billing: Fixed a bug where Conformity consumption billing reduced
               the expected billing charges for some accounts with S3, IAM, EC2, and Azure Monitor
               resources. As a result of the bug fix, you may see an increase in your Conformity
               consumption and, consequently, your billing charges.</div>]]></description>
    <pubDate>Thu, 08 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-increased-conformity-consu</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated rule logic to restrict default network access for Azure Cosmos DB Accounts</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-logic-to-restrict-def</link>
    <description><![CDATA[<div class="p">June 08, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_903_08c_b6b__ul_d5e_fae">
<li class="li">CosmosDB-003: Restrict Default Network Access for Azure Cosmos DB Accounts: Updated
                  the rule logic to incorporate public network setting to avoid false negatives.</li>
</ul>]]></description>
    <pubDate>Thu, 08 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-logic-to-restrict-def</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug Fix for Template Scanner for CMK Encrypted RDS</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-template-scanner-for-c</link>
    <description><![CDATA[<div class="p">June 13, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_572_ca6_567__ul_5cd_292">
<li class="li">RDS-005: RDS Encrypted With KMS Customer Master Keys: Fixed a bug with Template Scanner
                  to return correct scan results for CMK encrypted RDS.</li>
</ul>]]></description>
    <pubDate>Tue, 13 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-template-scanner-for-c</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Trend Vision One integration moved to Trend Cloud One console</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-vision-one-integration-moved</link>
    <description><![CDATA[<div class="p">June 15, 2023, Workload Security—The integration of Trend Cloud One - Endpoint &amp; Workload
               Security with Trend Vision One has been deprecated. In the past, users integrated
               Trend Vision One with Trend Cloud One - Endpoint &amp; Workload Security (C1WS &gt; Administration
               &gt; Vision One (XDR)). Now, to check the Trend Vision One integration status, users
               must use the Trend Cloud One console (Integrations &gt; Vision One).</div>]]></description>
    <pubDate>Thu, 15 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-vision-one-integration-moved</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>New GCP rule requires defining index page suffix and error page for bucket websites</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rule-requires-defining-ind</link>
    <description><![CDATA[<div class="p">June 19, 2023, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_4fb_b30_cf5__ul_004_5c7">
<li class="li">CloudStorage-005: Define index page suffix and error page for the bucket website configuration:
                  This rule ensures that the bucket website configuration includes a main page suffix
                  and an error page.</li>
</ul>]]></description>
    <pubDate>Mon, 19 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rule-requires-defining-ind</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Configure load balancers for Managed Instance Groups in GCP</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-configure-load-balancers-for-manag</link>
    <description><![CDATA[<div class="p">June 21, 2023, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_9ca_0d9_d36__ul_47b_8fc">
<li class="li">ComputeEngine-013: Configure load balancers for Managed Instance Groups: This rule
                  ensures that Managed Instance Groups (MIGs) are associated with load balancers.</li>
</ul>]]></description>
    <pubDate>Wed, 21 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-configure-load-balancers-for-manag</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug Fix for S3 Bucket DNS Compliance Check Accuracy</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-s3-bucket-dns-complian</link>
    <description><![CDATA[<div class="p">June 22, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_fdd_340_027__ul_627_6ce">
<li class="li">S3-018: DNS Compliant S3 Bucket Names: Fixed a bug to return correct check results
                  when the S3 bucket resource sets the DNS compliant bucket name.</li>
</ul>]]></description>
    <pubDate>Thu, 22 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-s3-bucket-dns-complian</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Deep Security Agent now supports Amazon Linux 2023 on AWS ARM-based Graviton 2</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-now-supports-a</link>
    <description><![CDATA[<div class="p">June 28, 2023, Workload Security—Deep Security Agent 20.0.0-7303 (20 LTS Update 2023-06-28)
               supports Amazon Linux 2023 (AWS ARM-based Graviton 2). This requires Deep Security
               Manager 20.0.789 or later.</div>]]></description>
    <pubDate>Wed, 28 Jun 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-now-supports-a</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity Bot now accurately scans RDS Snapshots</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-bot-now-accurately-scan</link>
    <description><![CDATA[<div class="p">July 03, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_af5_917_144__ul_49e_98e">
<li class="li">Fixed a bug that limited Conformity Bot from scanning the RDS Snapshots accurately.</li>
</ul>]]></description>
    <pubDate>Mon, 03 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-bot-now-accurately-scan</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity User Interface transitioning to Dark Mode on 12 July 2023</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-user-interface-transiti</link>
    <description><![CDATA[<div class="p">July 04, 2023, Conformity—We’re moving the Conformity User Interface to Dark Mode
               on 12 July 2023 to align with Trend’s brand identity and be consistent with the user
               experience and messaging across all assets and standards.</div>]]></description>
    <pubDate>Tue, 04 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-user-interface-transiti</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug Fix for Weekly Summary Emails in `us-west-2` Region</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-weekly-summary-emails</link>
    <description><![CDATA[<div class="p">July 04, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_9e3_d43_b2a__ul_706_ff1">
<li class="li">Fixed a bug where some users belonging to Organisations in the region `us-west-2`
                  were not receiving their weekly summary emails.</li>
</ul>]]></description>
    <pubDate>Tue, 04 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-weekly-summary-emails</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug Fix: Active users without email no longer appear in recipient list</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-active-users-without-email</link>
    <description><![CDATA[<div class="p">July 05, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_05a_581_cf8__ul_55a_a90">
<li class="li">Fixed a bug where active users without an email were showing up on the email recipient
                  list when sending a failed rule resolution email or when setting up an email communication
                  channel.</li>
</ul>]]></description>
    <pubDate>Wed, 05 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-active-users-without-email</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity Bot bug fix ensures STS enabled in all AWS regions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-bot-bug-fix-ensures-sts</link>
    <description><![CDATA[<div class="p">July 06, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_be9_c4a_d16__ul_791_cac">
<li class="li">Fixed a bug with the Conformity Bot's scanning where STS was disabled in at least
                  one AWS region.</li>
</ul>]]></description>
    <pubDate>Thu, 06 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-bot-bug-fix-ensures-sts</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS account scanner stacks for enhanced S3 bucket protection</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-account-scanner-stacks-for-enh</link>
    <description><![CDATA[<div class="p">July 10, 2023, File Storage Security—File Storage Security now provides AWS account
               scanner stacks which are capable to protect all AWS S3 buckets in your AWS account.</div><div class="p">For details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-aws-deploy-account-scanner-stacks-" target="_blank">Deploy account scanner stacks</a>.</div>]]></description>
    <pubDate>Mon, 10 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-account-scanner-stacks-for-enh</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced scanner reports password-protected PDF files</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-scanner-reports-password</link>
    <description><![CDATA[<div class="p">July 10, 2023, File Storage Security—The scanner is now able to report if a PDF file
               is password-protected.</div>]]></description>
    <pubDate>Mon, 10 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-scanner-reports-password</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Updated Security Policy Rules with Configurability and Latest TLS Versions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-security-policy-rules-with</link>
    <description><![CDATA[<div class="p">July 12, 2023, Conformity—Rule Update</div><div class="p">Updated the following security policy rules to be configurable, and updated to the
               latest TLS versions:</div><ul class="ul" id="whatsnew_420_e3b_fb7__ul_c8b_ed7">
<li class="li">ELBv2-003: ELBv2 ALB Security Policy</li>
<li class="li">ELBv2-009: Network Load Balancer Security Policy</li>
<li class="li">CF-006: CloudFront Security Policy</li>
<li class="li">ELB-004: ELB Security Policy</li>
<li class="li">ELB-015: Web-Tier ELB Security Policy</li>
<li class="li">ELB-016: App-Tier ELB Security Policy</li>
</ul>]]></description>
    <pubDate>Wed, 12 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-security-policy-rules-with</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity UI transitions to Dark Mode for improved consistency and branding</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-ui-transitions-to-dark</link>
    <description><![CDATA[<div class="p">July 12, 2023, Conformity—Trend Cloud One Conformity - Dark Mode Released</div><div class="p">We’ve moved the Conformity User Interface to Dark Mode to align with Trend’s brand
               identity and be consistent with the user experience and messaging across all assets
               and standards.</div>]]></description>
    <pubDate>Wed, 12 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-ui-transitions-to-dark</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Azure StorageAccounts-023 Rule: Private Endpoint Enforcement for Microsoft Azure Storage Accounts</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-storageaccounts-023-rule-pri</link>
    <description><![CDATA[<div class="p">July 14, 2023, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_026_d44_1e9__ul_ab8_bdd">
<li class="li">StorageAccounts-023: Private Endpoint in Use: This rule ensures that private endpoints
                  are used to access Microsoft Azure Storage accounts.</li>
</ul>]]></description>
    <pubDate>Fri, 14 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-storageaccounts-023-rule-pri</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Azure rule enforces no custom subscription administrator roles</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-rule-enforces-no-custom</link>
    <description><![CDATA[<div class="p">July 19, 2023, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_157_6b5_4fb__ul_045_ac0">
<li class="li">AccessControl-003: Subscription Administrator Custom Role: This rule ensures that
                  there are no custom subscription administrator roles within your Microsoft Azure cloud
                  account.</li>
</ul>]]></description>
    <pubDate>Wed, 19 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-rule-enforces-no-custom</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Historical Reports Download Bug Fixed, Restoration Efforts Made</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-historical-reports-download-bug-fi</link>
    <description><![CDATA[<div class="p">July 20, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_c40_9b0_7a5__ul_f27_b39">
<li class="li">Fixed a bug where some customers could not download their organization's historical
                  reports. We've made every effort to restore the maximum number of historical reports,
                  but could not recover all.</li>
</ul>]]></description>
    <pubDate>Thu, 20 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-historical-reports-download-bug-fi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug Fix: AWS Conformity Bot now supports disabled AWS Gov Cloud regions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-aws-conformity-bot-now-sup</link>
    <description><![CDATA[<div class="p">July 24, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_a2a_be8_aa3__ul_e47_004">
<li class="li">Fixed a bug that prevented users from updating the AWS Conformity Bot settings with
                  disabled AWS Gov Cloud regions.</li>
</ul>]]></description>
    <pubDate>Mon, 24 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-aws-conformity-bot-now-sup</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated CloudFront Security Policy for CF-006 Rule Compliance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-cloudfront-security-policy</link>
    <description><![CDATA[<div class="p">July 25, 2023, Conformity—Rule Update</div><div class="p">CF-006: CloudFront Security Policy</div><ul class="ul" id="whatsnew_174_5d2_349__ul_80a_ace">
<li class="li">Updated the rule to be compliant with the latest security policy.</li>
</ul>]]></description>
    <pubDate>Tue, 25 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-cloudfront-security-policy</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Manual Scan Trigger via Right-Click for Deep Security Agent</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-manual-scan-trigger-via-right-clic</link>
    <description><![CDATA[<div class="p">July 25, 2023, Workload Security—Deep Security Agent now allows users to trigger a
               manual scan by right-clicking on a file or folder and selecting Scan with Deep Security
               Agent.</div>]]></description>
    <pubDate>Tue, 25 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-manual-scan-trigger-via-right-clic</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced AWS CloudFront scanning for improved security checks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-cloudfront-scanning-f</link>
    <description><![CDATA[<div class="p">July 26, 2023, Conformity—Rule Update</div><div class="p">Fixed an issue with the way we scan AWS CloudFront resources to provide a more accurate
               and complete set of checks.</div><ul class="ul" id="whatsnew_cdf_59d_d04__ul_a01_100">
<li class="li">CF-001: CloudFront In Use</li>
<li class="li">CF-002: CloudFront Insecure Origin SSL Protocols</li>
<li class="li">CF-003: CloudFront Traffic To Origin Unencrypted</li>
<li class="li">CF-004: CloudFront Integrated With WAF</li>
<li class="li">CF-005: CloudFront Logging Enabled</li>
<li class="li">CF-006: CloudFront Security Policy</li>
<li class="li">CF-007: CloudFront Viewer Protocol Policy</li>
<li class="li">CF-008: CloudFront Geo Restriction</li>
<li class="li">CF-009: CloudFront Compress Objects Automatically</li>
<li class="li">CF-011: FieldLevel Encryption</li>
<li class="li">CF-012: Use CloudFront Content Distribution Network</li>
</ul>]]></description>
    <pubDate>Wed, 26 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-cloudfront-scanning-f</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Azure Rules Enhance Security and Compliance Measures</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-rules-enhance-security-a</link>
    <description><![CDATA[<div class="p">July 26, 2023, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_ae1_ef6_f63__ul_df1_fa9">
<li class="li">Monitor-011: Configure Application Insights: This rule ensures that an Application
                  Insights resource is created within your Azure cloud account.</li>
</ul><ul class="ul" id="whatsnew_ae1_ef6_f63__ul_a57_e1d">
<li class="li">PostgreSQL-014: Disable "Allow access to Azure services" for PostgreSQL database servers:
                  This rule ensures that any access from Azure services to Azure PostgreSQL database
                  servers is disabled.</li>
</ul><ul class="ul" id="whatsnew_ae1_ef6_f63__ul_8f3_955">
<li class="li">Network-026: Bastion Host in Use: This rule ensures that Azure Bastion service is
                  used within your Microsoft Azure cloud account.</li>
</ul><ul class="ul" id="whatsnew_ae1_ef6_f63__ul_e96_7ba">
<li class="li">Subscriptions-004: Basic/Consumption SKU Should not be Used in Production: This rule
                  ensures that the Basic/Consumption SKU is not used for Azure cloud resources that
                  need to be monitored, for example, production workloads.</li>
</ul>]]></description>
    <pubDate>Wed, 26 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-rules-enhance-security-a</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Azure encryption rule &amp; compliance updates for NIST, APRA, and CIS Controls</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-encryption-rule--complia</link>
    <description><![CDATA[<div class="p">July 27, 2023, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_8fc_e99_ed6__ul_1f2_b17">
<li class="li">StorageAccounts-024: Enable Infrastructure Encryption: This rule ensures that infrastructure
                  encryption is enabled for Microsoft Azure Storage accounts.</li>
</ul><div class="p">Rules' Mapping Update for Compliance Standards</div><ul class="ul" id="whatsnew_8fc_e99_ed6__ul_158_34e">
<li class="li">We've updated the Rule mappings to be compliant with the NIST 800-53 Rev.5, APRA CPS
                  234 and CIS Controls Version 8 Compliance and Standard Reports.</li>
</ul>]]></description>
    <pubDate>Thu, 27 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-encryption-rule--complia</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Scanner Lambda function vulnerability in dependent modules fixed</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanner-lambda-function-vulnerabil</link>
    <description><![CDATA[<div class="p">July 28, 2023, File Storage Security—Fixed the issue where the scanner Lambda function
               was vulnerable in the dependent modules.</div>]]></description>
    <pubDate>Fri, 28 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanner-lambda-function-vulnerabil</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enhanced Azure Network Watcher rule with region customization and failure notification</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azure-network-watcher-rul</link>
    <description><![CDATA[<div class="p">July 31, 2023, Conformity—Rule Update</div><div class="p">Network-003: Enable Azure Network Watcher: You can now Add or Remove Azure regions
               from the rule Settings in addition to a default list of regions we've included in
               the rule. We've also updated the rule to return a failure if the Network Watcher service
               isn't enabled for all the configured Azure regions.</div>]]></description>
    <pubDate>Mon, 31 Jul 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azure-network-watcher-rul</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Custom Compliance Standards now accessible via Conformity API endpoints</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-compliance-standards-now-ac</link>
    <description><![CDATA[<div class="p">August 03, 2023, Conformity—Custom Compliance Standards</div><div class="p">We’re excited to share that you can now <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-sentry-" target="_blank">preview</a> Custom Compliance Standards through the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Custom-Compliance-Standards" target="_blank">Conformity API endpoints</a>. For details, see our <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-custom-compliance-standards-" target="_blank">help documentation</a>.</div>]]></description>
    <pubDate>Thu, 03 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-compliance-standards-now-ac</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated CFM-006 rule now generates failure check for overly permissive IAM role policies</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-cfm-006-rule-now-generates</link>
    <description><![CDATA[<div class="p">August 04, 2023, Conformity—Rule Update</div><div class="p">CFM-006: CloudFormation Stack With IAM Role: Updated the rule to generate a failure
               check if the policy allows for all actions with all the resources.</div>]]></description>
    <pubDate>Fri, 04 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-cfm-006-rule-now-generates</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Trend Micro Artifact Scanner CLI now supports scanning multiple-architecture container images</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-artifact-scanner-cli-n</link>
    <description><![CDATA[<div class="p">August 09, 2023, Container Security—<a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-container-security--container-security-tmas-about-" target="_blank">Trend Micro Artifact Scanner (TMAS) CLI</a> now supports scanning container images with multiple architectures and platforms.</div><div class="p">The new platform flag lets you specify which platform/architecture to use when scanning
               multiple-architecture container images. It also allows you to scan images from the
               docker or podman daemons with different architectures than the host that is running
               TMAS. For example, if you are on an M1 powered Mac, you can now easily scan x86_64
               specific images.</div>]]></description>
    <pubDate>Wed, 09 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-micro-artifact-scanner-cli-n</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Updated rule for identifying KMS keys in S3 buckets with customer-provided CMKs</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-for-identifying-kms-k</link>
    <description><![CDATA[<div class="p">August 10, 2023, Conformity—Bug Fixes</div><div class="p">S3-025: S3 Buckets Encrypted with Customer-Provided CMKs: Updated the rule to identify
               KMS keys properly.</div>]]></description>
    <pubDate>Thu, 10 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-for-identifying-kms-k</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Azure Stack Storage Security Configurations Applied</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azure-stack-storage-secur</link>
    <description><![CDATA[<div class="p">August 11, 2023, File Storage Security—The following Azure security configurations
               are now used for the storage accounts deployed in the Azure stacks:</div><ul class="ul" id="whatsnew_4fe_f3a_16f__ul_2f2_99e">
<li class="li">The `allowBlobPublicAccess` property is set to `false`.</li>
<li class="li">The `supportsHttpsTrafficOnly` property is set to `true`.</li>
</ul><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Fri, 11 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azure-stack-storage-secur</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Vulnerability in GCP scanner cloud function modules fixed</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-vulnerability-in-gcp-scanner-cloud</link>
    <description><![CDATA[<div class="p">August 11, 2023, File Storage Security—Fixed the issue where the GCP scanner cloud
               function was vulnerable in the dependent modules.</div>]]></description>
    <pubDate>Fri, 11 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-vulnerability-in-gcp-scanner-cloud</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>AWS Account Scanner now supports encrypted DLQs for enhanced security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-account-scanner-now-supports-e</link>
    <description><![CDATA[<div class="p">August 13, 2023, File Storage Security—Fixed AWS Account Scanner's PostScanActionLambda
               Lambda function where it was unable to send message to an encrypted DLQ due to lacking
               permission to access KMS key responsible for DLQ encryption.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Sun, 13 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-account-scanner-now-supports-e</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Standalone Conformity SSO Certificate Expiry Reminder</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-standalone-conformity-sso-certific</link>
    <description><![CDATA[<div class="p">August 14, 2023, Conformity—IMPORTANT: Standalone Conformity SSO Certificate Expiry</div><div class="p">The current Conformity SSO certificate will expire on Thursday 17 August 2023 at 09:41:05
               UTC. Follow the instructions on this <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-conformity-saml-2.0-sso-certificate-rotation-guide-" target="_blank">help page</a> for actions that you may need to take to switch to the new certificate.</div><div class="p">Trend Micro support will be reaching out to customers affected.</div><div class="p">Customers using Cloud One SSO are unaffected.</div>]]></description>
    <pubDate>Mon, 14 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-standalone-conformity-sso-certific</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP Rule for Configuring &quot;log_min_messages&quot; Flag on PostgreSQL Instances</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rule-for-configuring-log_m</link>
    <description><![CDATA[<div class="p">August 15, 2023, Conformity—New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_cab_8e4_41a__ul_9eb_f98">
<li class="li">CloudSQL-030: Configure "log_min_messages" Flag for PostgreSQL Instances: This rule
                  ensures that PostgreSQL database instances have the appropriate configuration set
                  for the "log_min_messages" flag.</li>
</ul>]]></description>
    <pubDate>Tue, 15 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rule-for-configuring-log_m</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Rule CloudSQL-001 Updated to Align with CIS GCP v2.0 Control 6</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-cloudsql-001-updated-to-align</link>
    <description><![CDATA[<div class="p">August 15, 2023, Conformity—Rule Update</div><div class="p">CloudSQL-001: Check for Cloud SQL Database Instances with Public IPs: Update the rule
               to align more closely with CIS GCP v2.0 Control 6.2.9.</div>]]></description>
    <pubDate>Tue, 15 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-cloudsql-001-updated-to-align</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Azure scanner vulnerability in dependent modules now fixed</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-scanner-vulnerability-in-dep</link>
    <description><![CDATA[<div class="p">August 15, 2023, File Storage Security—Fixed the issue where the Azure scanner function
               was vulnerable in the dependent modules.</div>]]></description>
    <pubDate>Tue, 15 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-scanner-vulnerability-in-dep</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>New rule to manage API keys for active services in Google Cloud projects</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-rule-to-manage-api-keys-for-ac</link>
    <description><![CDATA[<div class="p">August 16, 2023, Conformity—New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_cf1_712_ec3__ul_b65_384">
<li class="li">CloudAPI-005: API Keys Should Only Exist for Active Services (Not Scored): This rule
                  ensures that there are no API keys in use within your Google Cloud projects.</li>
</ul>]]></description>
    <pubDate>Wed, 16 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-rule-to-manage-api-keys-for-ac</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New PostgreSQL configuration rule for CloudSQL instances</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-postgresql-configuration-rule</link>
    <description><![CDATA[<div class="p">August 21, 2023, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_b4a_025_f8a__ul_d20_68c">
<li class="li">CloudSQL-031: Configure "log_error_verbosity" Flag for PostgreSQL Instances: This
                  rule ensures that PostgreSQL database instances have the appropriate configuration
                  set for the "log_error_verbosity" flag.</li>
</ul>]]></description>
    <pubDate>Mon, 21 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-postgresql-configuration-rule</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated rule logic for EBS encryption with KMS Customer Master Keys</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-logic-for-ebs-encrypt</link>
    <description><![CDATA[<div class="p">August 22, 2023, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_d19_052_8e1__ul_6c7_8d8">
<li class="li">EBS-002: EBS Encrypted With KMS Customer Master Keys: Updated the rule logic to validate
                  the EBS volumes correctly.</li>
</ul>]]></description>
    <pubDate>Tue, 22 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-logic-for-ebs-encrypt</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved AWS stack security with role policy update requirement</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-stack-security-with-r</link>
    <description><![CDATA[<div class="p">August 23, 2023, File Storage Security—Fixed the issue of cross-service confused deputy
               problem in the AWS stacks. To update the existing stacks, the `iam:UpdateAssumeRolePolicy`
               permission is required.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Wed, 23 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-stack-security-with-r</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved performance for uploading large number of files to Azure Storage</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-performance-for-uploading</link>
    <description><![CDATA[<div class="p">August 25, 2023, File Storage Security—Fixed the performance issue when large number
               of files were uploaded to the Azure storage account.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Fri, 25 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-performance-for-uploading</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Custom Rule Updates for Enhanced Customization Experience</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-rule-updates-for-enhanced-c</link>
    <description><![CDATA[<div class="p">August 28, 2023, Conformity—Custom Rule Updates</div><div class="p">When creating a new custom rule, there is now an option to specify rule slug that
               will yield a custom rule id combined from the `CUSTOM` prefix and the slug provided.
               The slug field needs to be unique across organization, up to 200 characters long and
               comprised of only alphanumeric characters and - and _ without spaces.</div>]]></description>
    <pubDate>Mon, 28 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-rule-updates-for-enhanced-c</guid>
    <category>Conformity</category>
</item>
<item>
    <title>GCP Conformity Bot no longer scans shutdown projects</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-conformity-bot-no-longer-scans</link>
    <description><![CDATA[<div class="p">August 29, 2023, Conformity—We've updated the GCP Conformity Bot; it won't scan a
               shutdown GCP project now.</div>]]></description>
    <pubDate>Tue, 29 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-conformity-bot-no-longer-scans</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved scanning for GCP Resource Manager service to reduce API throttling</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-scanning-for-gcp-resource</link>
    <description><![CDATA[<div class="p">August 29, 2023, Conformity—Bug Fix</div><div class="p">Updated the way we scan GCP Resource Manager service to reduce API throttling with
               the following rules:</div><ul class="ul" id="whatsnew_6ea_a96_0d0__ul_1fa_2cd">
<li class="li">ResourceManager-001: Disable User-Managed Key Creation for Service Accounts</li>
<li class="li">ResourceManager-002: Disable Automatic IAM Role Grants for Default Service Accounts</li>
<li class="li">ResourceManager-003: Enforce Uniform Bucket-Level Access</li>
</ul>]]></description>
    <pubDate>Tue, 29 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-scanning-for-gcp-resource</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Deep Security Agent now supports Miracle Linux 8 in FIPS mode</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-now-supports-m</link>
    <description><![CDATA[<div class="p">August 29, 2023, Workload Security—Deep Security Agent version 20.0.0-7719 and later
               supports Miracle Linux 8, including FIPS mode. This requires Deep Security Manager
               version 20.0.817 or later.</div>]]></description>
    <pubDate>Tue, 29 Aug 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-now-supports-m</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity Report renamed to Cloud Posture Report; Lambda Runtime Environment Version Rule Update</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-report-renamed-to-cloud</link>
    <description><![CDATA[<ul class="ul" id="whatsnew_75f_233_351__ul_6f4_805">
<li class="li">We've renamed The 'Conformity Report' to the 'Cloud Posture Report' to align with
                  Trend's brand messaging.</li>
</ul><div class="p">September 01, 2023, Conformity—Rule Update</div><div class="p">Lambda-001: Lambda Runtime Environment Version: Updated the rule with a default 'Latest
               runtime version' list configurable from the Rule Settings, to ensure the use the latest
               version of the execution environment configured for your Amazon Lambda functions.</div>]]></description>
    <pubDate>Fri, 01 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-report-renamed-to-cloud</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Container Security FAQs and TMAS Upgrade Guidelines for Improved User Experience</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-container-security-faqs-a</link>
    <description><![CDATA[<div class="p">September 01, 2023, Container Security—Revised the FAQ section titled "If I Restrict
               Outbound Traffic, What URLs Do I Need to Allow for Internet Communication?" to incorporate
               additional URLs for all C1 regions, which is responsible for enabling the download
               of vulnerability reports for TMAS directly from S3.</div><div class="p">Updated the TMAS documentation by adding additional guidelines on how to upgrade TMAS
               to the most recent version.</div>]]></description>
    <pubDate>Fri, 01 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-container-security-faqs-a</guid>
    <category>Container Security</category>
</item>
<item>
    <title>New Rule for Examining and Resolving Microsoft Defender for Cloud Security Alerts in Azure</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-rule-for-examining-and-resolvi</link>
    <description><![CDATA[<div class="p">September 05, 2023, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_1bf_580_63c__ul_992_582">
<li class="li">SecurityCenter-041: Microsoft Defender for Cloud Security Alerts: This rule ensures
                  that Microsoft Defender for Cloud security alerts are examined and resolved.</li>
<li class="li">Known issue: We have an existing issue with the new rule where alerts that are in
                  progress status will be displayed as active. We'll share an update as soon as this
                  is resolved.</li>
</ul>]]></description>
    <pubDate>Tue, 05 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-rule-for-examining-and-resolvi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Efficient Scanning for Cloud Accounts with Large Resources Added</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-efficient-scanning-for-cloud-accou</link>
    <description><![CDATA[<div class="p">September 07, 2023, Conformity—Introduced a system improvement to increase the efficiency
               of scanning cloud accounts with large numbers of resources.</div><div class="p">Please note: some accounts with large number of resources may experience a brief disruption
               in scheduled Conformity Bot scans while the change is being rolled out. The system
               will recover and return to normal within 2 hours.</div>]]></description>
    <pubDate>Thu, 07 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-efficient-scanning-for-cloud-accou</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AI Assistant now available for Knowledge Base and Help pages</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-ai-assistant-now-available-for-kno</link>
    <description><![CDATA[<div class="p">September 08, 2023, Conformity—You can now use our new AI Assistant for the <a class="xref" href="https://www.trendmicro.com/cloudoneconformity/ai-assistant-kb.html" target="_blank">Knowledge base</a> and <a class="xref" href="https://www.trendmicro.com/cloudoneconformity/ai-assistant-help.html" target="_blank">Help pages</a> to get the most out of Conformity and help improve your cloud infrastructure.</div>]]></description>
    <pubDate>Fri, 08 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-ai-assistant-now-available-for-kno</guid>
    <category>Conformity</category>
</item>
<item>
    <title>File Storage Security expands support to new Azure regions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-expands-supp</link>
    <description><![CDATA[<div class="p">September 11, 2023, File Storage Security—File Storage Security now supports Australia
               East (australiaeast), Australia Southeast (australiasoutheast) and Japan West (japanwest)
               regions on Azure. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-supported-azure-#AzureRegion" target="_blank">What's supported in Azure</a>.</div>]]></description>
    <pubDate>Mon, 11 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-expands-supp</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Rule Update for ComputeEngine-003: Improved identification of Interactive Serial Console Support status</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-update-for-computeengine-003</link>
    <description><![CDATA[<div class="p">September 12, 2023, Conformity—Rule Update</div><div class="p">GCP</div><ul class="ul" id="whatsnew_b1c_197_1d5__ul_33d_e96">
<li class="li">ComputeEngine-003: Disable Interactive Serial Console Support: Update the rule to
                  identify "Enable connecting to serial ports" configuration setting status properly.</li>
</ul>]]></description>
    <pubDate>Tue, 12 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-update-for-computeengine-003</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Integrate Conformity with Trend Vision One for enhanced risk insights</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-integrate-conformity-with-trend-vi</link>
    <description><![CDATA[<div class="p">September 13, 2023, Conformity—Integrate Trend Cloud One - Conformity with Trend Vision
               One</div><div class="p">Trend Cloud One - Conformity customers</div><div class="p">You can now integrate Conformity with <a class="xref" href="https://www.trendmicro.com/en_au/business/products/one-platform.html" target="_blank">Trend Vision One</a> by signing up for a 30 day fully customizable <a class="xref" href="https://resources.trendmicro.com/vision-one-test-drive.html" target="_blank">Trend Vision One trial</a>. Once you sign-up or you've already signed up with Trend Vision One, you can integrate
               Conformity with Trend Vision One &gt; Risk Insights using an API key.</div><div class="p">For step-by step insrtuctions, see the help page: <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-integrate-conformity-with-trend-vision-one-" target="_blank">Integrating Trend Vision One Conformity with Trend Vision One</a>.</div><div class="p">Haven't Signed up for Conformity</div><div class="p">If you haven't signed up for Conformity yet, please follow the <a class="xref" href="https://docs.trendmicro.com/en-us/enterprise/trend-micro-xdr-help/AWSConformitySetup" target="_blank">Conformity AWS Data Source Setup</a> guide and follow the steps in the help page linked above.</div><div class="p">Conformity Standalone (Legacy Customers)</div><div class="p">Refer to the Conformity Standalone (Legacy) Customers section in the help page linked
               above.</div>]]></description>
    <pubDate>Wed, 13 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-integrate-conformity-with-trend-vi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated rule in Azure SecurityCenter for enabling Microsoft Defender Standard Pricing Tier</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-in-azure-securitycent</link>
    <description><![CDATA[<div class="p">September 13, 2023, Conformity—Rule Update</div><div class="p">Azure</div><ul class="ul" id="whatsnew_2a4_c91_2c1__ul_959_925">
<li class="li">SecurityCenter-001: Enable Microsoft Defender Standard Pricing Tier: Updated the rule
                  enabling you to configure 'Resource Types' validation from the 'Rule Settings'.</li>
</ul>]]></description>
    <pubDate>Wed, 13 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-in-azure-securitycent</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AI Assistants now support 85 languages for enhanced user experience</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-ai-assistants-now-support-85-langu</link>
    <description><![CDATA[<div class="p">September 13, 2023, Conformity—Our AI Assistants for the <a class="xref" href="https://www.trendmicro.com/cloudoneconformity/ai-assistant-kb.html" target="_blank">Knowledge base</a> and <a class="xref" href="https://www.trendmicro.com/cloudoneconformity/ai-assistant-help.html" target="_blank">Help pages</a> can now answer questions in 85 languages including English, Spanish, French, German,
               Portuguese, Italian, Dutch, Russian, Arabic, and Chinese.</div>]]></description>
    <pubDate>Wed, 13 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-ai-assistants-now-support-85-langu</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Rule Update for GCP Compute Engine-001: Improved identification of VM instance network interface access configuration</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-update-for-gcp-compute-engine</link>
    <description><![CDATA[<div class="p">September 14, 2023, Conformity—Rule Update</div><div class="p">GCP</div><ul class="ul" id="whatsnew_0c8_eb5_d90__ul_8dd_9ee">
<li class="li">ComputeEngine-001: Check for Virtual Machine Instances with Public IP Addresses: Updated
                  the rule to identify the VM instance network interface access configuration status
                  accurately.</li>
</ul>]]></description>
    <pubDate>Thu, 14 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-update-for-gcp-compute-engine</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Azure SQL Managed Instances now support encryption with Customer-Managed Keys</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-sql-managed-instances-now-su</link>
    <description><![CDATA[<div class="p">September 18, 2023, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_3e9_f2d_a0d__ul_4f5_15c">
<li class="li">SQL-019: Enable Transparent Data Encryption for SQL Managed Instance using Customer-Managed
                  Keys: This rule ensures that Azure SQL managed instances are encrypted at rest using
                  Customer-Managed Keys (CMKs).</li>
</ul>]]></description>
    <pubDate>Mon, 18 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-sql-managed-instances-now-su</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS scanner retry period reduced to 4 minutes for quicker error resolution</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-scanner-retry-period-reduced-t</link>
    <description><![CDATA[<div class="p">September 19, 2023, File Storage Security—The retry period for the scan error of the
               AWS scanner is shortened from 12 minutes to 4 minutes.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Tue, 19 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-scanner-retry-period-reduced-t</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Object names in GCP scan activities no longer contain bucket names</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-object-names-in-gcp-scan-activitie</link>
    <description><![CDATA[<div class="p">September 20, 2023, File Storage Security—Fixed the issue where the object names of
               GCP scan activities contained Google Cloud Storage bucket names.</div>]]></description>
    <pubDate>Wed, 20 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-object-names-in-gcp-scan-activitie</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Enable Transparent Data Encryption for Azure Synapse Analytics Dedicated SQL Pools</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-transparent-data-encryption</link>
    <description><![CDATA[<div class="p">September 21, 2023, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_924_b99_d5a__ul_a8e_c4e">
<li class="li">Synapse-001: Enable Transparent Data Encryption for Azure Synapse Analytics Dedicated
                  SQL Pools: This rule ensures that Transparent Data Encryption (TDE) is enabled for
                  dedicated SQL pools in Azure Synapse Analytics.</li>
</ul>]]></description>
    <pubDate>Thu, 21 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-transparent-data-encryption</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New AWS Lambda rule to ensure supported runtime environments usage</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-lambda-rule-to-ensure-supp</link>
    <description><![CDATA[<div class="p">September 22, 2023, Conformity—Rule Update</div><div class="p">AWS</div><ul class="ul" id="whatsnew_068_676_e6e__ul_d49_0e7">
<li class="li">Lambda-001: Lambda Using Latest Runtime Environment: Updated the rule title from 'Lambda
                  Runtime Environment Version' to 'Lambda Using Latest Runtime Environment'.</li>
</ul><div class="p">New Rules</div><div class="p">AWS</div><ul class="ul" id="whatsnew_068_676_e6e__ul_53f_6f0">
<li class="li">Lambda-012: Lambda Using Supported Runtime Environment: This rule ensures that you
                  always use a supported environment version for your Amazon Lambda functions in order
                  to avoid end of support timeframes from AWS.</li>
</ul>]]></description>
    <pubDate>Fri, 22 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-lambda-rule-to-ensure-supp</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced AWS Account Scanner template with ExclusiveBucketList parameter</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-account-scanner-templ</link>
    <description><![CDATA[<div class="p">September 22, 2023, File Storage Security—A new parameter `ExclusiveBucketList` has
               been added to the AWS Account Scanner template. You can now ignore some S3 buckets
               for scanning, and the quarantine bucket will be skipped as well.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Fri, 22 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-account-scanner-templ</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>New AWS Rule Update Allows Disabling Specific Regions for Conformity Checks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-rule-update-allows-disabli</link>
    <description><![CDATA[<div class="p">September 26, 2023, Conformity—Rule Update</div><div class="p">AWS</div><div class="p">You can now disable specific regions from the Rule configuration settings and exclude
               them from generating checks for the following AWS rules:</div><ul class="ul" id="whatsnew_925_e59_e59__ul_f11_992">
<li class="li">IAM-065: IAM Access Analyzer in Use</li>
<li class="li">EBS-014: EBS default encryption</li>
<li class="li">Macie2-003: Amazon Macie Discovery Jobs</li>
<li class="li">SecurityHub-002: Security Hub Enabled</li>
</ul>]]></description>
    <pubDate>Tue, 26 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-rule-update-allows-disabli</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Rule mappings now compliant with ISO 27001:2022 and AWS Well-Architected Framework</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-mappings-now-compliant-with-i</link>
    <description><![CDATA[<div class="p">September 27, 2023, Conformity—Rules' Mapping Update for Compliance Standards</div><ul class="ul" id="whatsnew_d31_cf6_253__ul_190_048">
<li class="li">We've updated the Rule mappings to be compliant with the ISO 27001:2022 and AWS Well-Architected
                  Framework Compliance and Standard Reports.</li>
</ul>]]></description>
    <pubDate>Wed, 27 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-mappings-now-compliant-with-i</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Instance Storage AutoScaling and Template Scanner Bug Fix</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-instance-storage-autoscalin</link>
    <description><![CDATA[<ul class="ul" id="whatsnew_809_315_bf3__ul_4aa_50e">
<li class="li">RDS-041: Enable Instance Storage AutoScaling</li>
</ul><ul class="ul" id="whatsnew_809_315_bf3__ul_806_52d">
<li class="li">Fixed a bug with the Template Scanner to support the `MaxAllocatedStorage` property
                  in the RDS DBInstance resource.</li>
</ul>]]></description>
    <pubDate>Wed, 27 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-instance-storage-autoscalin</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved Scanner Lambda Function Connectivity in File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-scanner-lambda-function-c</link>
    <description><![CDATA[<div class="p">September 27, 2023, File Storage Security—Fixed the issue where the scanner Lambda
               function may timeout when failing to connect to File Storage Security backend.</div>]]></description>
    <pubDate>Wed, 27 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-scanner-lambda-function-c</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>New `dateComparison` operator added for Custom Rules</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-datecomparison-operator-added</link>
    <description><![CDATA[<div class="p">September 28, 2023, Conformity—We've introduced a new operator, `dateComparison`,
               for Custom Rules. This operator enables the creation of custom rules that interact
               with date strings in resources. Within this operator, we've added two sub-operators:
               olderThan and within. You can use this operator to determine whether a date string
               is older than a specific date or falls within a certain time frame.</div><div class="p">For more information, see</div><ul class="ul" id="whatsnew_493_082_b2a__ul_cb7_de9">
<li class="li"><a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-in-preview-custom-rules-overview-#operators" target="_blank">An Overview of Conformity Custom Rules</a></li>
</ul><ul class="ul" id="whatsnew_493_082_b2a__ul_b2e_bc1">
<li class="li"><a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Custom-Rules-" target="_blank">API Reference</a></li>
</ul>]]></description>
    <pubDate>Thu, 28 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-datecomparison-operator-added</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated Conformity rules for optimal interaction with restricted AWS regions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-conformity-rules-for-optim</link>
    <description><![CDATA[<div class="p">September 28, 2023, Conformity—Rule Update</div><div class="p">AWS</div><div class="p">Updated the following rules' to interact optimally with AWS regions with restricted
               permissions in Conformity:</div><ul class="ul" id="whatsnew_305_177_19e__ul_a55_043">
<li class="li">Config-001: AWS Config Enabled</li>
<li class="li">CT-001: CloudTrail Enabled</li>
<li class="li">GD-001: GuardDuty Enabled</li>
</ul>]]></description>
    <pubDate>Thu, 28 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-conformity-rules-for-optim</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated Compliance Standards Mapping for Rules in Conformity</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-compliance-standards-mappi</link>
    <description><![CDATA[<div class="p">September 28, 2023, Conformity—Rules' Mapping Update for Compliance Standards</div><ul class="ul" id="whatsnew_774_c42_845__ul_bfb_bc6">
<li class="li">We've updated the Rule mappings to be compliant with the NIST Cybersecurity Framework
                  and ISO 27001 Compliance and Standard Reports.</li>
</ul>]]></description>
    <pubDate>Thu, 28 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-compliance-standards-mappi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated rule now supports Windows and unsupported Linux VMs for Azure Virtual Machines</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-now-supports-windows</link>
    <description><![CDATA[<div class="p">September 29, 2023, Conformity—Rule Update</div><div class="p">Azure</div><div class="p">VirtualMachines-024: Enable Performance Diagnostics for Azure Virtual Machines: Updated
               this rule to support Windows and unsupported Linux VMs.</div>]]></description>
    <pubDate>Fri, 29 Sep 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-now-supports-windows</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Advanced Threat Scan Engine now integrated with AWS, Azure, and GCP scanners</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-advanced-threat-scan-engine-now-in</link>
    <description><![CDATA[<div class="p">October 05, 2023, File Storage Security—The AWS, Azure, and GCP scanners with Advanced
               Threat Scan Engine (ATSE) 22.610.1017 are now available.</div>]]></description>
    <pubDate>Thu, 05 Oct 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-advanced-threat-scan-engine-now-in</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Scanner Lambda function issue resolved for File Storage Security backend</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanner-lambda-function-issue-reso</link>
    <description><![CDATA[<div class="p">October 05, 2023, File Storage Security—Fixed the issue where the scanner Lambda function
               repeatedly sent a scan event to the File Storage Security backend.</div>]]></description>
    <pubDate>Thu, 05 Oct 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scanner-lambda-function-issue-reso</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity Enhancements for SOC 2 Compliance and Security Group Mapping Updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-for-soc-2</link>
    <description><![CDATA[<div class="p">October 12, 2023, Conformity—Rules' Mapping Update for Compliance Standards</div><ul class="ul" id="whatsnew_08c_e01_cb3__ul_338_231">
<li class="li">We've updated the Rule mappings to be compliant with the System and Organization Controls
                  2 (SOC 2) Compliance and Standard Reports.</li>
</ul><div class="p">Rule Update</div><div class="p">Azure</div><ul class="ul" id="whatsnew_08c_e01_cb3__ul_cd3_8c4">
<li class="li">AppService-012: Enable FTPS-Only Access: Updated this rule to resolve the case-sensitive
                  issue to avoid false negatives.</li>
</ul><div class="p">AWS</div><div class="p">The following rules won't generate checks for security groups that are shared from
               other accounts.</div><ul class="ul" id="whatsnew_08c_e01_cb3__ul_c52_fd9">
<li class="li">EC2-001: Security Group Port Range</li>
<li class="li">EC2-002: Unrestricted SSH Access</li>
<li class="li">EC2-003: Unrestricted RDP Access</li>
<li class="li">EC2-004: Unrestricted Oracle Access</li>
<li class="li">EC2-005: Unrestricted MySQL Access</li>
<li class="li">EC2-006: Unrestricted PostgreSQL Access</li>
<li class="li">EC2-007: Unrestricted DNS Access</li>
<li class="li">EC2-008: Unrestricted MsSQL Access</li>
<li class="li">EC2-012: Security Group Excessive Counts</li>
<li class="li">EC2-013: Security Group Large Counts</li>
<li class="li">EC2-014: Security Group Rules Counts</li>
<li class="li">EC2-032: SecurityGroup RFC 1918</li>
<li class="li">EC2-033: Unrestricted Security Group Egress</li>
<li class="li">EC2-034: Unrestricted Security Group Ingress on Uncommon Ports</li>
<li class="li">EC2-036: Security Group Naming Conventions</li>
<li class="li">EC2-038: Unrestricted Telnet Access</li>
<li class="li">EC2-039: Unrestricted SMTP Access</li>
<li class="li">EC2-040: Unrestricted RPC Access</li>
<li class="li">EC2-041: Unrestricted NetBIOS Access</li>
<li class="li">EC2-042: Unrestricted FTP Access</li>
<li class="li">EC2-043: Unrestricted CIFS Access</li>
<li class="li">EC2-044: Unrestricted ICMP Access</li>
<li class="li">EC2-045: Unrestricted MongoDB Access</li>
<li class="li">EC2-059: Descriptions for Security Group Rules</li>
<li class="li">EC2-061: Security Group Name Prefixed With 'launch-wizard'</li>
<li class="li">EC2-063: Unrestricted Elasticsearch Access</li>
<li class="li">EC2-064: Unrestricted HTTP Access</li>
<li class="li">EC2-065: Unrestricted HTTPS Access</li>
<li class="li">EC2-074: Check for Unrestricted Redis Access</li>
<li class="li">EC2-075: Check for Unrestricted Memcached Access</li>
<li class="li">RG-001: Tags</li>
</ul><div class="p">Shared security groups won't be considered by the following rules:</div><ul class="ul" id="whatsnew_08c_e01_cb3__ul_d75_d86">
<li class="li">EC2-015: EC2 Instance Security Group Rules Counts</li>
<li class="li">ELB-007: ELB Security Group</li>
</ul>]]></description>
    <pubDate>Thu, 12 Oct 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-for-soc-2</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated Compliance Standards: CIS Foundations Benchmarks for AWS, Azure, and GCP</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-compliance-standards-cis-f</link>
    <description><![CDATA[<div class="p">October 19, 2023, Conformity—Updated Compliance Standards: CIS Foundations Benchmarks</div><div class="p">We've updated our compliance standards to meet the Center of Internet Security (CIS)
               Foundations Benchmarks for AWS, Azure and GCP. You can now filter Checks and download
               Compliance Reports to ensure your cloud environment complies with the latest CIS Foundations
               Benchmarks.</div><ul class="ul" id="whatsnew_efc_eee_f5a__ul_1a9_0c0">
<li class="li">CIS Amazon Web Services Foundations Benchmark v2.0.0</li>
<li class="li">CIS Microsoft Azure Foundations Benchmark v2.0.0</li>
<li class="li">CIS Google Cloud Platform Foundation Benchmark v2.0.0</li>
</ul><div class="p">You can view the CIS certifications awarded to Trend Micro Cloud One - Conformity
               on the <a class="xref" href="https://www.cisecurity.org/partner/trend-micro" target="_blank">CIS partner website</a> and find out more about <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-compliance-and-conformity-" target="_blank">Compliance and Conformity</a> in our documentation.</div>]]></description>
    <pubDate>Thu, 19 Oct 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-compliance-standards-cis-f</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated Azure Cosmos DB rule to improve network access restriction validation</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-azure-cosmos-db-rule-to-im</link>
    <description><![CDATA[<div class="p">October 25, 2023, Conformity—Rule Update</div><div class="p">Azure</div><div class="p">CosmosDB-003: Restrict Default Network Access for Azure Cosmos DB Accounts: Updated
               this rule to skip virtual network validation to avoid false negatives.</div>]]></description>
    <pubDate>Wed, 25 Oct 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-azure-cosmos-db-rule-to-im</guid>
    <category>Conformity</category>
</item>
<item>
    <title>GuardDuty Enabled Rule now supports all AWS regions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-guardduty-enabled-rule-now-support</link>
    <description><![CDATA[<div class="p">October 25, 2023, Conformity—Rule Update</div><div class="p">AWS</div><div class="p">GD-001: GuardDuty Enabled: Updated rule to support all regions. <a class="xref" href="https://aws.amazon.com/guardduty/faqs/" target="_blank">Read more &gt;&gt;</a></div>]]></description>
    <pubDate>Wed, 25 Oct 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-guardduty-enabled-rule-now-support</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Update Required for Azure Scanner and Storage Stacks for Application Insights Migration</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-update-required-for-azure-scanner</link>
    <description><![CDATA[<div class="p">October 26, 2023, File Storage Security—You need to update your Azure Scanner and
               Storage Stacks to migrate the classic Application Insights to the workspace-based
               Application Insights before Feb 29, 2024.</div><div class="p">For more information, see <a class="xref" href="https://azure.microsoft.com/en-us/updates/we-re-retiring-classic-application-insights-on-29-february-2024/" target="_blank">We are retiring Classic Application Insights on 29 February 2024</a> on the official Azure site. It is recommended to migrate the Application Insights
               by updating your Scanner and Storage Stacks as soon as possible.</div><div class="p">In the Azure deployment templates, a new parameter  `VNETRestrictedAccessForAzureMonitorResources`
               was added, so that you can allow or disallow public network access to those Azure
               Monitor resources deployed by the templates. The parameter, `VNETRestrictedAccessForApplicationInsights`,
               will be replaced by the new one and be deprecated after October 31st, 2024.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Thu, 26 Oct 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-update-required-for-azure-scanner</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Template Scanner in Conformity now continues scanning Terraform plans without interruption</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-in-conformity-now</link>
    <description><![CDATA[<div class="p">November 08, 2023, Conformity—Template Scanner - Terraform plans: Fixed a bug to ensure
               that the Template Scanner continues scanning in event of missing or empty attributes
               from certain rules in the template.</div>]]></description>
    <pubDate>Wed, 08 Nov 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-in-conformity-now</guid>
    <category>Conformity</category>
</item>
<item>
    <title>File Storage Security expands to AWS Jakarta and Zurich regions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-expands-to-a</link>
    <description><![CDATA[<div class="p">November 10, 2023, File Storage Security—File Storage Security now supports Jakarta
               (ap-southeast-3) and Zurich (eu-central-2) regions on AWS. For more information, see
               <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-supported-aws-#AWSRegion" target="_blank">What's supported in AWS</a>.</div>]]></description>
    <pubDate>Fri, 10 Nov 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-expands-to-a</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>File Storage Security scanner now updated with urllib3 version 1.26.18</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-scanner-now</link>
    <description><![CDATA[<div class="p">November 10, 2023, File Storage Security—Update urllib3 version to 1.26.18 in scanner
               to resolve <a class="xref" href="https://nvd.nist.gov/vuln/detail/CVE-2023-45803" target="_blank">CVE-2023-45803</a></div>]]></description>
    <pubDate>Fri, 10 Nov 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-scanner-now</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Expanded Tag Support for Additional AWS Resource Types</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-expanded-tag-support-for-additiona</link>
    <description><![CDATA[<div class="p">November 13, 2023, Conformity—Rules Update</div><div class="p">AWS</div><div class="p">RG-001: Tags: Update the rule to add the following resource types to support tags:</div><ul class="ul" id="whatsnew_c4e_b1b_055__ul_3a6_e8b">
<li class="li">EC2 Key Pair</li>
<li class="li">EC2 Reserved Instance</li>
<li class="li">ECS Cluster</li>
<li class="li">ECS Container Instance</li>
<li class="li">ECS Services</li>
<li class="li">ECS Task Definition</li>
<li class="li">EKS Cluster</li>
<li class="li">Lambda Function</li>
<li class="li">Neptune DB Cluster</li>
<li class="li">RDS DB Cluster</li>
<li class="li">RDS DB Snapshot</li>
<li class="li">RDS Event Subscription</li>
<li class="li">RDS Reserved DB Instance</li>
<li class="li">VPC Egress-Only Internet Gateway</li>
<li class="li">VPC Endpoint</li>
<li class="li">VPC Internet Gateway</li>
<li class="li">VPC NAT Gateway</li>
<li class="li">VPC Peering Connection</li>
<li class="li">VPC Route Table</li>
<li class="li">VPC Subnet</li>
<li class="li">VPC Transit Gateway</li>
<li class="li">VPC Transit Gateway Attachment</li>
<li class="li">VPC Transit Gateway Route Table</li>
<li class="li">VPC VPN Connection</li>
<li class="li">VPC VPN Gateway</li>
</ul>]]></description>
    <pubDate>Mon, 13 Nov 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-expanded-tag-support-for-additiona</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Fixed IAM certificate bug impacting multiple SSL/TLS certificate rules and updated CloudLogging-001 rule</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-iam-certificate-bug-impactin</link>
    <description><![CDATA[<div class="p">November 14, 2023, Conformity—Bug Fix</div><div class="p">AWS</div><ul class="ul" id="whatsnew_7e8_2e0_caa__ul_fbb_27c">
<li class="li">Fixed a bug impacting IAM certificate which affected the following rules:</li>
<li class="li">IAM-018: SSL/TLS Certificate Expiry 7 Days</li>
<li class="li">IAM-019: SSL/TLS Certificate Expiry 30 Days</li>
<li class="li">IAM-020: SSL/TLS Certificate Expiry 45 Days</li>
<li class="li">IAM-021: Expired SSL/TLS Certificate</li>
<li class="li">IAM-033: Pre-Heartbleed Server Certificates</li>
<li class="li">IAM-059: Server Certificate Signature Algorithm</li>
<li class="li">IAM-062: AWS IAM Server Certificate Size</li>
</ul><div class="p">GCP</div><ul class="ul" id="whatsnew_7e8_2e0_caa__ul_4e4_0e0">
<li class="li">CloudLogging-001: Enable Monitoring for Bucket Permission Changes: Updated the rule
                  to validate the alerting policy correctly.</li>
</ul>]]></description>
    <pubDate>Tue, 14 Nov 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-iam-certificate-bug-impactin</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New parameter added for selecting tag format in File Storage Security template</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-parameter-added-for-selecting</link>
    <description><![CDATA[<div class="p">November 15, 2023, File Storage Security—A new parameter `ScanResultTagFormat` has
               been added to the AWS All-in-one, Storage Stack and Account Scanner template. You
               can now select tag format for the post scan action tag. For more information, see
               <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security--file-storage-security-scan-tag-overview#ViewTag" target="_blank">View Tags</a>.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Wed, 15 Nov 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-parameter-added-for-selecting</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Updated terminology to &#x27;Microsoft Entra ID&#x27; in Conformity and UI for clarity</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-terminology-to-microsoft-e</link>
    <description><![CDATA[<div class="p">November 20, 2023, Conformity—We've updated all instances of the term 'Azure AD' to
               'Microsoft Entra ID' in Trend Cloud One - Conformity and Standalone UI, Online help
               and API documentation following an update from Microsoft in July 2023. For details,
               see: <a class="xref" href="https://learn.microsoft.com/en-us/entra/fundamentals/new-name#glossary-of-updated-terminology" target="_blank">Microsoft's Glossary of Updated Terminology</a>.</div>]]></description>
    <pubDate>Mon, 20 Nov 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-terminology-to-microsoft-e</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved accuracy in scanning Terraform Templates for invalid format in Template Scanner</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-accuracy-in-scanning-terr</link>
    <description><![CDATA[<div class="p">November 21, 2023, Conformity—We've added sanity checking to produce more accurate
               results while scanning a Terrafrom Template with an invalid format in the Template
               Scanner.</div>]]></description>
    <pubDate>Tue, 21 Nov 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-accuracy-in-scanning-terr</guid>
    <category>Conformity</category>
</item>
<item>
    <title>System events descriptions in Trend Cloud One now display time zones accurately</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-system-events-descriptions-in-tren</link>
    <description><![CDATA[<div class="p">November 21, 2023, Workload Security—As part of the SNS update, time zones in the
               description of the system events in Trend Cloud One - Endpoint &amp; Workload Security
               are no longer converted to the local time zone to match security events.</div>]]></description>
    <pubDate>Tue, 21 Nov 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-system-events-descriptions-in-tren</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Improved Azure template deployment success with explicit dependencies in Application Insights</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-azure-template-deployment</link>
    <description><![CDATA[<div class="p">November 27, 2023, File Storage Security—Fixed the issue of Azure template deployment
               failure by adding explicit dependencies in Application Insights to ensure that the
               Log Analytics workspace was deployed before them.</div>]]></description>
    <pubDate>Mon, 27 Nov 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-azure-template-deployment</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Bug Fix for CloudLogging Rules and Update to CloudIAM-001 Rule Configuration</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-cloudlogging-rules-and</link>
    <description><![CDATA[<div class="p">December 04, 2023, Conformity—Bug Fix</div><div class="p">GCP</div><ul class="ul" id="whatsnew_739_22e_923__ul_bc1_240">
<li class="li">Fixed a bug impacting the following CloudLogging rules:</li>
<li class="li">CloudLogging-001: Enable Monitoring for Bucket Permission Changes</li>
<li class="li">CloudLogging-002: Enable VPC Network Route Changes Monitoring</li>
<li class="li">CloudLogging-003: Enable VPC Network Changes Monitoring</li>
<li class="li">CloudLogging-004: Enable Monitoring for Custom Role Changes</li>
<li class="li">CloudLogging-005: Enable Monitoring for SQL Instance Configuration Changes</li>
<li class="li">CloudLogging-006: Enable Monitoring for Firewall Rule Changes</li>
<li class="li">CloudLogging-007: Enable Monitoring for Audit Configuration Changes</li>
<li class="li">CloudLogging-008: Enable Project Ownership Assignments Monitoring</li>
</ul><div class="p">Rules Update</div><div class="p">GCP</div><div class="p">CloudIAM-001: Restrict Administrator Access for Service Accounts:</div><ul class="ul" id="whatsnew_739_22e_923__ul_018_472">
<li class="li">Update the rule to accurately exclude Google-managed service accounts.</li>
<li class="li">Update the rule to display the number of service accounts associated with each role.
                  Additionally, detailed information will only be shown for roles that have fewer than
                  5 service accounts.</li>
</ul>]]></description>
    <pubDate>Mon, 04 Dec 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-cloudlogging-rules-and</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Microsoft Azure AD renamed to Microsoft Entra ID in Trend Cloud One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-microsoft-azure-ad-renamed-to-micr</link>
    <description><![CDATA[<div class="p">December 07, 2023, Workload Security—Azure AD is now referred to as Microsoft Entra
               ID in Trend Cloud One - Endpoint &amp; Workload Security UI, online help, and API documentation
               following the product name change by Microsoft in July 2023. For details, see <a class="xref" href="https://learn.microsoft.com/en-us/entra/fundamentals/new-name#glossary-of-updated-terminology" target="_blank">Microsoft's Glossary of Updated Terminology</a></div>]]></description>
    <pubDate>Thu, 07 Dec 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-microsoft-azure-ad-renamed-to-micr</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Deep Security Agent (DSA) Requires Upgrade to New Revision in January 2024</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-dsa-requires-u</link>
    <description><![CDATA[<div class="p">December 11, 2023, Workload Security—Using the new release of Deep Security Agent
               (DSA) requires upgrading agents with the new DSA revision in January 2024. For details,
               see <a class="xref" href="https://success.trendmicro.com/en-us/solution/ka-0013804" target="_blank">Platform support updates for Deep Security Agent (DSA) version revision in January
                  2024 Update Release</a>.</div>]]></description>
    <pubDate>Mon, 11 Dec 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-dsa-requires-u</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Updated Conformity Custom Policy with Added Permissions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-conformity-custom-policy-w</link>
    <description><![CDATA[<div class="p">December 12, 2023, Conformity—Custom Policy Update</div><div class="p">The Conformity AWS custom policy was updated on 5.12.2023 at 09:59 AEST. The new custom
               policy version is 1.45 and the permissions added are:</div><ul class="ul" id="whatsnew_ff2_54e_ca4__ul_303_b21">
<li class="li">ecr:DescribeImages</li>
<li class="li">lambda:ListLayers</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Tue, 12 Dec 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-conformity-custom-policy-w</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Deep Security Agent now supports Debian Linux 12</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-now-supports-d</link>
    <description><![CDATA[<div class="p">December 12, 2023, Workload Security—Deep Security Agent 20.0.0-8438 and later supports
               Debian Linux 12.</div>]]></description>
    <pubDate>Tue, 12 Dec 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-now-supports-d</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Deep Security Agent now supports Windows 11 23H2</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-now-supports-w</link>
    <description><![CDATA[<div class="p">December 12, 2023, Workload Security—Deep Security Agent 20.0.0-8438 and later supports
               Windows 11 23H2.</div>]]></description>
    <pubDate>Tue, 12 Dec 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-now-supports-w</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity Enhancements for NIS Europe Compliance Standards and Rule Updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-for-nis-eu</link>
    <description><![CDATA[<div class="p">December 19, 2023, Conformity—Rules' Mapping Update for Compliance Standards</div><ul class="ul" id="whatsnew_e9a_f45_67f__ul_fad_a82">
<li class="li">We've updated the Rule mappings to be compliant with the NIS Europe Compliance and
                  Standard Reports.</li>
</ul><div class="p">Rules Update</div><div class="p">AWS</div><div class="p">IAM-042: Hardware MFA for AWS Root Account: Updated this rule to a not scored rule.
               AWS can now support multiple virtual and hardware MFA devices on the root account.
               It is no longer possible to conclusively determine the presence of a hardware MFA
               device on the root account via API.</div><div class="p">Azure</div><div class="p">Advisor-001: Check for Azure Advisor Recommendations: Updated the extra data within
               the check message to improve the identification of the check and its corresponding
               recommendation.</div>]]></description>
    <pubDate>Tue, 19 Dec 2023 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-for-nis-eu</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug Fix improves Activity Log Storage Container checks in Monitor-005</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-improves-activity-log-stor</link>
    <description><![CDATA[<div class="p">January 09, 2024, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_329_7b8_689__ul_bfe_bf4">
<li class="li">Monitor-005: Check for Publicly Accessible Activity Log Storage Container: Fixed a
                  bug that was inhibiting the checks being created by the scanner.</li>
</ul>]]></description>
    <pubDate>Tue, 09 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-improves-activity-log-stor</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New AWS Lambda function rule and S3 bucket encryption exceptions added</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-lambda-function-rule-and-s</link>
    <description><![CDATA[<div class="p">January 09, 2024, Conformity—New Rules</div><div class="p">AWS</div><div class="p">Lambda-013: Function in Private Subnet: This rule ensures that your Amazon Lambda
               functions are configured to use private subnets.</div><div class="p">Rules Update</div><div class="p">AWS</div><div class="p">S3-025: S3 Buckets Encrypted with Customer-Provided CMKs: You can now add exceptions
               to the rule configurations.</div><div class="p">DynamoD-004: AWS KMS Customer Master Keys for Table Encryption: Update the rule title,
               description, and check message to clearly distinguish between Customer Managed Keys
               (CMK) and AWS Managed Keys.</div>]]></description>
    <pubDate>Tue, 09 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-lambda-function-rule-and-s</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Amazon Inspector 2 for enhanced AWS cloud environment security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-amazon-inspector-2-for-enha</link>
    <description><![CDATA[<div class="p">January 10, 2024, Conformity—New Rules</div><div class="p">AWS</div><div class="p">Inspector2-001: Enable Amazon Inspector 2: This rule ensures that Amazon Inspector
               2 is enabled for your AWS cloud environment.</div>]]></description>
    <pubDate>Wed, 10 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-amazon-inspector-2-for-enha</guid>
    <category>Conformity</category>
</item>
<item>
    <title>GCP Scanner now auto-retries on failure for improved File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-scanner-now-auto-retries-on-fa</link>
    <description><![CDATA[<div class="p">January 10, 2024, File Storage Security—The GCP scanner function auto retry on failure
               is now enabled. This mitigates a known issue where the cloud function randomly threw
               an error when performing HTTP requests.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Wed, 10 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-scanner-now-auto-retries-on-fa</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>GCP Deprecating &#x27;python38&#x27; and &#x27;nodejs16&#x27; Runtimes for Functions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-deprecating-python38-and-nodej</link>
    <description><![CDATA[<div class="p">January 10, 2024, File Storage Security—The GCP functions currently run in the Node.js
               20 and Python 3.12 runtimes. Both `python38` and `nodejs16` runtimes are scheduled
               to be deprecated later this year by GCP. For more information, see <a class="xref" href="https://cloud.google.com/functions/docs/runtime-support" target="_blank">Runtime support</a>. It is recommended to update the runtime as soon as possible by updating the Scanner
               Stack and Storage Stack.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Wed, 10 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-gcp-deprecating-python38-and-nodej</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved AWS API call monitoring with bug fix for regex validation</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-api-call-monitoring-w</link>
    <description><![CDATA[<div class="p">January 11, 2024, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_93e_fa2_dfd__ul_623_f35">
<li class="li">RTM-011: Monitor Unintended AWS API Calls: Fixed the regex validation for the rule
                  setting. We advise checking for any existing invalid regex patterns as your configured
                  rule settings will not be modified.</li>
</ul>]]></description>
    <pubDate>Thu, 11 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-api-call-monitoring-w</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Support for AWS RDS Transport Encryption for MySQL and Aurora Databases</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-aws-rds-transport-encr</link>
    <description><![CDATA[<div class="p">January 16, 2024, Conformity—Rule Update</div><ul class="ul" id="whatsnew_37b_a58_d68__ul_b17_91b">
<li class="li">RDS-037: Enable AWS RDS Transport Encryption: Updated the rule to support MySQL, Aurora
                  MySQL, and Aurora PostgreSQL database engines.</li>
</ul>]]></description>
    <pubDate>Tue, 16 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-aws-rds-transport-encr</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced VDI Support and Endpoint Identification in Trend Cloud One Integration</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-vdi-support-and-endpoint</link>
    <description><![CDATA[<div class="p">January 16, 2024, Workload Security—Trend Vision One Endpoint Security and Trend Cloud
               One integrated with Trend Vision One can now use Virtual Desktop Infrastructure (VDI)
               operations on endpoints without needing the image setup tool. This feature can be
               enabled via the agent <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security-agent-system-settings" target="_blank">System Settings</a> by selecting <b class="uicontrol">Allow Vision One Virtual Desktop Infrastructure (VDI) support</b> and cloned virtual machines. Before enabling this feature, be aware of the following:</div><ul class="ul" id="whatsnew_a7f_828_8de__ul_18f_c4e">
<li class="li">Enabling VDI support locks three system settings:
                  <ul class="ul" id="whatsnew_a7f_828_8de__ul_xks_l1z_c3c">
<li class="li">If a computer already exists: Reactivate the existing computer</li>
<li class="li">Reactivate cloned agents: True</li>
<li class="li">Reactivate unknown agents: True</li>
</ul>
</li>
<li class="li">The number of hosts in the computer list may vary.</li>
</ul><div class="p">This enhancement also resolves the following issues:</div><ul class="ul" id="whatsnew_a7f_828_8de__ul_4ac_c9a">
<li class="li">Trend Cloud One - Endpoint &amp; Workload Security and Trend Vision One Endpoint Security
                  Server &amp; Workload Protection mistook multiple endpoints as the same endpoint.</li>
<li class="li">The detection log for Trend Vision One and the endpoint inventory for Trend Vision
                  One Endpoint Security mistook agents installed on one device as a different endpoint.</li>
</ul>]]></description>
    <pubDate>Tue, 16 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-vdi-support-and-endpoint</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Upgrade to Deep Security Agent version 20.0.1-690 required for new release</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upgrade-to-deep-security-agent-ver</link>
    <description><![CDATA[<div class="p">January 17, 2024, Workload Security—Using the new release of Deep Security Agent requires
               upgrading agents with the new version 20.0.1-690. For details, see <a class="xref" href="https://success.trendmicro.com/en-us/solution/ka-0013804" target="_blank">Platform support updates for Deep Security Agent (DSA) version revision in January
                  2024 Update Release</a></div>]]></description>
    <pubDate>Wed, 17 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upgrade-to-deep-security-agent-ver</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity introduces updated AWS custom policy with new permissions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-updated-aws</link>
    <description><![CDATA[<div class="p">January 18, 2024, Conformity—Custom Policy Update</div><div class="p">The Conformity AWS custom policy was updated on 16.01.2024 at 10:59 AEDT. The new
               custom policy version is 1.46 and the permissions added are:</div><ul class="ul" id="whatsnew_a7b_0fc_ef7__ul_327_7a0">
<li class="li">rds:DescribeDBClusterParameters</li>
<li class="li">rds:DescribeDBClusterParameterGroups</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Thu, 18 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-updated-aws</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Support for Google Cloud Architecture Framework compliance in GCP</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-google-cloud-architect</link>
    <description><![CDATA[<div class="p">January 18, 2024, Conformity—Compliance standards</div><div class="p">Google Cloud Architecture Framework</div><div class="p">We now support Google Cloud Architecture Framework (version August 2023) across compliance
               features for GCP.</div>]]></description>
    <pubDate>Thu, 18 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-google-cloud-architect</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Custom Role for File Storage Security Bucket Listener in GCP Terraform Deployment</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-role-for-file-storage-secur</link>
    <description><![CDATA[<div class="p">January 18, 2024, File Storage Security—Created a custom role Trend Micro File Storage
               Security Bucket Listener Storage Role to access the scanning bucket in a GCP stack's
               Terraform deployment to prevent a predefined role's IAM binding from being overwritten.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Thu, 18 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-role-for-file-storage-secur</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Stable Network Connectivity for AWS Scanner Function</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-stable-network-connectivity-for-aw</link>
    <description><![CDATA[<div class="p">January 22, 2024, File Storage Security—Fixed the issue where the AWS scanner function
               sometimes reported an "Invalid license status" message in the scan results due to
               unstable network status.</div>]]></description>
    <pubDate>Mon, 22 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-stable-network-connectivity-for-aw</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>AWS Lambda upgraded to Python 3.11 runtime, deprecating Python 3.8 later</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-lambda-upgraded-to-python-311</link>
    <description><![CDATA[<div class="p">January 23, 2024, File Storage Security—The AWS Lambda now runs on Python 3.11 runtime.
               AWS Lambda Python 3.8 is scheduled to be deprecated later this year by AWS. For more
               information, see <a class="xref" href="https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html" target="_blank">Lambda runtimes</a>. It is recommended to update the runtime as soon as possible by updating the Scanner
               Stack, Storage Stack, and Account Scanner Stack.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Tue, 23 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-lambda-upgraded-to-python-311</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity Enhancements: New Custom Checks TTL Management and Rule Update for Client Certificates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-new-custom</link>
    <description><![CDATA[<div class="p">January 29, 2024, Conformity—Rule Update</div><ul class="ul" id="whatsnew_d46_f04_cae__ul_a73_525">
<li class="li">AppService-008: Enable Incoming Client Certificates: Updated the rule to automatically
                  produce a SUCCESS check if HTTP 2.0 is enabled.</li>
</ul><div class="p">Custom Checks Updates</div><div class="p">We have made the following updates to the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Checks#paths-~1checks-post" target="_blank">Custom Checks API</a> feature:</div><ul class="ul" id="whatsnew_d46_f04_cae__ul_ba4_72a">
<li class="li">Updated the Custom Checks 'Time-To-Live' (TTL) feature to allow mutability for existing
                  checks, enabling easier stateless management and deletion.</li>
<li class="li">Introduced a Maximum TTL of 12 months for newly created checks. If no TTL is specified,
                  the value will default to 12 months after the creation date.</li>
<li class="li">Fixed a bug that resulted in some existing custom checks being incorrectly deleted.</li>
</ul><div class="p">Custom Checks Data Migration</div><ul class="ul" id="whatsnew_d46_f04_cae__ul_960_2c0">
<li class="li">On Wednesday 31 January (AEDT), we will migrate your existing custom checks to the
                  new TTL system.</li>
<li class="li">All existing custom checks without a TTL will be updated to include a TTL of 12 months
                  from the update date.</li>
</ul><div class="p">For further details, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Checks-#paths-~1checks-post" target="_blank">Create Custom Checks</a> and <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-custom-rules-vs-conformity-rules-" target="_blank">Custom Rules vs Conformity Rules</a>.</div>]]></description>
    <pubDate>Mon, 29 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhancements-new-custom</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Azure Scanner with Updated Service Bus SDK for Improved Authorization Timeout Handling</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azure-scanner-with-update</link>
    <description><![CDATA[<div class="p">January 29, 2024, File Storage Security—Updated the Azure Service Bus SDK's version
               to 7.10.0 in the Azure scanner to mitigate the Authorization timeout issue during
               publishing scan results to the Service Bus.</div>]]></description>
    <pubDate>Mon, 29 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-azure-scanner-with-update</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Custom Checks now support Time-To-Live updates for better customization</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-checks-now-support-time-to</link>
    <description><![CDATA[<div class="p">January 31, 2024, Conformity—Custom Checks Updates</div><div class="p">On Monday 29 January 2024 (AEDT), we introduced the following updates to Custom Checks:</div><ul class="ul" id="whatsnew_2f4_fba_99e__ul_156_d9b">
<li class="li">Allow 'Time-To-Live' (TTL) to be mutable.</li>
<li class="li">Introduced a default and maximum TTL value of 12 months after the check creation date.</li>
</ul><div class="p">As of Wednesday 31 January (AEDT), we have migrated all existing Custom Checks to
               use TTL. The affected checks now have a TTL of 12 months from today, at which point
               they will automatically be deleted.</div><div class="p">If you have existing Custom Checks, you can update the TTL value via the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Checks#paths-~1checks~1%7BcheckId%7D-patch" target="_blank">Update Check</a> endpoint. If you wish to maintain a Custom Check beyond 12 months, we recommend scheduling
               an automated API process to keep your Custom Checks up-to-date.</div>]]></description>
    <pubDate>Wed, 31 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-checks-now-support-time-to</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved AWS scanner function for reliable scan retries</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-scanner-function-for</link>
    <description><![CDATA[<div class="p">January 31, 2024, File Storage Security—Fixed the issue where the AWS scanner function
               sometimes did not retry the scan for scan error scan results.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Wed, 31 Jan 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-scanner-function-for</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Updated rules exclude cross account evaluation for BigQuery encryption with customer-managed keys</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rules-exclude-cross-accoun</link>
    <description><![CDATA[<div class="p">February 05, 2024, Conformity—Rule Update</div><div class="p">Updated these rules to exclude cross account evaluation to avoid false positive checks:</div><ul class="ul" id="whatsnew_d49_316_e25__ul_772_71f">
<li class="li">BigQuery-002: Enable BigQuery Encryption with Customer-Managed Keys</li>
<li class="li">BigQuery-003: Enable BigQuery Dataset Encryption with Customer-Managed Encryption
                  Keys</li>
</ul>]]></description>
    <pubDate>Mon, 05 Feb 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rules-exclude-cross-accoun</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP account permission &quot;iam.roles.list&quot; added for Conformity cloudiam-roles descriptor</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permission-iamrole</link>
    <description><![CDATA[<div class="p">February 07, 2024, Conformity—GCP account permission list updated</div><div class="p">New permission "iam.roles.list" added for "cloudiam-roles" descriptor. For the full
               list of required GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">here</a>.</div>]]></description>
    <pubDate>Wed, 07 Feb 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permission-iamrole</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Upcoming Rule Updates for AWS and GCP with Key Rotation and Runtime Environment Changes</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upcoming-rule-updates-for-aws-and</link>
    <description><![CDATA[<div class="p">February 08, 2024, Conformity—Upcoming Rule Updates</div><div class="p">The following rule updates will be released soon. These changes may affect your checks
               and compliance scores:</div><div class="p">AWS</div><ul class="ul" id="whatsnew_148_3f0_84c__ul_e95_878">
<li class="li">KMS-002: Key Rotation Enabled: Update to stop incorrect checks for Asymmetric keys.</li>
<li class="li">Lambda-001: Lambda Using Latest Runtime Environment: Remove 'dotnet7' and add 'dotnet8'
                  to the default recommended list of latest runtime versions.</li>
<li class="li">Lambda-012: Lambda Using Supported Runtime Environment: Add 'dotnet8' to the list
                  of supported runtime versions. See <a class="xref" href="https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html" target="_blank">AWS documentation - Lambda runtimes</a> for further details.</li>
</ul><div class="p">GCP</div><ul class="ul" id="whatsnew_148_3f0_84c__ul_a31_f83">
<li class="li">CloudVPC-003: Enable VPC Flow Logs for VPC Subnets: Update to exclude non-PRIVATE
                  subnets from being incorrectly evaluated by the rule. VPC Flow Logs cannot be enabled
                  for subnets whose purpose is not PRIVATE.</li>
</ul>]]></description>
    <pubDate>Thu, 08 Feb 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upcoming-rule-updates-for-aws-and</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Rule Updates: Key Rotation and VPC Flow Logs Improvements</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-updates-key-rotation-and-vpc</link>
    <description><![CDATA[<div class="p">February 12, 2024, Conformity—Rule Updates</div><ul class="ul" id="whatsnew_d99_355_c74__ul_079_d6a">
<li class="li">KMS-002: Key Rotation Enabled: Updated the rule to bypass asymmetric keys for having
                  rotation enabled.</li>
<li class="li">CloudVPC-003: Enable VPC Flow Logs for VPC Subnets: Updated the rule to exclude non
                  PRIVATE purpose subnets from being incorrectly evaluated. VPC Flow Logs cannot be
                  enabled for subnets whose purpose is not PRIVATE.</li>
</ul>]]></description>
    <pubDate>Mon, 12 Feb 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-updates-key-rotation-and-vpc</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Container Security Enhances Runtime Security Rule Download for Improved Protection</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-enhances-runtim</link>
    <description><![CDATA[<div class="p">February 20, 2024, Container Security—If you are using Runtime security, you should
               upgrade scout to version 2.3.26 or later to ensure access to future Runtime Security
               rules.</div><div class="p">Container Security's Runtime Security has been updated to allow scout to download
               larger runtime security rule files. You should upgrade clusters that are running scout
               versions older than 2.3.26 to the latest available version to ensure that you have
               access to new runtime security rules as they become available. Older versions of scout
               will continue receiving rules and existing installations will retain their protection,
               but they will not be updated as frequently with new rules due to file size limitations
               that are fixed in newer versions.</div><div class="p">To upgrade Runtime security, upgrade clusters individually via Helm by following instructions
               provided in <a class="xref" href="https://github.com/trendmicro/cloudone-container-security-helm/?tab=readme-ov-file#upgrade-a-trend-micro-cloud-one-container-security-deployment" target="_blank">Upgrade a Trend Micro Cloud One Container Security deployment</a>.</div>]]></description>
    <pubDate>Tue, 20 Feb 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-container-security-enhances-runtim</guid>
    <category>Container Security</category>
</item>
<item>
    <title>Lambda Runtime Updates and Security Group Rule Deprecation</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-runtime-updates-and-securit</link>
    <description><![CDATA[<div class="p">February 26, 2024, Conformity—Rule Updates</div><ul class="ul" id="whatsnew_57e_9da_86f__ul_0a9_0b5">
<li class="li">Lambda-001: Lambda Using Latest Runtime Environment: Removed 'dotnet6' and added 'dotnet8'
                  to the default recommended list of latest runtime versions.</li>
<li class="li">Lambda-009: Enable Encryption at Rest for Environment Variables using Customer Master
                  Keys: Improved the rule logic to generate no check when lambda functions have no environment
                  variable.</li>
<li class="li">Lambda-012: Lambda Using Supported Runtime Environment: Added 'dotnet8' to the list
                  of supported runtime versions. See <a class="xref" href="https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html" target="_blank">AWS documentation - Lambda runtimes</a> for further details.</li>
</ul><div class="p">Rule Deprecation</div><ul class="ul" id="whatsnew_57e_9da_86f__ul_1b4_34c">
<li class="li">EC2-015: EC2 Instance Security Group Rules Counts: The recommendation of limiting
                  security group rules to a certain quota is no longer a best practice. See the <a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/EC2/ec2-instance-security-group-rules-counts.html" target="_blank">knowledge base article</a> for additional context. For more information on rule deprecation, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-rules-#deprecated-rules" target="_blank">here</a>.</li>
</ul>]]></description>
    <pubDate>Mon, 26 Feb 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-runtime-updates-and-securit</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated DynamoDB-005 Rule for Accurate Backup and Restore Detection</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-dynamodb-005-rule-for-accu</link>
    <description><![CDATA[<div class="p">February 27, 2024, Conformity—Rule Update</div><ul class="ul" id="whatsnew_595_e27_4b6__ul_328_af0">
<li class="li">DynamoDB-005: DynamoDB Backup and Restore: Updated the rule to correctly get backups
                  created with both Amazon DynamoDB and AWS Backup.</li>
</ul>]]></description>
    <pubDate>Tue, 27 Feb 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-dynamodb-005-rule-for-accu</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP account permissions for Conformity added</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permissions-for-co</link>
    <description><![CDATA[<div class="p">February 28, 2024, Conformity—Updated GCP account permission list</div><div class="p">We've added the following new GCP account permissions:</div><ul class="ul" id="whatsnew_e33_b62_58e__ul_fae_c47">
<li class="li">`compute.disks.getIamPolicy`</li>
<li class="li">`compute.disks.list`</li>
</ul><div class="p">For a full list of GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">Add a GCP Account</a>.</div>]]></description>
    <pubDate>Wed, 28 Feb 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permissions-for-co</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved uninstallation process removes all Deep Security Agent folders</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-uninstallation-process-re</link>
    <description><![CDATA[<div class="p">February 29, 2024, Workload Security—Uninstalling Deep Security Agent did not remove
               all folders associated with the agent.</div>]]></description>
    <pubDate>Thu, 29 Feb 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-uninstallation-process-re</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity enhances Azure compliance reporting with updated frameworks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhances-azure-complian</link>
    <description><![CDATA[<div class="p">March 05, 2024, Conformity—Standards and Compliance Reports</div><div class="p">The Azure Well-Architected Framework compliance standard report has been updated to
               reflect recent updates to Azure's Well-Architected Framework.</div><div class="p">Considering substantial changes applied to the rule mapping, Conformity now supports
               the following compliance standards:</div><ul class="ul" id="whatsnew_1c8_ab3_6ce__ul_ed6_cb4">
<li class="li">Azure Well-Architected Framework (updated October 2023)</li>
<li class="li">Azure Well-Architected Framework (Deprecated) (updated July 2022)</li>
</ul><div class="p">As of 01 June 2024, the following compliance standards will be deprecated:</div><ul class="ul" id="whatsnew_1c8_ab3_6ce__ul_836_d76">
<li class="li">Azure Well-Architected Framework (Deprecated) (updated July 2022)</li>
</ul><div class="p">This deprecated compliance standard will be no longer be accessible in the filters,
               preventing the creation of new reports or report-configurations with this outdated
               standard. If any existing report configurations include the deprecated compliance
               standard, it will not be possible to generate new PDF/CSV reports. However, the list
               of previously generated PDF/CSV reports remains available. We recommend updating your
               report configurations to use the latest versions of the Azure Well-Architected Framework
               by 01 June 2024.</div>]]></description>
    <pubDate>Tue, 05 Mar 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-enhances-azure-complian</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Lambda VPC setting can now be removed during stack updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-vpc-setting-can-now-be-remo</link>
    <description><![CDATA[<div class="p">March 06, 2024, File Storage Security—Fixed the issue where Lambda VPC setting could
               not be removed in the stack update when the VPC setting-related parameters were empty.</div><div class="p">This requires a stack update.</div>]]></description>
    <pubDate>Wed, 06 Mar 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-lambda-vpc-setting-can-now-be-remo</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>New GCP account permission `compute.vpnGateways.list` added</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permission-compute</link>
    <description><![CDATA[<div class="p">March 13, 2024, Conformity—Updated GCP account permission list</div><div class="p">We've added the following new GCP account permissions:</div><ul class="ul" id="whatsnew_956_ac3_c7b__ul_6b5_2e1">
<li class="li">`compute.vpnGateways.list`</li>
</ul><div class="p">For a full list of GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">Add a GCP Account</a>.</div>]]></description>
    <pubDate>Wed, 13 Mar 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permission-compute</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated rule for Application Insights in Azure App Service</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-for-application-insig</link>
    <description><![CDATA[<div class="p">March 13, 2024, Conformity—Rule Update</div><div class="p">This change may affect your checks and compliance scores:</div><div class="p">Azure</div><div class="p">AppService-016: Enable Application Insights: Updated the rule to handle Application
               Insights configured using either instrumentation keys or connection strings.</div>]]></description>
    <pubDate>Wed, 13 Mar 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-for-application-insig</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Template Scanner now supports Lambda Function, Kinesis Stream, and SNS Topic resources</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-supports-lamb</link>
    <description><![CDATA[<div class="p">March 20, 2024, Conformity—More Terraform resources supported by Template Scanner</div><div class="p">We've supported the following Terraform resources in Template Scanner:</div><ul class="ul" id="whatsnew_8c7_7bf_2ad__ul_53a_661">
<li class="li">Lambda Function</li>
<li class="li">Kinesis Stream</li>
<li class="li">SNS Topic</li>
</ul>]]></description>
    <pubDate>Wed, 20 Mar 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-supports-lamb</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP account permissions added for enhanced network and function management</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permissions-added</link>
    <description><![CDATA[<div class="p">March 20, 2024, Conformity—Updated GCP account permission list</div><div class="p">We've added the following new GCP account permissions:</div><ul class="ul" id="whatsnew_9d5_333_a0b__ul_238_28b">
<li class="li">`networkconnectivity.hubs.list`</li>
<li class="li">`networkconnectivity.hubs.listSpokes`</li>
<li class="li">`cloudfunctions.functions.list`</li>
<li class="li">`cloudfunctions.functions.getIamPolicy`</li>
</ul><div class="p">For a full list of GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">Add a GCP Account</a>.</div>]]></description>
    <pubDate>Wed, 20 Mar 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permissions-added</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Real-Time Monitoring Issue Resolved for AWS Region us-east-1</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-real-time-monitoring-issue-resolve</link>
    <description><![CDATA[<div class="p">March 25, 2024, Conformity—Incident Affecting Real-Time Monitoring for AWS</div><div class="p">From 11:16 UTC 21 March to 01:10 UTC 25 March, Trend Cloud One Conformity did not
               receive Real-Time Monitoring events from the AWS region `us-east-1`. The affected
               events may include critical IAM service events and resource-based events in your AWS
               accounts from `us-east-1`.</div><div class="p">We have resolved the issue and sincerely apologize for the inconvenience this may
               have caused. If you have any more concerns, please feel free to raise a support request.</div>]]></description>
    <pubDate>Mon, 25 Mar 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-real-time-monitoring-issue-resolve</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP Cloud Logging rules updated to accept bucket-based log-based metrics</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-cloud-logging-rules-update</link>
    <description><![CDATA[<div class="p">March 27, 2024, Conformity—Upcoming Rule Update</div><div class="p">These GCP Cloud Logging rules have been updated to accept bucket-based log-based metrics:</div><ul class="ul" id="whatsnew_b18_31c_5a8__ul_70d_4e4">
<li class="li">CloudLogging-001: Enable Monitoring for Bucket Permission Changes</li>
<li class="li">CloudLogging-002: Enable VPC Network Route Changes Monitoring</li>
<li class="li">CloudLogging-003: Enable VPC Network Changes Monitoring</li>
<li class="li">CloudLogging-004: Enable Monitoring for Custom Role Changes</li>
<li class="li">CloudLogging-005: Enable Monitoring for SQL Instance Configuration Changes</li>
<li class="li">CloudLogging-006: Enable Monitoring for Firewall Rule Changes</li>
<li class="li">CloudLogging-007: Enable Monitoring for Audit Configuration Changes</li>
<li class="li">CloudLogging-008: Enable Project Ownership Assignments Monitoring</li>
</ul>]]></description>
    <pubDate>Wed, 27 Mar 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-cloud-logging-rules-update</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Azure Functions Service Bus Extension updated to v5.x for enhanced file storage security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-functions-service-bus-extens</link>
    <description><![CDATA[<div class="p">March 27, 2024, File Storage Security—The Azure Functions Service Bus Extension for
               Azure blob listener and post-scan functions have been updated to v5.x.</div>]]></description>
    <pubDate>Wed, 27 Mar 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-functions-service-bus-extens</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Improved AWS Stack Deployment Compatibility for File Storage Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-stack-deployment-comp</link>
    <description><![CDATA[<div class="p">March 28, 2024, File Storage Security—Fixed the issue where the AWS stacks could not
               be deployed on the File Storage Security console if the stacks were deployed on an
               AWS account where the AWS region's STS of the selected Cloud One region was not activated.</div>]]></description>
    <pubDate>Thu, 28 Mar 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-aws-stack-deployment-comp</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>New Supported Cache Node Types Added to Conformity Rule Settings</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-supported-cache-node-types-add</link>
    <description><![CDATA[<div class="p">April 03, 2024, Conformity—Upcoming Rule Update</div><div class="p">The change will allow you to add new supported cache node types to the rule settings:</div><ul class="ul" id="whatsnew_983_5c6_0d4__ul_847_3d8">
<li class="li">EC-011: ElastiCache Desired Node Type</li>
</ul>]]></description>
    <pubDate>Wed, 03 Apr 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-supported-cache-node-types-add</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated GCP account permission list now includes `compute.targetVpnGateways.list`</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-account-permission-lis</link>
    <description><![CDATA[<div class="p">April 04, 2024, Conformity—Updated GCP account permission list</div><div class="p">We've added the following new GCP account permissions:</div><ul class="ul" id="whatsnew_020_a67_73b__ul_48d_88d">
<li class="li">`compute.targetVpnGateways.list`</li>
</ul><div class="p">For a full list of GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">Add a GCP Account</a>.</div>]]></description>
    <pubDate>Thu, 04 Apr 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-account-permission-lis</guid>
    <category>Conformity</category>
</item>
<item>
    <title>RTM introduces new AWS rules for EKS cluster security and logging</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rtm-introduces-new-aws-rules-for-e</link>
    <description><![CDATA[<div class="p">April 08, 2024, Conformity—RTM for AWS</div><div class="p">RTM now supports the following rules:</div><ul class="ul" id="whatsnew_c35_c32_916__ul_8b0_c08">
<li class="li">EKS-001: EKS Cluster Endpoint Public Access: Ensure that AWS EKS cluster endpoint
                  access isn't public and prone to security risks.</li>
<li class="li">EKS-003: Kubernetes Cluster Logging: Ensure that EKS control plane logging is enabled
                  for your Amazon EKS clusters.</li>
</ul>]]></description>
    <pubDate>Mon, 08 Apr 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rtm-introduces-new-aws-rules-for-e</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AuditEvent Logging now enabled for Azure Key Vaults</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-auditevent-logging-now-enabled-for</link>
    <description><![CDATA[<div class="p">April 11, 2024, Conformity—Bug Fix</div><ul class="ul" id="whatsnew_ed8_725_c99__ul_9d8_ce6">
<li class="li">KeyVault-004: Enable AuditEvent Logging for Azure Key Vaults: Fixed a bug that created
                  failed checks when the audit category group is enabled.</li>
</ul>]]></description>
    <pubDate>Thu, 11 Apr 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-auditevent-logging-now-enabled-for</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Rule Added: Scan ECR Container Images Automatically on Push</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-rule-added-scan-ecr-container</link>
    <description><![CDATA[<div class="p">April 17, 2024, Conformity—RTM for AWS</div><div class="p">Added the following rule to RTM:</div><ul class="ul" id="whatsnew_c24_ef8_a8a__ul_abc_4e4">
<li class="li">ECR-003: Enable Scan on Push for ECR Container Images: This rule ensures that each
                  Amazon ECR container image is automatically scanned for vulnerabilities when pushed
                  to a repository.</li>
</ul>]]></description>
    <pubDate>Wed, 17 Apr 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-rule-added-scan-ecr-container</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Template Scanner now supports Auto Scaling Group, CloudFormation Stack, and SQS Queue</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-template-scanner-now-supp</link>
    <description><![CDATA[<div class="p">April 18, 2024, Conformity—Additional Terraform Resources' support in the Template
               Scanner</div><div class="p">We now support the following Terraform resources in the Template Scanner:</div><ul class="ul" id="whatsnew_d65_58d_dbe__ul_353_32c">
<li class="li">Auto Scaling Group</li>
<li class="li">CloudFormation Stack</li>
<li class="li">SQS Queue</li>
</ul>]]></description>
    <pubDate>Thu, 18 Apr 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-template-scanner-now-supp</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated GCP account permissions for Conformity now include new options</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-account-permissions-fo</link>
    <description><![CDATA[<div class="p">April 22, 2024, Conformity—GCP account permission list updated</div><div class="p">New permissions</div><ul class="ul" id="whatsnew_466_7c2_9d7__ul_cb0_73b">
<li class="li">apigateway.apis.list</li>
<li class="li">apigateway.apis.getIamPolicy</li>
</ul><div class="p">For the full list of required GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">here</a>.</div>]]></description>
    <pubDate>Mon, 22 Apr 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-account-permissions-fo</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated Lambda Runtimes for Improved Performance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-lambda-runtimes-for-improv</link>
    <description><![CDATA[<div class="p">April 23, 2024, Conformity—Rule Updates</div><ul class="ul" id="whatsnew_91c_9e7_a75__ul_fa7_ea6">
<li class="li">Lambda-001: Lambda Using Latest Runtime Environment: Removed 'ruby3.2' and added 'ruby3.3'
                  to the default recommended list of latest runtime versions.</li>
<li class="li">Lambda-012: Lambda Using Supported Runtime Environment: Added 'ruby3.3' to the list
                  of supported runtime versions. See <a class="xref" href="https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html" target="_blank">AWS documentation - Lambda runtimes</a> for further details.</li>
</ul>]]></description>
    <pubDate>Tue, 23 Apr 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-lambda-runtimes-for-improv</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Azure API Management Rules Enhance Security and Performance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-api-management-rules-enh</link>
    <description><![CDATA[<div class="p">April 24, 2024, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_42e_c7c_e3a__ul_88f_952">
<li class="li">APIManagement-001: Enable Built-In Response Caching: This rule ensures that built-in
                  response caching is enabled for Microsoft Azure API Management APIs to reduce latency
                  for API callers and backend load for API providers.</li>
<li class="li">APIManagement-004: Prevent the Exposure of Credentials and Secrets using Encrypted
                  Named Values: This rule ensures that named values are encrypted to prevent the exposure
                  of secrets in Azure API Management.</li>
</ul>]]></description>
    <pubDate>Wed, 24 Apr 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-api-management-rules-enh</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced SUSE Linux Enterprise Server 12 SP5 Support in Deep Security Agent</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-suse-linux-enterprise-ser</link>
    <description><![CDATA[<div class="p">April 24, 2024, Workload Security—Deep Security Agent version 20.0.1-7380 and later
               supports the majority of features for SUSE Linux Enterprise Server 12 SP5 (PowerPC
               little-endian), with the exception of Integrity Monitoring, Application Control, and
               Trend Vision One (XDR).</div>]]></description>
    <pubDate>Wed, 24 Apr 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-suse-linux-enterprise-ser</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Azure API Management now enforces resource logs for enhanced monitoring</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-api-management-now-enforces</link>
    <description><![CDATA[<div class="p">May 02, 2024, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_c15_fd1_d3f__ul_ce6_9c6">
<li class="li">APIManagement-005: Enable Resource Logs: This rule ensures that Azure API Management
                  API services are configured to use resource logs.</li>
</ul>]]></description>
    <pubDate>Thu, 02 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-api-management-now-enforces</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Terraform Template Scanner with ELBv2 Support and Lambda VPC Access Fix</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-terraform-template-scanne</link>
    <description><![CDATA[<div class="p">May 06, 2024, Conformity—Template Scanner Updates</div><ul class="ul" id="whatsnew_e95_734_c94__ul_4e4_093">
<li class="li">Additional Terraform Resources' Support: We now support Terraform resource ELBv2 in
                  the Template Scanner.</li>
<li class="li">Lambda-007: VPC Access for AWS Lambda Functions: Fixed a bug in the Terraform Template
                  Scanner to return correct checks.</li>
</ul>]]></description>
    <pubDate>Mon, 06 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-terraform-template-scanne</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity GCP account permissions updated with new AlloyDB access</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-gcp-account-permissions</link>
    <description><![CDATA[<div class="p">May 06, 2024, Conformity—GCP account permission list updated</div><div class="p">New permissions</div><ul class="ul" id="whatsnew_dca_636_58c__ul_e84_0f5">
<li class="li">alloydb.clusters.list</li>
<li class="li">alloydb.instances.list</li>
</ul><div class="p">For the full list of required GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">here</a>.</div>]]></description>
    <pubDate>Mon, 06 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-gcp-account-permissions</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Azure Custom Role Template Update: Permission Removal for Queue Read Access</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-custom-role-template-update</link>
    <description><![CDATA[<div class="p">May 07, 2024, Conformity—Azure Custom Role Permissions Update</div><div class="p">The Azure permission `Microsoft.Storage/storageAccounts/queueServices/queues/read`
               has been removed from the Custom Role template. For the full list of required Azure
               permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-azure-introduction-and-guide-" target="_blank">here</a>.</div>]]></description>
    <pubDate>Tue, 07 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-custom-role-template-update</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated PCI DSS v4 Standards Report for AWS, Azure, and GCP compliance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-pci-dss-v4-standards-repor</link>
    <description><![CDATA[<div class="p">May 08, 2024, Conformity—Standards and Compliance Reports</div><div class="p">The PCI DSS v4  Standards and Compliance report has been updated to reflect the latest
               rules released for AWS, Azure and GCP.</div>]]></description>
    <pubDate>Wed, 08 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-pci-dss-v4-standards-repor</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Azure API Management now supports HTTP/2 for improved performance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-api-management-now-supports</link>
    <description><![CDATA[<div class="p">May 08, 2024, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_6ec_57d_6dd__ul_eda_edf">
<li class="li">APIManagement-006: Enable Support for HTTP/2: This rule ensures that Azure API Management
                  API gateways are configured to use HTTP/2.</li>
</ul>]]></description>
    <pubDate>Wed, 08 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-api-management-now-supports</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP account permissions for pubsub topics added</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permissions-for-pu</link>
    <description><![CDATA[<div class="p">May 09, 2024, Conformity—Updated GCP account permission list</div><div class="p">We've added the following new GCP account permissions:</div><ul class="ul" id="whatsnew_e9b_14c_b86__ul_f8c_ce9">
<li class="li">pubsub.topics.get</li>
<li class="li">pubsub.topics.getIamPolicy</li>
</ul>]]></description>
    <pubDate>Thu, 09 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permissions-for-pu</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Lambda runtime changes affecting conformity scores</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-lambda-runtime-changes-affecti</link>
    <description><![CDATA[<div class="p">May 13, 2024, Conformity—Upcoming Rule Update</div><div class="p">The following rule updates will be released soon. These changes may affect your checks
               and compliance scores:</div><div class="p">AWS</div><ul class="ul" id="whatsnew_3d8_a76_948__ul_d23_116">
<li class="li">Lambda-001: Lambda Using Latest Runtime Environment: Removed 'dotnet7' from the default
                  recommended list of latest runtime versions.</li>
<li class="li">Lambda-012: Lambda Using Supported Runtime Environment: Removed 'dotnet7' from the
                  list of supported runtime versions. See <a class="xref" href="https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html" target="_blank">AWS documentation - Lambda runtimes</a> for further details.</li>
</ul>]]></description>
    <pubDate>Mon, 13 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-lambda-runtime-changes-affecti</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Apigee API &amp; Account Permissions added for enhanced GCP project management</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-apigee-api--account-permission</link>
    <description><![CDATA[<div class="p">May 13, 2024, Conformity—Updated GCP project APIs &amp; Account Permissions list</div><div class="p">We've added the following new APIs &amp; Account Permissions:</div><ul class="ul" id="whatsnew_303_299_ec0__ul_bb8_d4b">
<li class="li">Apigee API</li>
</ul><div class="p">New permissions:</div><ul class="ul" id="whatsnew_303_299_ec0__ul_84b_5b3">
<li class="li">apigee.apiproducts.list</li>
<li class="li">apigee.deployments.list</li>
<li class="li">apigee.envgroupattachments.list</li>
<li class="li">apigee.envgroups.list</li>
<li class="li">apigee.instanceattachments.list</li>
<li class="li">apigee.instances.list</li>
<li class="li">apigee.proxies.list</li>
<li class="li">apigee.proxyrevisions.list</li>
</ul><div class="p">For the full list of required GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">here</a>.</div>]]></description>
    <pubDate>Mon, 13 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-apigee-api--account-permission</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated GCP account permissions now include spanner and memcache instance access</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-account-permissions-no</link>
    <description><![CDATA[<div class="p">May 20, 2024, Conformity—GCP account permission list updated</div><div class="p">New permissions</div><ul class="ul" id="whatsnew_f5b_246_b20__ul_c9d_8bf">
<li class="li">spanner.instances.getIamPolicy</li>
<li class="li">spanner.instances.list</li>
<li class="li">memcache.instances.list</li>
</ul><div class="p">For the full list of required GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">here</a>.</div>]]></description>
    <pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-account-permissions-no</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Custom Policy Update: New `lambda:GetFunction` Permission Added</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-custom-policy-update-new-lambd</link>
    <description><![CDATA[<div class="p">May 21, 2024, Conformity—AWS Custom Policy Update</div><div class="p">The Conformity AWS Custom Policy has been updated to version 1.49. The new permission
               added is:</div><ul class="ul" id="whatsnew_d13_e2c_000__ul_c44_fc7">
<li class="li">`lambda:GetFunction`</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the latest custom policy.</div><div class="p">For more information, refer to the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-aws-custom-policy" target="_blank">AWS Custom Policy documentation</a>.</div>]]></description>
    <pubDate>Tue, 21 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-custom-policy-update-new-lambd</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Integration with Application Insights for API Gateway APIs</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-integration-with-applicatio</link>
    <description><![CDATA[<div class="p">May 21, 2024, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_cca_244_df6__ul_6b5_d70">
<li class="li">APIManagement-003: Enable Integration with Application Insights: This rule ensures
                  that API Gateway APIs are integrated with application insights for diagnostic logging.</li>
</ul>]]></description>
    <pubDate>Tue, 21 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-integration-with-applicatio</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity now available in AWS ca-west-1 and il-central-1 regions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-now-available-in-aws-ca</link>
    <description><![CDATA[<div class="p">May 23, 2024, Conformity—New Region</div><div class="p">AWS</div><ul class="ul" id="whatsnew_023_783_b35__ul_3b1_91e">
<li class="li">The new AWS region ca-west-1 and il-central-1 is enabled for Conformity.</li>
</ul>]]></description>
    <pubDate>Thu, 23 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-now-available-in-aws-ca</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enforce HTTPS for Azure API Management APIs</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enforce-https-for-azure-api-manage</link>
    <description><![CDATA[<div class="p">May 26, 2024, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_b2d_963_660__ul_933_730">
<li class="li">APIManagement-002: Enforce HTTPS: This rule ensures that Azure API Management APIs
                  are using HTTPS.</li>
</ul>]]></description>
    <pubDate>Sun, 26 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enforce-https-for-azure-api-manage</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Trusted Launch for Azure Virtual Machines with New Rule Azure VirtualMachines-040</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-trusted-launch-for-azure-vi</link>
    <description><![CDATA[<div class="p">May 30, 2024, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_b6c_217_740__ul_b44_6e1">
<li class="li">VirtualMachines-040: Enable Trusted Launch for Virtual Machines: This rule ensures
                  that all Azure Virtual Machines are using the Trusted Launch security feature.</li>
</ul>]]></description>
    <pubDate>Thu, 30 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-trusted-launch-for-azure-vi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Removed unused permission &#x27;apigee.proxyrevisions.list&#x27; from GCP account permission list</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-removed-unused-permission-apigeepr</link>
    <description><![CDATA[<div class="p">May 30, 2024, Conformity—GCP account permission list updated</div><div class="p">Removed the following unused permission:</div><ul class="ul" id="whatsnew_2ad_6bb_d49__ul_2d5_cde">
<li class="li">apigee.proxyrevisions.list</li>
</ul><div class="p">For the full list of required GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">here</a>.</div>]]></description>
    <pubDate>Thu, 30 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-removed-unused-permission-apigeepr</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated Azure Rule: Microsoft Defender Standard Pricing Tier now excludes deprecated KubernetesService</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-azure-rule-microsoft-defen</link>
    <description><![CDATA[<div class="p">May 30, 2024, Conformity—Rule Update</div><div class="p">Azure</div><ul class="ul" id="whatsnew_d7f_079_e0c__ul_b54_524">
<li class="li">SecurityCenter-001: Enable Microsoft Defender Standard Pricing Tier: This rule has
                  been updated not to check a deprecated KubernetesService.</li>
</ul>]]></description>
    <pubDate>Thu, 30 May 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-azure-rule-microsoft-defen</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Template Scanner now accurately detects Cluster Deletion Protection settings in CloudFormation</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-accurately-de</link>
    <description><![CDATA[<div class="p">June 03, 2024, Conformity—Template Scanner Updates</div><ul class="ul" id="whatsnew_ac4_19b_f0e__ul_c95_f37">
<li class="li">RDS-035: Cluster Deletion Protection: Fixed a bug where Template Scanner indicated
                  that DeletionProtection was not enabled incorrectly. Template Scanner will now correctly
                  return `SUCCESS` for `RDS-035` if `DeletionProtection` is set to `true` in CloudFormation.</li>
</ul>]]></description>
    <pubDate>Mon, 03 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-accurately-de</guid>
    <category>Conformity</category>
</item>
<item>
    <title>CloudSQL now supports SSL/TLS for incoming connections</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloudsql-now-supports-ssltls-for-i</link>
    <description><![CDATA[<div class="p">June 03, 2024, Conformity—Bug Fix</div><div class="p">GCP</div><div class="p">CloudSQL-004: Enable SSL/TLS for Cloud SQL Incoming Connections:</div><div class="p">Fixed a bug where the rule generated false positive checks while CloudSQL instance
               is configured correctly to only allow SSL connections.</div>]]></description>
    <pubDate>Mon, 03 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloudsql-now-supports-ssltls-for-i</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Deprecation of Azure Well-Architected Framework in Compliance Reports</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deprecation-of-azure-well-architec</link>
    <description><![CDATA[<div class="p">June 03, 2024, Conformity—Standards and Compliance Reports</div><div class="p">Following up on previous notification (05 March 2024), as of 03 June 2024, the following
               compliance standard have been deprecated:</div><ul class="ul" id="whatsnew_f70_981_7c3__ul_599_a1f">
<li class="li">Azure Well-Architected Framework (Deprecated) (updated July 2022)</li>
</ul><div class="p">This compliance standard is no longer accessible in the filters, preventing the creation
               of new reports or report-configurations with this outdated standard. If any existing
               report configurations include the deprecated compliance standard, it will not be possible
               to generate new PDF/CSV reports. However, the list of previously generated PDF/CSV
               reports remains available. We recommend updating your report configurations to use
               the latest version of the Azure Well-Architected Framework.</div>]]></description>
    <pubDate>Mon, 03 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deprecation-of-azure-well-architec</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated AWS account permissions now include wafv2:GetWebACL</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-account-permissions-no</link>
    <description><![CDATA[<div class="p">June 04, 2024, Conformity—AWS account permission list updated</div><div class="p">Added the following permission:</div><ul class="ul" id="whatsnew_4ab_77a_d03__ul_204_f12">
<li class="li">wafv2:GetWebACL</li>
</ul>]]></description>
    <pubDate>Tue, 04 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-account-permissions-no</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Filter Checks and Download Compliance Reports for AWS, Azure, and GCP environments</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-filter-checks-and-download-complia</link>
    <description><![CDATA[<div class="p">June 04, 2024, Conformity—Standards and Compliance Reports</div><div class="p">You can now filter Checks and download Compliance Reports to ensure your AWS, Azure
               and GCP cloud environments comply with the following standards:</div><ul class="ul" id="whatsnew_876_61c_286__ul_dd1_3c7">
<li class="li">NIST Cybersecurity Framework v2.0</li>
</ul>]]></description>
    <pubDate>Tue, 04 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-filter-checks-and-download-complia</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Upgrade to Python Lambda runtime version 3.12 for improved AWS account templates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upgrade-to-python-lambda-runtime-v</link>
    <description><![CDATA[<div class="p">June 05, 2024, Cloud Account Management—Python Lambda runtime has been upgraded from
               version 3.8 to 3.12. You need to update your connected AWS accounts with the most
               recent template.</div>]]></description>
    <pubDate>Wed, 05 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upgrade-to-python-lambda-runtime-v</guid>
    <category>Cloud Account Management</category>
</item>
<item>
    <title>Upcoming AWS Lambda Rule Update: Removal of &#x27;nodejs16.x&#x27; Runtime Version</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upcoming-aws-lambda-rule-update-re</link>
    <description><![CDATA[<div class="p">June 12, 2024, Conformity—Upcoming Rule Update</div><div class="p">The following rule update will be released soon. These changes may affect your checks
               and compliance scores:</div><div class="p">AWS</div><ul class="ul" id="whatsnew_f63_2c3_51b__ul_b90_bbd">
<li class="li">Lambda-012: Lambda Using Supported Runtime Environment: Removed 'nodejs16.x' from
                  the list of supported runtime versions. See <a class="xref" href="https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html" target="_blank">AWS documentation - Lambda runtimes</a> for further details.</li>
</ul>]]></description>
    <pubDate>Wed, 12 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upcoming-aws-lambda-rule-update-re</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved CSV and PDF report generation with fixed user filter display issues</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-csv-and-pdf-report-genera</link>
    <description><![CDATA[<div class="p">June 17, 2024, Conformity—Bug Fixes</div><ul class="ul" id="whatsnew_a7b_8d7_883__ul_b52_08d">
<li class="li">CSV Reports:</li>
<li class="li">Fixed a bug in generated CSV reports where values for user selected filters for 'Region',
                  'Providers' and 'Risk Levels' were not displayed in the same format as the values
                  of the respective data columns of the report.</li>
<li class="li">Fixed a bug in generated CSV reports where user selected filters for 'Standards &amp;
                  Frameworks controls' were not displayed.</li>
<li class="li">PDF Reports:</li>
<li class="li">Fixed a bug in generated PDF reports where user selected filters for 'Rules' were
                  not displayed.</li>
<li class="li">Fixed a bug in generated PDF reports where user selected filters for 'Categories'
                  and 'Risk Levels' were not displayed in the same format as they appear in the 'List
                  of Performed Checks'.</li>
</ul>]]></description>
    <pubDate>Mon, 17 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-csv-and-pdf-report-genera</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Fixed issue with Terraform Template Scanner for scanning plans with only modules</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-issue-with-terraform-templat</link>
    <description><![CDATA[<div class="p">June 18, 2024, Conformity—Bug Fixes</div><ul class="ul" id="whatsnew_902_44f_610__ul_616_b31">
<li class="li">Template Scanner:</li>
</ul><div class="p">Fixed an issue with Terraform Template Scanner where attempting to scan plans which
               contained only modules and no resources produced an error.</div>]]></description>
    <pubDate>Tue, 18 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-issue-with-terraform-templat</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity RTM Update: Google Cloud Platform Runtime Changes for Node.js 16</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-rtm-update-google-cloud</link>
    <description><![CDATA[<div class="p">June 18, 2024, Conformity—Cloud Functions Runtime Changes for Google Cloud Platform
               (GCP) RTM</div><div class="p">The current Cloud Functions runtime version used for Conformity RTM is Node.js 16
               and will be decommissioned by Google Cloud on 30 January 2025. This change will affect
               Conformity GCP Real Time Monitoring (RTM) configurations but does not immediately
               affect the existing Conformity customers.</div><div class="p">We have updated the GCP Real-Time Monitoring installation template to use the latest
               1st generation Runtime version.</div><div class="p">Please follow the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-real-time-threat-monitoring-settings-#rtm-for-gcp" target="_blank">Real-time Monitoring Settings &gt; RTM for GCP</a> to install RTM for GCP again to upgrade the existing configuration before 30 January
               2025.</div>]]></description>
    <pubDate>Tue, 18 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-rtm-update-google-cloud</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Bug Fix for SSM Managed Instances Check in AWS Conformity</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-ssm-managed-instances</link>
    <description><![CDATA[<div class="p">June 19, 2024, Conformity—Rule Update</div><div class="p">AWS</div><div class="p">SSM-003: Check for SSM Managed Instances:</div><div class="p">Fixed a bug that generated false negative checks for a recently created instance despite
               being correctly managed by the AWS Systems Manager.</div>]]></description>
    <pubDate>Wed, 19 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-bug-fix-for-ssm-managed-instances</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Azure API Management rule enforces secure TLS version configuration for API gateways</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-api-management-rule-enfo</link>
    <description><![CDATA[<div class="p">June 20, 2024, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_64e_7de_916__ul_187_d2d">
<li class="li">APIManagement-007: Check the TLS Version Configured for API Gateways: This rule ensures
                  that Azure API Management API gateways are not configured to use weak and deprecated
                  TLS protocols.</li>
</ul>]]></description>
    <pubDate>Thu, 20 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-api-management-rule-enfo</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity Terraform Template Scanner now available with Cloud Formation resources</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-terraform-template-scan</link>
    <description><![CDATA[<div class="p">June 24, 2024, Conformity—Terraform Template Scanner support for Cloud Formation Template
               Scanner Resources now Generally Available </div><div class="p">Conformity Terraform Template Scanner is now Generally Available with parity of coverage
               of the following Cloud Formation Template Scanner resource types:</div><ul class="ul" id="whatsnew_3a4_6a8_b84__ul_0b4_90b">
<li class="li">Autoscaling Group</li>
<li class="li">CF Stack</li>
<li class="li">CloudTrail</li>
<li class="li">Kinesis Stream</li>
<li class="li">Lambda Function</li>
<li class="li">SNS Topic</li>
<li class="li">SQS Queue</li>
<li class="li">API Gateway RestAPI</li>
<li class="li">ELBv2</li>
<li class="li">ES Domain</li>
<li class="li">Workspaces</li>
<li class="li">ELB Classic</li>
<li class="li">Redshift Cluster</li>
<li class="li">EMR Cluster</li>
<li class="li">ElacticCache</li>
<li class="li">EFS File System</li>
</ul>]]></description>
    <pubDate>Mon, 24 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-terraform-template-scan</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable MFA for Azure VM privileged identities for enhanced security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-mfa-for-azure-vm-privileged</link>
    <description><![CDATA[<div class="p">June 24, 2024, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_9a5_bfd_3c7__ul_db3_100">
<li class="li">VirtualMachines-041: Enable MFA for Privileged Identities with Access to Virtual Machines:
                  Ensure that only MFA-enabled identities can access your Azure virtual machine (VM)
                  instances.</li>
</ul>]]></description>
    <pubDate>Mon, 24 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-mfa-for-azure-vm-privileged</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Template Scanner now supports scanning provider-level tags in Terraform AWS provider block</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-supports-scan</link>
    <description><![CDATA[<div class="p">June 26, 2024, Conformity—Template Scanner Updates</div><div class="p">Template Scanner now supports scanning provider-level tags in Terraform AWS provider
               configuration block.</div>]]></description>
    <pubDate>Wed, 26 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-supports-scan</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Red Hat Enterprise Linux 8.6 (PowerPC) Support Added in Deep Security Agent 20</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-red-hat-enterprise-linux-86-powerp</link>
    <description><![CDATA[<div class="p">June 26, 2024, Workload Security—Deep Security Agent version 20.0.1-12510 (20 LTS
               Update 2024-06-26) and later supports Red Hat Enterprise Linux 8.6 (PowerPC little-endian).</div>]]></description>
    <pubDate>Wed, 26 Jun 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-red-hat-enterprise-linux-86-powerp</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Updated validation logic for RDS Publicly Accessible security groups</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-validation-logic-for-rds-p</link>
    <description><![CDATA[<div class="p">July 01, 2024, Conformity—Bug Fix</div><div class="p">AWS</div><div class="p">RDS-008: RDS Publicly Accessible: Updated the rule logic to validate the security
               groups correctly.</div>]]></description>
    <pubDate>Mon, 01 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-validation-logic-for-rds-p</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated GCP account permissions feature new apigee.proxyrevisions.get permission</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-account-permissions-fe</link>
    <description><![CDATA[<div class="p">July 01, 2024, Conformity—GCP account permission list updated</div><div class="p">New permissions</div><ul class="ul" id="whatsnew_b06_61f_d9d__ul_929_deb">
<li class="li">apigee.proxyrevisions.get</li>
</ul><div class="p">For the full list of required GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">here</a>.</div>]]></description>
    <pubDate>Mon, 01 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-account-permissions-fe</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Webhook Communication with Static IP Allow-listing</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-webhook-communication-wit</link>
    <description><![CDATA[<div class="p">July 02, 2024, Conformity—Communication Channels Update</div><div class="p">Webhook Communication: You can now allow-list static IP addresses used by Webhook
               communication channel to ensure reliable connection from Conformity to your webhook
               endpoint. See <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-webhook-communication-#conformity-ip-addresses" target="_blank">Conformity IP addresses</a> for more details.</div>]]></description>
    <pubDate>Tue, 02 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-webhook-communication-wit</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Template Scanner now supports additional AWS S3 Terraform resources</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-supports-addi</link>
    <description><![CDATA[<div class="p">July 02, 2024, Conformity—Template Scanner Updates</div><div class="p">Template Scanner now supports `aws_s3_bucket_versioning`, `aws_s3_bucket_acl` and
               `aws_s3_bucket_logging` Terraform resources.</div>]]></description>
    <pubDate>Tue, 02 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-supports-addi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP permissions added for account permission list</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-permissions-added-for-acco</link>
    <description><![CDATA[<div class="p">July 03, 2024, Conformity—GCP account permission list updated</div><div class="p">New permissions</div><ul class="ul" id="whatsnew_77e_430_615__ul_19f_37b">
<li class="li">`bigtable.instances.list`</li>
<li class="li">`bigtable.clusters.list`</li>
<li class="li">`bigtable.instances.getIamPolicy`</li>
</ul><div class="p">For a full list of GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">Add a GCP Account</a>.</div>]]></description>
    <pubDate>Wed, 03 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-permissions-added-for-acco</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP Rule for PostgreSQL Database Instances: Configure &quot;log_statement&quot; Flag for Compliance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rule-for-postgresql-databa</link>
    <description><![CDATA[<div class="p">July 08, 2024, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_a8c_d03_878__ul_8c2_94b">
<li class="li">CloudSQL-032:Configure "log_statement" Flag for PostgreSQL Database Instances: This
                  rule ensures that PostgreSQL database instances have the appropriate configuration
                  set for the 'log_statement' flag.</li>
</ul>]]></description>
    <pubDate>Mon, 08 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rule-for-postgresql-databa</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Custom Policy Updated to Version 1.53 with Permissions Removal</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-custom-policy-updated-to-versi</link>
    <description><![CDATA[<div class="p">July 11, 2024, Conformity—AWS Custom Policy Update</div><div class="p">The Conformity AWS Custom Policy has been updated to version 1.53. The following permissions
               are removed:</div><ul class="ul" id="whatsnew_fd6_bbe_627__ul_ac9_fb2">
<li class="li">`iam:GenerateServiceLastAccessedDetails`</li>
<li class="li">`iam:GetServiceLastAccessedDetails`</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the latest custom policy.</div><div class="p">For more information, refer to the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-aws-custom-policy" target="_blank">AWS Custom Policy documentation</a>.</div>]]></description>
    <pubDate>Thu, 11 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-custom-policy-updated-to-versi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Maintenance Scheduled for Trend Cloud One in US and Germany Regions on July 20, 2024</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-maintenance-scheduled-for-trend-cl</link>
    <description><![CDATA[<div class="p">July 12, 2024, General—System maintenance for Trend Cloud One is scheduled for US
               region (us-1) and Germany region (de-1) between 03:00 and 10:00 UTC on Saturday, July
               20, 2024. During this maintenance period, console and API access for some Trend Cloud
               One services will be unavailable. For more information or to be notified of scheduled
               maintenance, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-maintenance-schedule#Trend_Cloud_One_maintenance">Trend Cloud One maintenance</a>.</div>]]></description>
    <pubDate>Fri, 12 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-maintenance-scheduled-for-trend-cl</guid>
    <category>General</category>
</item>
<item>
    <title>Improved handling of API timeouts for Azure Sql-007 Threat Detection Types</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-handling-of-api-timeouts</link>
    <description><![CDATA[<div class="p">July 15, 2024, Conformity—Upcoming Rule Update</div><div class="p">Azure</div><div class="p">Sql-007: Enable All Threat Detection Types: Improved this rule to smoothly handle
               API timeout.</div>]]></description>
    <pubDate>Mon, 15 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-handling-of-api-timeouts</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Template Scanner now supports new Terraform resources for AWS configurations</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-supports-new</link>
    <description><![CDATA[<div class="p">July 17, 2024, Conformity—Template Scanner Updates</div><div class="p">Template Scanner now supports the following Terraform resources.</div><ul class="ul" id="whatsnew_e29_fc1_ce6__ul_a04_824">
<li class="li">`aws_rds_cluster_instance`</li>
<li class="li">`aws_security_group`</li>
<li class="li">`aws_vpc_security_group_ingress_rule`</li>
</ul>]]></description>
    <pubDate>Wed, 17 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-supports-new</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Deep Security Agent now displays most recent component update date</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-now-displays-m</link>
    <description><![CDATA[<div class="p">July 17, 2024, Workload Security—Deep Security Agent shows the date for the most recent
               component update.</div>]]></description>
    <pubDate>Wed, 17 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-now-displays-m</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Agent testing connection to management server for enhanced security maintenance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-testing-connection-to-manage</link>
    <description><![CDATA[<div class="p">July 17, 2024, Workload Security—Deep Security Agent can test the connection to the
               management server.</div>]]></description>
    <pubDate>Wed, 17 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-testing-connection-to-manage</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Customize malware detection messages in Deep Security console</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-customize-malware-detection-messag</link>
    <description><![CDATA[<div class="p">July 17, 2024, Workload Security—Deep Security can show customized malware detection
               messages. Set up custom messages in the management console (Administration &gt; System
               Settings &gt; Agents &gt; Agent Notification).</div>]]></description>
    <pubDate>Wed, 17 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-customize-malware-detection-messag</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>File Storage Security now supports Calgary region on AWS</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-supports</link>
    <description><![CDATA[<div class="p">July 19, 2024, File Storage Security—File Storage Security now supports the Calgary
               (ca-west-1) region on AWS. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security-supported-aws" target="_blank">What's supported in AWS</a>.</div>]]></description>
    <pubDate>Fri, 19 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-file-storage-security-now-supports</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>SUSE Linux Enterprise Server 15 Arm v8 support added in Deep Security Agent</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-suse-linux-enterprise-server-15-ar</link>
    <description><![CDATA[<div class="p">July 20, 2024, Workload Security—Deep Security Agent version 20.0.1-14610 (20 LTS
               Update 2024-07-20) and later supports SUSE Linux Enterprise Server 15 for Arm v8.
               This requires Deep Security Manager version 20.0.935 or later.</div>]]></description>
    <pubDate>Sat, 20 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-suse-linux-enterprise-server-15-ar</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Updated Replay API endpoint now supports replaying checks for account with org-level setting</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-replay-api-endpoint-now-su</link>
    <description><![CDATA[<ul class="ul" id="whatsnew_54c_304_2df__ul_b1b_961">
<li class="li">Updated the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Checks#paths-~1checks~1communication~1replay-post" target="_blank">Replay</a> API endpoint to support replaying checks for an account using organisation-level
                  communication setting.</li>
</ul>]]></description>
    <pubDate>Mon, 22 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-replay-api-endpoint-now-su</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated encryption validation for GKE clusters&#x27; application-layer secrets</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-encryption-validation-for</link>
    <description><![CDATA[<div class="p">July 30, 2024, Conformity—Bug Fix</div><div class="p">GCP</div><div class="p">GKE-002: Enable Encryption for Application-Layer Secrets for GKE Clusters: Updated
               the rule logic to validate the Application-layer secrets encryption correctly.</div>]]></description>
    <pubDate>Tue, 30 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-encryption-validation-for</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Azure Machine Learning Workspaces now require High Business Impact for sensitive data</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-machine-learning-workspaces</link>
    <description><![CDATA[<div class="p">July 30, 2024, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_b25_eb8_65b__ul_05a_a29">
<li class="li">MachineLearning-001: Enable High Business Impact for Machine Learning Workspaces:
                  This rule ensures that High Business Impact (HBI) feature is enabled for Azure Machine
                  Learning (ML) workspaces with sensitive data to limit the data collection by Microsoft
                  Azure for diagnostic purposes.</li>
</ul>]]></description>
    <pubDate>Tue, 30 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-machine-learning-workspaces</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated Azure AppService rule to validate incoming client certificates correctly</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-azure-appservice-rule-to-v</link>
    <description><![CDATA[<div class="p">July 31, 2024, Conformity—Bug Fix</div><div class="p">Azure</div><div class="p">AppService-008: Check that the Azure App requests incoming client certificates: Updated
               the rule logic to validate the configuration of incoming client cetrificates correctly.</div>]]></description>
    <pubDate>Wed, 31 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-azure-appservice-rule-to-v</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated Rule Mapping in CIS Azure Benchmarks for Immutable Blob Storage</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-mapping-in-cis-azure</link>
    <description><![CDATA[<div class="p">July 31, 2024, Conformity—Standards and Frameworks</div><div class="p">We have updated the rule mapping by removing rule StorageAccounts-012:Enable Immutable
               Blob Storage from control 3.12 of the following standards:</div><ul class="ul" id="whatsnew_401_3f9_db5__ul_f65_af1">
<li class="li">CIS Microsoft Azure Foundations Benchmark v1.5.0</li>
<li class="li">CIS Microsoft Azure Foundations Benchmark v2.0.0</li>
</ul>]]></description>
    <pubDate>Wed, 31 Jul 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-mapping-in-cis-azure</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Amazon Bedrock guardrails now protect agent sessions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-amazon-bedrock-guardrails-now-prot</link>
    <description><![CDATA[<div class="p">August 01, 2024, Conformity—New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_005_4bc_f06__ul_0bb_b38">
<li class="li">Bedrock-002: Use Guardrails to Protect Agent Sessions: This rule ensures that your
                  Amazon Bedrock guardrails are protecting agent sessions.</li>
</ul>]]></description>
    <pubDate>Thu, 01 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-amazon-bedrock-guardrails-now-prot</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Use Customer-Managed Keys to Encrypt Amazon Bedrock Guardrails in AWS</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-use-customer-managed-keys-to-encry</link>
    <description><![CDATA[<div class="p">August 01, 2024, Conformity—New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_c9e_2d5_7f7__ul_045_9ba">
<li class="li">Bedrock-003: Use Customer-Managed Keys to Encrypt Amazon Bedrock Guardrails: This
                  rule ensures that your Amazon Bedrock guardrails are encrypted with Amazon KMS Customer
                  Managed Keys (CMKs) instead of AWS managed keys.</li>
</ul>]]></description>
    <pubDate>Thu, 01 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-use-customer-managed-keys-to-encry</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Defender for APIs in Azure API Management Services</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-defender-for-apis-in-azure</link>
    <description><![CDATA[<div class="p">August 07, 2024, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_76d_7c2_87e__ul_215_bca">
<li class="li">SecurityCenter-042: Enable Defender for APIs: This rule ensures that Defender for
                  APIs, a feature of Microsoft Defender for Cloud, is enabled for your Azure API Management
                  services.</li>
</ul>]]></description>
    <pubDate>Wed, 07 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-defender-for-apis-in-azure</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Azure Rules for Enhanced Data Security and Compliance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-rules-for-enhanced-data</link>
    <description><![CDATA[<div class="p">August 08, 2024, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_60e_0a0_8c3__ul_a2e_ee7">
<li class="li">MachineLearning-004: Machine Learning Workspace Encryption using Customer-Managed
                  Keys: This rule ensures that Azure Machine Learning workspaces are using Customer
                  Managed Keys (CMKs) for encryption.</li>
<li class="li">AIServices-001: Use Private Endpoints for OpenAI Service Instances: This rule ensures
                  that network access to OpenAI service instances is allowed via private endpoints only.</li>
<li class="li">AIServices-005: OpenAI Encryption using Customer-Managed Keys: This rule ensures that
                  Azure OpenAI service instances are using Customer-Managed Keys (CMKs) for encryption.</li>
</ul>]]></description>
    <pubDate>Thu, 08 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-rules-for-enhanced-data</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New &quot;logging.logEntries.list&quot; permission added to GCP account permission list</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-logginglogentrieslist-permissi</link>
    <description><![CDATA[<div class="p">August 09, 2024, Conformity—GCP account permission list updated</div><div class="p">New permission "logging.logEntries.list" is added. For the full list of required GCP
               permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">here</a>.</div>]]></description>
    <pubDate>Fri, 09 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-logginglogentrieslist-permissi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Managed Virtual Network Isolation with Internet Outbound Access in Azure Machine Learning</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-managed-virtual-network-iso</link>
    <description><![CDATA[<div class="p">August 12, 2024, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_f91_322_319__ul_aab_9a6">
<li class="li">MachineLearning-005: Enable Managed Virtual Network Isolation with Internet Outbound
                  Access: This rule ensures that managed virtual network (managed VNet) isolation with
                  Internet outbound is enabled.</li>
</ul>]]></description>
    <pubDate>Mon, 12 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-managed-virtual-network-iso</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Security with Public Network Access Disabled for Azure OpenAI Instances</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-with-public-netw</link>
    <description><![CDATA[<div class="p">August 12, 2024, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_eae_9c9_16d__ul_668_5d4">
<li class="li">AIServices-002: Disable Public Network Access to OpenAI Service Instances: This rule
                  ensures that public network access (i.e. all network access) to Microsoft Azure OpenAI
                  service instances is disabled in order to enhance security by preventing unauthorized
                  access.</li>
</ul>]]></description>
    <pubDate>Mon, 12 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-with-public-netw</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated Compliance Reports with CIS Azure Benchmarks v2.1.0 Available Now</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-compliance-reports-with-ci</link>
    <description><![CDATA[<div class="p">August 12, 2024, Conformity—Standards and Compliance Reports</div><div class="p">We've updated our compliance standards to meet the Center of Internet Security (CIS)
               Foundations Benchmarks for Azure. You can now filter Checks and download Compliance
               Reports to ensure your cloud environment complies with the latest CIS Foundations
               Benchmarks.</div><ul class="ul" id="whatsnew_be2_156_fdf__ul_d90_5b5">
<li class="li">CIS Microsoft Azure Foundations Benchmark v2.1.0</li>
</ul><div class="p">You can view the CIS certifications awarded to Trend Micro Cloud One - Conformity
               on the <a class="xref" href="https://www.cisecurity.org/partner/trend-micro" target="_blank">CIS partner website</a> and find out more about <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-compliance-and-conformity-" target="_blank">Compliance and Conformity</a> in our documentation.</div><div class="p">As of 04 November 2024, the following compliance standard will be deprecated:</div><ul class="ul" id="whatsnew_be2_156_fdf__ul_b4a_2a9">
<li class="li">CIS Microsoft Azure Foundations Benchmark v1.5.0</li>
</ul><div class="p">This deprecated compliance standard will no longer be accessible in the filters, preventing
               the creation of new reports or report-configurations with this outdated standard.
               If any existing report configurations include the deprecated compliance standard,
               it will not be possible to generate new PDF/CSV reports. However, the list of previously
               generated PDF/CSV reports remains available. We recommend updating your report configurations
               to use the latest versions of the CIS Microsoft Azure Foundations Benchmark by 04
               November 2024.</div>]]></description>
    <pubDate>Mon, 12 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-compliance-reports-with-ci</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Security with Customer-Managed Keys in Amazon Bedrock</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-with-customer-ma</link>
    <description><![CDATA[<div class="p">August 12, 2024, Conformity—New Rules</div><div class="p">AWS</div><ul class="ul" id="whatsnew_f83_c35_0cb__ul_448_f6e">
<li class="li">Bedrock-001: Use Customer-Managed Keys to Encrypt Agent Sessions: This rule ensures
                  that your Amazon Bedrock agent session data are encrypted with Amazon KMS Customer
                  Managed Keys (CMKs) instead of AWS managed keys.</li>
<li class="li">Bedrock-004: Use Customer-Managed Keys to Encrypt Custom Models: This rule snsures
                  that your Amazon Bedrock custom models are encrypted with Amazon KMS Customer-Managed
                  Keys (CMKs) instead of AWS-managed keys.</li>
<li class="li">Bedrock-005: Use Customer-Managed Keys to Encrypt Knowledge Base Transient Data: This
                  rule ensures that your Amazon Bedrock knowledge base transient data are encrypted
                  with Amazon KMS Customer Managed Keys (CMKs) instead of AWS managed keys.</li>
<li class="li">Bedrock-006: Use Customer-Managed Keys to Encrypt Amazon Bedrock Studio Workspaces:
                  This rule ensures that Bedrock Studio workspaces are encrypted with Amazon KMS Customer
                  Managed Keys (CMKs).</li>
</ul>]]></description>
    <pubDate>Mon, 12 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-with-customer-ma</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Diagnostic Logs Enabled for Azure OpenAI Service Instances</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-diagnostic-logs-enabled-for-azure</link>
    <description><![CDATA[<div class="p">August 13, 2024, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_c23_c46_527__ul_79f_88d">
<li class="li">AIServices-003: Enable Diagnostic Logs for OpenAI Service Instances: This rule ensures
                  that Diagnostic Logs are enabled for your Azure OpenAI service instances.</li>
</ul>]]></description>
    <pubDate>Tue, 13 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-diagnostic-logs-enabled-for-azure</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated AWS Custom Policy with New Permissions Available</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-with-new</link>
    <description><![CDATA[<div class="p">August 13, 2024, Conformity—AWS Custom Policy Update</div><div class="p">The Conformity AWS custom policy has been updated. The new custom policy version is
               1.56 and the permissions added are:</div><ul class="ul" id="whatsnew_ff3_ce6_6a5__ul_266_c96">
<li class="li">ec2:DescribeVpcEndpointConnections</li>
<li class="li">ec2:DescribeVpcEndpointServices</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Tue, 13 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-with-new</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Azure OpenAI Service Instances now required to use Managed Identities</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-openai-service-instances-now</link>
    <description><![CDATA[<div class="p">August 14, 2024, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_65c_b5f_4ac__ul_630_9aa">
<li class="li">AIServices-004: Use Managed Identities for OpenAI Service Instances: This rule ensures
                  that Azure OpenAI service instances are using managed identities.</li>
</ul>]]></description>
    <pubDate>Wed, 14 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-openai-service-instances-now</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Custom Policy Updated with New Permissions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-custom-policy-updated-with-new</link>
    <description><![CDATA[<div class="p">August 14, 2024, Conformity—AWS Custom Policy Update</div><div class="p">The Conformity AWS custom policy has been updated. The new custom policy version is
               1.58 and the permissions added are:</div><ul class="ul" id="whatsnew_65c_01b_3d3__ul_ed6_6c8">
<li class="li">bedrock:ListKnowledgeBases</li>
<li class="li">bedrock:GetKnowledgeBases</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Wed, 14 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-custom-policy-updated-with-new</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Rule Update for AWS VPC Endpoint Cross Account Access Check Generation</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-update-for-aws-vpc-endpoint-c</link>
    <description><![CDATA[<div class="p">August 15, 2024, Conformity—Rule Update</div><div class="p">AWS</div><ul class="ul" id="whatsnew_ccf_c1a_cc8__ul_e3f_5b3">
<li class="li">VPC-006: VPC Endpoint Cross Account Access: Update the rule to generate checks correctly.</li>
</ul>]]></description>
    <pubDate>Thu, 15 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rule-update-for-aws-vpc-endpoint-c</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP account permission added: notebooks.instances.getIamPolicy</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permission-added-n</link>
    <description><![CDATA[<div class="p">August 15, 2024, Conformity—Updated GCP account permission list</div><div class="p">We've added the following new GCP account permission:</div><ul class="ul" id="whatsnew_b71_cc4_f81__ul_62a_22c">
<li class="li">`notebooks.instances.getIamPolicy`</li>
</ul><div class="p">For a full list of GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">Add a GCP Account</a>.</div>]]></description>
    <pubDate>Thu, 15 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permission-added-n</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity now allows customization of Idle days for AWS EBS volumes</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-now-allows-customizatio</link>
    <description><![CDATA[<div class="p">August 15, 2024, Conformity—Rule Update</div><div class="p">AWS</div><ul class="ul" id="whatsnew_1c0_55e_be5__ul_978_530">
<li class="li">EBS-008: Idle EBS Volume: Updated the rule to make Idle days for EBS volumes configurable
                  via a new parameter in the rule settings, allowing customization based on specific
                  requirements.</li>
</ul>]]></description>
    <pubDate>Thu, 15 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-now-allows-customizatio</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Google Cloud Vertex AI offers encryption with Customer-Managed Encryption Keys</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-google-cloud-vertex-ai-offers-encr</link>
    <description><![CDATA[<div class="p">August 20, 2024, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_b4d_5dc_155__ul_a6b_a4b">
<li class="li">VertexAI-001: Vertex AI Dataset Encryption with Customer-Managed Encryption Keys (not
                  scored): Ensure that your Google Cloud Vertex AI datasets are encrypted using Customer-Managed
                  Encryption Keys (CMEKs) in order to have full control over data encryption and decryption
                  process. You can create and manage your own Customer-Managed Encryption Keys with
                  Cloud Key Management Service (Cloud KMS).</li>
</ul>]]></description>
    <pubDate>Tue, 20 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-google-cloud-vertex-ai-offers-encr</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Conformity updates rule for OpenSearch Version to 2.13</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-conformity-updates-rule-for-op</link>
    <description><![CDATA[<div class="p">August 21, 2024, Conformity—Upcoming Rule Update</div><div class="p">AWS</div><ul class="ul" id="whatsnew_1da_e92_b43__ul_75f_ef6">
<li class="li">ES-007: OpenSearch Version: Updated the version specified in the checking rule from
                  OpenSearch_2.11 to OpenSearch_2.13.</li>
</ul>]]></description>
    <pubDate>Wed, 21 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-conformity-updates-rule-for-op</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated GCP Permissions and New Rule for Vertex AI Workbench Instances</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-permissions-and-new-ru</link>
    <description><![CDATA[<div class="p">August 28, 2024, Conformity—Updated GCP account permission list</div><div class="p">We've added the following new GCP account permission:</div><ul class="ul" id="whatsnew_851_7cb_025__ul_987_5ff">
<li class="li">`notebooks.instances.list`</li>
</ul><div class="p">For a full list of GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">Add a GCP Account</a>.</div><div class="p">New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_851_7cb_025__ul_409_89e">
<li class="li">VertexAI-002:Disable Root Access for Workbench Instances: This rule ensures that root
                  access is disabled for Vertex AI Workbench Instances.</li>
</ul>]]></description>
    <pubDate>Wed, 28 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-permissions-and-new-ru</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Azure now defaults to Express configuration for vulnerability assessment emails</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-now-defaults-to-express-conf</link>
    <description><![CDATA[<div class="p">August 29, 2024, Conformity—Rule Update</div><div class="p">Azure</div><ul class="ul" id="whatsnew_ea7_e44_55b__ul_a92_45b">
<li class="li">Sql-008: Configure Emails for Vulnerability Assessment Scan Reports and Alerts: Updated
                  this rule to a not scored rule. Azure supports vulnerability assessment with `express`
                  and `classic` configurations. Express configuration is now the default procedure and
                  there is no need to configure notification setting with the email addresses. There
                  is no way to check if the vulnerability assessment configuration is `express` or `classic`
                  via API</li>
</ul>]]></description>
    <pubDate>Thu, 29 Aug 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-now-defaults-to-express-conf</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Secure Boot for Vertex AI Workbench Instances</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-secure-boot-for-vertex-ai-w</link>
    <description><![CDATA[<div class="p">September 02, 2024, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_2d1_852_882__ul_050_08e">
<li class="li">VertexAI-003:Enable Secure Boot for Workbench Instances: This rule ensures that Secure
                  Boot is enabled for your Vertex AI workbench instances.</li>
</ul>]]></description>
    <pubDate>Mon, 02 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-secure-boot-for-vertex-ai-w</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Configure Sensitive Information Filters for Amazon Bedrock Guardrails in Conformity</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-configure-sensitive-information-fi</link>
    <description><![CDATA[<div class="p">September 03, 2024, Conformity—New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_38e_aa7_300__ul_a2a_bce">
<li class="li">Bedrock-007: Configure Sensitive Information Filters for Amazon Bedrock Guardrails:
                  Ensure that Amazon Bedrock guardrails are configured to block or mask sensitive information
                  such as Personally Identifiable Information (PII).</li>
</ul>]]></description>
    <pubDate>Tue, 03 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-configure-sensitive-information-fi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Integrity Monitoring for Vertex AI Workbench Instances</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-integrity-monitoring-for-ve</link>
    <description><![CDATA[<div class="p">September 03, 2024, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_cfd_2d5_0af__ul_92f_c6e">
<li class="li">VertexAI-007:Enable Integrity Monitoring for Workbench Instances: This rule ensures
                  that the integrity monitoring is enabled for Vertex AI Workbench Instances.</li>
</ul>]]></description>
    <pubDate>Tue, 03 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-integrity-monitoring-for-ve</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Upgrade Conformity GCP RTM Configuration for Node.js 16 Decommissioning</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upgrade-conformity-gcp-rtm-configu</link>
    <description><![CDATA[<div class="p">September 04, 2024, Conformity—Reminder: Upgrade existing configuration for Google
               Cloud Platform (GCP) RTM</div><div class="p">The Cloud Functions runtime version used for old Conformity RTM is Node.js 16 and
               will be decommissioned by Google Cloud on 30 January 2025. This change will affect
               Conformity GCP Real Time Monitoring (RTM) configurations but does not immediately
               affect the existing Conformity customers.</div><div class="p">We have released the GCP Real-Time Monitoring installation template to use the latest
               1st generation Runtime version on 2024-06-18.</div><div class="p">Please follow the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-real-time-threat-monitoring-settings-#rtm-for-gcp" target="_blank">Real-time Monitoring Settings &gt; RTM for GCP</a> to install RTM for GCP again to upgrade the existing configuration before 30 January
               2025.</div>]]></description>
    <pubDate>Wed, 04 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upgrade-conformity-gcp-rtm-configu</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Virtual Trusted Platform Module (vTPM) for Vertex AI Workbench Instances</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-virtual-trusted-platform-mo</link>
    <description><![CDATA[<div class="p">September 05, 2024, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_73c_4a5_c00__ul_e54_6a6">
<li class="li">VertexAI-004:Enable Virtual Trusted Platform Module (vTPM) for Workbench Instances:
                  This rule ensures that vTPM is enabled for your Vertex AI workbench instances.</li>
</ul>]]></description>
    <pubDate>Thu, 05 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-virtual-trusted-platform-mo</guid>
    <category>Conformity</category>
</item>
<item>
    <title>VertexAI-006: Encrypt Workbench Instances with Customer-Managed Keys</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-vertexai-006-encrypt-workbench-ins</link>
    <description><![CDATA[<div class="p">September 05, 2024, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_e19_21d_aa0__ul_6fc_854">
<li class="li">VertexAI-006: Workbench Instance Encryption with Customer-Managed Encryption Keys:
                  This rule ensures that your Google Cloud Vertex AI workbench instances are encrypted
                  using Customer-Managed Encryption Keys (CMEKs).</li>
</ul>]]></description>
    <pubDate>Thu, 05 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-vertexai-006-encrypt-workbench-ins</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Managed Identity Options for Azure API Management Services</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-managed-identity-options-for-a</link>
    <description><![CDATA[<div class="p">September 05, 2024, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_e12_734_4b1__ul_a8f_8f5">
<li class="li">APIManagement-010: Use System-Assigned Managed Identities for Azure API Management
                  Services: Ensure that your Azure API Management service instances are using system-assigned
                  managed identities in order to allow secure access to other Microsoft Azure protected
                  resources such as Azure Key Vaults. System-assigned managed identities minimizes risks,
                  simplifies management, and maintains compliance with evolving cloud services.</li>
<li class="li">APIManagement-011: Use User-Assigned Managed Identities for Azure API Management Services:
                  Ensure that your Azure API Management service instances are using user-assigned managed
                  identities for fine-grained control over access permissions.</li>
</ul>]]></description>
    <pubDate>Thu, 05 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-managed-identity-options-for-a</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Automatic Upgrades for Vertex AI Workbench Instances Enabled in Conformity</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automatic-upgrades-for-vertex-ai-w</link>
    <description><![CDATA[<div class="p">September 05, 2024, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_5fc_7d5_4cb__ul_e65_375">
<li class="li">VertexAI-005: Enable Automatic Upgrades for Workbench Instances: This rule ensures
                  that the automatic upgrades are enabled for Vertex AI Workbench Instances.</li>
</ul>]]></description>
    <pubDate>Thu, 05 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automatic-upgrades-for-vertex-ai-w</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Rule Mapping with New Encryption Requirements for Azure Compliance Standards</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-rule-mapping-with-new-enc</link>
    <description><![CDATA[<div class="p">September 09, 2024, Conformity—Standards and Compliance Reports</div><div class="p">We have updated the rule mapping by adding rules VirtualMachines-038:Server Side Encryption
               for Non-Boot Disk using CMK and VirtualMachines-039:Server Side Encryption for Boot
               Disk using CMK to the control 7.2/7.3 of the following standards:</div><ul class="ul" id="whatsnew_acc_74d_4f7__ul_667_c80">
<li class="li">CIS Microsoft Azure Foundations Benchmark v1.5.0</li>
<li class="li">CIS Microsoft Azure Foundations Benchmark v2.0.0</li>
<li class="li">CIS Microsoft Azure Foundations Benchmark v2.1.0</li>
</ul>]]></description>
    <pubDate>Mon, 09 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-rule-mapping-with-new-enc</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Cloud Monitoring for Vertex AI Workbench Instances</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-cloud-monitoring-for-vertex</link>
    <description><![CDATA[<div class="p">September 09, 2024, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_36b_220_082__ul_569_adb">
<li class="li">VertexAI-009: Enable Cloud Monitoring for Workbench Instances: Ensure that Cloud Monitoring
                  feature is enabled for your Vertex AI workbench instances.</li>
</ul>]]></description>
    <pubDate>Mon, 09 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-cloud-monitoring-for-vertex</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Idle Shutdown for Vertex AI Workbench Instances Available with New Rule</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-idle-shutdown-for-vertex-ai</link>
    <description><![CDATA[<div class="p">September 09, 2024, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_1f9_881_ae4__ul_9cd_0a0">
<li class="li">VertexAI-008:Enable Idle Shutdown for Workbench Instances: This rule ensures that
                  idle shutdown is enabled for your Vertex AI workbench instances.</li>
</ul>]]></description>
    <pubDate>Mon, 09 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-idle-shutdown-for-vertex-ai</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Rule Enforces Avoidance of Default VPC Network for Workbench Instances</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-rule-enforces-avoidance-of-def</link>
    <description><![CDATA[<div class="p">September 10, 2024, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_bff_1b3_7b4__ul_175_b32">
<li class="li">VertexAI-010: Default VPC Network In Use: This rule ensures that your Workbench Instances
                  are not created in the default Virtual Private Cloud (VPC) network.</li>
</ul>]]></description>
    <pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-rule-enforces-avoidance-of-def</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Prevent External IP Assignments in VertexAI Notebooks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-prevent-external-ip-assignments-in</link>
    <description><![CDATA[<div class="p">September 10, 2024, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_91b_9a7_f95__ul_e30_5f4">
<li class="li">VertexAI-011: Prevent Assigning External IPs to Notebook Instances: This rule ensures
                  that external IP addresses are not assigned to your Google Cloud Vertex AI workbench
                  instances.</li>
</ul>]]></description>
    <pubDate>Tue, 10 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-prevent-external-ip-assignments-in</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Update to Azure AIServices-001 Rule for Improved Check Generation</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-update-to-azure-aiservices-001-rul</link>
    <description><![CDATA[<div class="p">September 16, 2024, Conformity—Rule Update</div><div class="p">Azure</div><ul class="ul" id="whatsnew_7b2_f91_e20__ul_272_c0b">
<li class="li">AIServices-001: Use Private Endpoints for OpenAI Service Instances: Update the rule
                  to generate checks correctly.</li>
</ul>]]></description>
    <pubDate>Mon, 16 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-update-to-azure-aiservices-001-rul</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Azure Vulnerability Assessment Rule Updates for SQL Servers</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-vulnerability-assessment-rul</link>
    <description><![CDATA[<div class="p">September 23, 2024, Conformity—Rule Update</div><div class="p">Azure</div><ul class="ul" id="whatsnew_709_5fd_93c__ul_7b6_7c1">
<li class="li">Sql-009: Enable Vulnerability Assessment Email Notifications for Admins and Subscription
                  Owners:</li>
</ul><ul class="ul" id="whatsnew_709_5fd_93c__ul_28a_d63">
<li class="li">Sql-017: Enable Vulnerability Assessment for Microsoft SQL Servers:</li>
</ul><ul class="ul" id="whatsnew_709_5fd_93c__ul_1d5_c3a">
<li class="li">Sql-018: Enable Vulnerability Assessment Periodic Recurring Scans: Updated this rule
                  to a not scored rule. Azure supports vulnerability assessment with `express` and `classic`
                  configurations. Express configuration is now the default procedure and there is no
                  need to configure notification setting with the email addresses. There is no way to
                  check if the vulnerability assessment configuration is `express` or `classic` via
                  API.</li>
</ul>]]></description>
    <pubDate>Mon, 23 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-vulnerability-assessment-rul</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Deep Security Agent now supports Ubuntu 24.04 with Secure Boot compatibility</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-now-supports-u</link>
    <description><![CDATA[<div class="p">September 25, 2024, Workload Security—Deep Security Agent version 20.0.1-19250 (20
               LTS Update 2024-09-18) and later supports Ubuntu 24.04, including Secure Boot. This
               requires Deep Security Manager version 20.0.954 or later.</div>]]></description>
    <pubDate>Wed, 25 Sep 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deep-security-agent-now-supports-u</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Updated Service Now Connector to Xanadu Version Available in Service Now Store</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-service-now-connector-to-x</link>
    <description><![CDATA[<div class="p">October 01, 2024, Conformity—We've upgraded the Service Now connector from Vancouver
               version to the latest Xanadu version and you can access it through the <a class="xref" href="https://store.servicenow.com/sn_appstore_store.do#!/store/integrations" target="_blank">Service Now Store</a> under Integrations.</div>]]></description>
    <pubDate>Tue, 01 Oct 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-service-now-connector-to-x</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Amazon SageMaker now supports VPC-only mode for notebook instances</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-amazon-sagemaker-now-supports-vpc</link>
    <description><![CDATA[<div class="p">October 01, 2024, Conformity—New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_7c4_755_477__ul_141_fa7">
<li class="li">SageMaker-006: Notebook in VPC Only mode can access required resources: This rule
                  ensures that Amazon SageMaker notebook instances running within a Virtual Private
                  Cloud (VPC) can access required resources.</li>
</ul>]]></description>
    <pubDate>Tue, 01 Oct 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-amazon-sagemaker-now-supports-vpc</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Lambda Update: Python 3.8 Support Removed</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-lambda-update-python-38-suppor</link>
    <description><![CDATA[<div class="p">October 08, 2024, Conformity—Upcoming Rule Update</div><div class="p">The following rule update will be released soon. These changes may affect your checks
               and compliance scores:</div><div class="p">AWS</div><ul class="ul" id="whatsnew_62b_e72_2ad__ul_39a_e73">
<li class="li">Lambda-012: Lambda Using Supported Runtime Environment: Removed 'Python 3.8' from
                  the list of supported runtime versions. See <a class="xref" href="https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html" target="_blank">AWS documentation - Lambda runtimes</a> for further details.</li>
</ul>]]></description>
    <pubDate>Tue, 08 Oct 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-lambda-update-python-38-suppor</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Custom Policy Update: New Permission Added for bedrock:ListFoundationModels</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-custom-policy-update-new-permi</link>
    <description><![CDATA[<div class="p">October 08, 2024, Conformity—AWS Custom Policy Update</div><div class="p">The Conformity AWS custom policy will be updated soon. The new custom policy version
               will be 1.59 and the permissions added are:</div><ul class="ul" id="whatsnew_24f_db1_1da__ul_0a0_01d">
<li class="li">bedrock:ListFoundationModels</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Tue, 08 Oct 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-custom-policy-update-new-permi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Standards and Compliance Reporting with 5 Cloud Provider Tags per Check</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-standards-and-compliance</link>
    <description><![CDATA[<div class="p">October 14, 2024, Conformity—Standards and Compliance Reports</div><div class="p">As of 21 October 2024, PDF report generated with individual checks will display a
               maximum of 5 cloud provider tags per check. To view a complete list of all associated
               tags, please refer to CSV report.</div>]]></description>
    <pubDate>Mon, 14 Oct 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-standards-and-compliance</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity Introduces AWS Custom Policy Update with New Permissions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-aws-custom-p</link>
    <description><![CDATA[<div class="p">October 14, 2024, Conformity—AWS Custom Policy Update</div><div class="p">The Conformity AWS custom policy will be updated soon. The new custom policy version
               will be 1.60 and the permissions added are:</div><ul class="ul" id="whatsnew_703_261_403__ul_442_e09">
<li class="li">sagemaker:ListModels</li>
<li class="li">sagemaker:DescribeModel</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Mon, 14 Oct 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-introduces-aws-custom-p</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Lambda Runtime Update to Exclude Python 3.8 Support</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-lambda-runtime-update-to-exclu</link>
    <description><![CDATA[<div class="p">October 14, 2024, Conformity— Rule Update</div><div class="p">AWS</div><ul class="ul" id="whatsnew_726_1e4_e1a__ul_c8d_0cb">
<li class="li">Lambda-012: Lambda Using Supported Runtime Environment: Removed 'Python 3.8' from
                  the list of supported runtime versions. See <a class="xref" href="https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html" target="_blank">AWS documentation - Lambda runtimes</a> for further details.</li>
</ul>]]></description>
    <pubDate>Mon, 14 Oct 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-lambda-runtime-update-to-exclu</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Scheduled Maintenance for Trend Cloud One Services on October 19, 2024</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scheduled-maintenance-for-trend-cl</link>
    <description><![CDATA[<div class="p">October 19, 2024, General—System maintenance for Trend Cloud One is scheduled for
               all regions between 03:00 and 10:00 UTC on Saturday, October 19, 2024. During this
               maintenance period, console and API access for some Trend Cloud One services will
               be unavailable. For more information or to be notified of scheduled maintenance, see
               <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-central-" target="_blank">Trend Cloud One Maintenance</a>.</div>]]></description>
    <pubDate>Sat, 19 Oct 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-scheduled-maintenance-for-trend-cl</guid>
    <category>General</category>
</item>
<item>
    <title>Enhanced Standards Reports with Cloud Provider Tags Limit</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-standards-reports-with-cl</link>
    <description><![CDATA[<div class="p">October 22, 2024, Conformity—Standards and Compliance Reports</div><div class="p">Following up on previous notification (14 October 2024), Effective October 22 2024,
               PDF report generated with individual checks display a maximum of 5 cloud provider
               tags per check. To view a complete list of all associated tags, please refer to CSV
               report.</div>]]></description>
    <pubDate>Tue, 22 Oct 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-standards-reports-with-cl</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity AWS Custom Policy Updated with New Permissions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-aws-custom-policy-updat</link>
    <description><![CDATA[<div class="p">October 23, 2024, Conformity—AWS Custom Policy Update</div><div class="p">The Conformity AWS custom policy has been updated. The new custom policy version is
               1.62 and the permissions added are:</div><ul class="ul" id="whatsnew_1a0_b57_7d7__ul_edd_bde">
<li class="li">bedrock:ListAgentKnowledgeBases</li>
<li class="li">bedrock:GetAgentKnowledgeBase</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Wed, 23 Oct 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-aws-custom-policy-updat</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated Compliance Standards to Meet CIS Foundations Benchmarks for AWS</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-compliance-standards-to-me</link>
    <description><![CDATA[<div class="p">October 24, 2024, Conformity—Updated Compliance Standards: CIS Foundations Benchmarks</div><div class="p">We've updated our compliance standards to meet the Center of Internet Security (CIS)
               Foundations Benchmarks for AWS. You can now filter Checks and download Compliance
               Reports to ensure your cloud environment complies with the latest CIS Foundations
               Benchmarks.</div><ul class="ul" id="whatsnew_587_0de_824__ul_bd8_c59">
<li class="li">CIS Amazon Web Services Foundations Benchmark v3.0.0</li>
</ul><div class="p">You can view the CIS certifications awarded to Trend Micro Cloud One - Conformity
               on the <a class="xref" href="https://www.cisecurity.org/partner/trend-micro" target="_blank">CIS partner website</a> and find out more about <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-compliance-and-conformity-" target="_blank">Compliance and Conformity</a> in our documentation.</div>]]></description>
    <pubDate>Thu, 24 Oct 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-compliance-standards-to-me</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New AWS Lambda runtime versions Python 3.14 and Nodejs.22 added</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-lambda-runtime-versions-py</link>
    <description><![CDATA[<div class="p">October 31, 2024, Conformity—Rule Update</div><div class="p">AWS</div><ul class="ul" id="whatsnew_6fd_0e4_87c__ul_241_835">
<li class="li">Lambda-012: Lambda Using Supported Runtime Environment: Added 'Python 3.14' and 'Nodejs.22'
                  to the list of supported runtime versions. See <a class="xref" href="https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html" target="_blank">AWS documentation - Lambda runtimes</a> for further details.</li>
</ul>]]></description>
    <pubDate>Thu, 31 Oct 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-lambda-runtime-versions-py</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Red Hat Enterprise Linux 9 (PowerPC) support for Deep Security Agent</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-red-hat-enterprise-linux-9-powerpc</link>
    <description><![CDATA[<div class="p">October 31, 2024, Workload Security—Deep Security Agent version 20.0.1-21510 (20 LTS
               Update 2024-10-31) and later supports Anti-Malware, Activity Monitoring, and SAP Scanner
               for Red Hat Enterprise Linux 9 (PowerPC little-endian). This requires Deep Security
               Manager version 20.0.979 or later.</div>]]></description>
    <pubDate>Thu, 31 Oct 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-red-hat-enterprise-linux-9-powerpc</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>AWS ElastiCache Engine Update to Latest Version Available for EC-013 Compliance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-elasticache-engine-update-to-l</link>
    <description><![CDATA[<div class="p">November 04, 2024, Conformity—Rule Update</div><div class="p">AWS</div><ul class="ul" id="whatsnew_ae9_a88_fb1__ul_b97_3e0">
<li class="li">EC-013: ElastiCache Engine Using Stable Version: Added Valkey and update Redis/Memcached
                  to latest version. See <a class="xref" href="https://docs.aws.amazon.com/AmazonElastiCache/latest/dg/supported-engine-versions.html" target="_blank">AWS documentation - ElastiCache Engine</a> for further details.</li>
</ul>]]></description>
    <pubDate>Mon, 04 Nov 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-elasticache-engine-update-to-l</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Deprecated CIS Microsoft Azure Foundations Benchmark v1.5.0 for Compliance Reports</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deprecated-cis-microsoft-azure-fou</link>
    <description><![CDATA[<div class="p">November 07, 2024, Conformity—Standards and Compliance Reports</div><div class="p">Following up on previous notification (12 August 2024), as of 07 November 2024, the
               following compliance standard have been deprecated:</div><ul class="ul" id="whatsnew_844_e82_460__ul_cb5_61b">
<li class="li">CIS Microsoft Azure Foundations Benchmark v1.5.0</li>
</ul><div class="p">This compliance standard is no longer accessible in the filters, preventing the creation
               of new reports or report-configurations with this outdated standard. If any existing
               report configurations include the deprecated compliance standard, it will not be possible
               to generate new PDF/CSV reports. However, the list of previously generated PDF/CSV
               reports remains available. We recommend updating your report configurations to use
               the latest version of the CIS Microsoft Azure Foundations Benchmark.</div>]]></description>
    <pubDate>Thu, 07 Nov 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deprecated-cis-microsoft-azure-fou</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS ElastiCache Engine Updated with Valkey Support and Latest Redis/Memcached Versions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-elasticache-engine-updated-wit</link>
    <description><![CDATA[<div class="p">November 11, 2024, Conformity—Rule Update</div><div class="p">AWS</div><ul class="ul" id="whatsnew_a37_436_25b__ul_a8b_769">
<li class="li">EC-013: ElastiCache Engine Using Stable Version: Added Valkey support and update Redis/Memcached
                  to latest version. See <a class="xref" href="https://docs.aws.amazon.com/AmazonElastiCache/latest/dg/supported-engine-versions.html" target="_blank">AWS documentation - ElastiCache Engine</a> for further details.</li>
</ul>]]></description>
    <pubDate>Mon, 11 Nov 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-elasticache-engine-updated-wit</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced Rule Mapping for CIS AWS Foundations Benchmark Compliance</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-rule-mapping-for-cis-aws</link>
    <description><![CDATA[<div class="p">November 14, 2024, Conformity—Standards and Compliance Reports</div><div class="p">We have updated the rule mapping, and the rule SecurityHub-002: Security Hub Enabled
               is now displayed under Control 4.16 of the following standard:</div><ul class="ul" id="whatsnew_d83_ca8_040__ul_304_ed8">
<li class="li">CIS Amazon Web Services Foundations Benchmark v3.0.0</li>
</ul>]]></description>
    <pubDate>Thu, 14 Nov 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-rule-mapping-for-cis-aws</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated GCP Account Permissions with New &#x27;artifactregistry.dockerimages.list&#x27; Permission</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-account-permissions-wi</link>
    <description><![CDATA[<div class="p">November 21, 2024, Conformity—GCP account permission list updated</div><div class="p">New permissions</div><ul class="ul" id="whatsnew_dc6_1fc_43b__ul_ae7_905">
<li class="li">`artifactregistry.dockerimages.list`</li>
</ul><div class="p">For a full list of GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">Add a GCP Account</a>.</div>]]></description>
    <pubDate>Thu, 21 Nov 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-account-permissions-wi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated rule logic for CloudVPC-006 to validate DNS Logging configuration</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-logic-for-cloudvpc-00</link>
    <description><![CDATA[<div class="p">November 26, 2024, Conformity—Bug Fix</div><div class="p">GCP</div><ul class="ul" id="whatsnew_843_d92_4c7__ul_9fa_f79">
<li class="li">CloudVPC-006:  Updated the rule logic to validate the configuration of DNS Logging
                  is enabled correctly will be updated soon.</li>
</ul>]]></description>
    <pubDate>Tue, 26 Nov 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-rule-logic-for-cloudvpc-00</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Improved Endpoint Address Inference for RDS DB Clusters and Instances</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-endpoint-address-inferenc</link>
    <description><![CDATA[<div class="p">November 26, 2024, Conformity—Template Scanner Updates</div><div class="p">Fixed an issue where the Endpoint address was being inferred incorrectly and set as
               resource name for RDS DB Clusters and Instances.</div>]]></description>
    <pubDate>Tue, 26 Nov 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-improved-endpoint-address-inferenc</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Lambda Runtime Environment Versions Updated to Latest for Conformity Feature</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-lambda-runtime-environment-ver</link>
    <description><![CDATA[<div class="p">November 28, 2024, Conformity—Rule Update</div><div class="p">AWS</div><ul class="ul" id="whatsnew_0c1_d05_fb4__ul_004_5aa">
<li class="li">Lambda-001: Lambda Runtime Environment Version: Removed 'nodejs20.x', 'python 3.12'
                  and added 'nodejs22.x', 'python 3.13' to the default recommended list of latest runtime
                  versions.</li>
</ul>]]></description>
    <pubDate>Thu, 28 Nov 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-lambda-runtime-environment-ver</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updates to AWS RDS Encryption Rule: New notifications for failed checks</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updates-to-aws-rds-encryption-rule</link>
    <description><![CDATA[<div class="p">November 28, 2024, Conformity—Upcoming Rule Update</div><div class="p">AWS</div><ul class="ul" id="whatsnew_377_06d_eff__ul_9dd_7ee">
<li class="li">RDS-004: RDS Encryption Enabled: Updated the rule to generate checks correctly. You
                  may receive a new notification for existing instances for failed checks.</li>
</ul>]]></description>
    <pubDate>Thu, 28 Nov 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updates-to-aws-rds-encryption-rule</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced CPU Usage Control for Linux Agents in Trend Cloud One</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-cpu-usage-control-for-lin</link>
    <description><![CDATA[<div class="p">November 29, 2024, Workload Security—On Linux, Deep Security Agents with Anti-Malware
               and Activity Monitoring enabled can now control the CPU usage in Trend Cloud One -
               Endpoint &amp; Workload Security. This requires Deep Security Agent version 20.0.1-4540
               (20 LTS Update 2024-03-20) or later.</div>]]></description>
    <pubDate>Fri, 29 Nov 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-cpu-usage-control-for-lin</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Updated CloudVPC-006 rule logic for correct DNS Logging configuration validation</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-cloudvpc-006-rule-logic-fo</link>
    <description><![CDATA[<div class="p">December 02, 2024, Conformity—Bug Fix</div><div class="p">GCP</div><ul class="ul" id="whatsnew_8e9_510_4ee__ul_c71_4d7">
<li class="li">CloudVPC-006:  Updated the rule logic to validate the configuration of DNS Logging
                  is enabled correctly.</li>
</ul>]]></description>
    <pubDate>Mon, 02 Dec 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-cloudvpc-006-rule-logic-fo</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Cloudformation Template Scanner Excludes ELBv2-004 and ELBv2-008 Rules</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloudformation-template-scanner-ex</link>
    <description><![CDATA[<div class="p">December 02, 2024, Conformity—Bug Fix</div><div class="p">Template Scanner Updates</div><div class="p">Cloudformation Template Scanner has been updated to exclude rules ELBv2-004 and ELBv2-008.
               These rules cannot run as they require knowledge of the TargetGroup TargetHealth,
               which is unknown before the template is deployed.</div>]]></description>
    <pubDate>Mon, 02 Dec 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cloudformation-template-scanner-ex</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Upgrade Google Cloud Platform RTM Configuration to Node.js 16 by 30 January 2025</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upgrade-google-cloud-platform-rtm</link>
    <description><![CDATA[<div class="p">December 02, 2024, Conformity—Reminder: Upgrade existing configuration for Google
               Cloud Platform (GCP) RTM</div><div class="p">The Cloud Functions runtime version used for old Conformity RTM is Node.js 16 and
               will be decommissioned by Google Cloud on 30 January 2025. This change will affect
               Conformity GCP Real Time Monitoring (RTM) configurations but does not immediately
               affect the existing Conformity customers.</div><div class="p">We have released the GCP Real-Time Monitoring installation template to use the latest
               1st generation Runtime version on 2024-06-18.</div><div class="p">Please follow the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-real-time-threat-monitoring-settings-#rtm-for-gcp" target="_blank">Real-time Monitoring Settings &gt; RTM for GCP</a> to install RTM for GCP again to upgrade the existing configuration before 30 January
               2025.</div>]]></description>
    <pubDate>Mon, 02 Dec 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upgrade-google-cloud-platform-rtm</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated HITRUST CSF v11.3.0 Compliance Standards and Reports</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-hitrust-csf-v1130-complian</link>
    <description><![CDATA[<div class="p">December 03, 2024, Conformity—Standards and Compliance Reports</div><div class="p">Updated the following Compliance Standards and Reports:</div><ul class="ul" id="whatsnew_525_377_ded__ul_8b6_214">
<li class="li">HITRUST CSF v11.3.0</li>
</ul>]]></description>
    <pubDate>Tue, 03 Dec 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-hitrust-csf-v1130-complian</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS GuardDuty now monitors S3 Protection feature for enhanced security detection</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-guardduty-now-monitors-s3-prot</link>
    <description><![CDATA[<div class="p">December 04, 2024, Conformity—New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_46e_0eb_2b4__ul_387_dba">
<li class="li">GD-004: Ensure that the S3 Protection feature is enabled for your Amazon GuardDuty
                  detectors: S3 Protection enables GuardDuty to monitor object-level API operations
                  in order to identify potential security risks for data stored within your S3 buckets.</li>
</ul>]]></description>
    <pubDate>Wed, 04 Dec 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-guardduty-now-monitors-s3-prot</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Malware Protection for EC2 in Amazon GuardDuty detectors</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-malware-protection-for-ec2</link>
    <description><![CDATA[<div class="p">December 04, 2024, Conformity—New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_2e2_460_332__ul_1bc_ff1">
<li class="li">GD-005: Ensure that Malware Protection for EC2 is enabled for your Amazon GuardDuty
                  detectors: Malware Protection for EC2 helps detect potential malware in Amazon EC2
                  instances.</li>
</ul>]]></description>
    <pubDate>Wed, 04 Dec 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-malware-protection-for-ec2</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Compliance Reports and Standards Filtering for AWS, Azure, and GCP Cloud Environments</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-compliance-reports-and-standards-f</link>
    <description><![CDATA[<div class="p">December 04, 2024, Conformity—Standards and Compliance Reports</div><div class="p">You can now filter Checks and download Compliance Reports to ensure your AWS, Azure
               and GCP cloud environments comply with the following standards:</div><ul class="ul" id="whatsnew_112_913_047__ul_ce7_550">
<li class="li">AusGov ISM Sep 2024</li>
</ul>]]></description>
    <pubDate>Wed, 04 Dec 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-compliance-reports-and-standards-f</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP Rule Ensures Functions Use Latest Runtime Version</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rule-ensures-functions-use</link>
    <description><![CDATA[<div class="p">December 05, 2024, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_e8a_48a_b46__ul_efa_42c">
<li class="li">CloudFunction-001: GCP Function Runtime Version: This rule ensures that GCP functions
                  are using the latest language runtime version available.</li>
</ul>]]></description>
    <pubDate>Thu, 05 Dec 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rule-ensures-functions-use</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Fixed Template Scanner API errors for parameter arguments and awsNotificationArns pseudoArguments</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-template-scanner-api-errors</link>
    <description><![CDATA[<div class="p">December 06, 2024, Conformity—Bug Fixes</div><div class="p">Template Scanner</div><ul class="ul" id="whatsnew_15d_46c_328__ul_63e_3db">
<li class="li">Fixed an issue where Vision One Template Scanner API would incorrectly return an error
                  when an argument for a parameter was passed as a number.</li>
<li class="li">Fixed an issue where Vision one Template Scanner API would incorrectly return an error
                  when pseudoArguments for `awsNotificationArns` was passed as an array of strings.</li>
</ul>]]></description>
    <pubDate>Fri, 06 Dec 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fixed-template-scanner-api-errors</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated AWS, Azure, and GCP Rules for Enhanced Cloud Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-azure-and-gcp-rules-fo</link>
    <description><![CDATA[<div class="p">December 11, 2024, Conformity—Rules Update</div><div class="p">AWS</div><ul class="ul" id="whatsnew_763_108_8f6__ul_b5b_a26">
<li class="li">EC2-011: vCPU-Based EC2 Instance Limit: Updated the rule title from 'Account Instance
                  Limit' to 'vCPU-Based EC2 Instance Limit'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_036_1fe">
<li class="li">S3-019: S3 Buckets with Website Hosting Configuration Enabled: Updated the rule title
                  from 'S3 Buckets with Website Configuration Enabled' to 'S3 Buckets with Website Hosting
                  Configuration Enabled'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_743_3aa">
<li class="li">S3-028: Enable S3 Bucket Keys: Updated the rule title from 'Enable Amazon S3 Bucket
                  Keys' to 'Enable S3 Bucket Keys'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_127_b56">
<li class="li">RDS-036: Amazon RDS Configuration Changes: Updated the rule title from 'RDS Configuration
                  Changes' to 'Amazon RDS Configuration Changes'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_399_73b">
<li class="li">RDS-041: Enable Instance Storage AutoScaling: Updated the rule title from 'Enable
                  Amazon RDS Storage AutoScaling' to 'Enable Instance Storage AutoScaling'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_d56_40d">
<li class="li">IAM-013: Enable MFA for IAM Users with Console Password: Updated the rule title from
                  'MFA For IAM Users With Console Password' to 'Enable MFA for IAM Users with Console
                  Password'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_eec_53e">
<li class="li">IAM-023: Check for Individual IAM Users: Updated the rule title from 'IAM User Present'
                  to 'Check for Individual IAM Users'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_189_138">
<li class="li">IAM-036: IAM Users with Administrative Privileges: Updated the rule title from 'AWS
                  IAM Users with Admin Privileges' to 'IAM Users with Administrative Privileges'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_977_e80">
<li class="li">IAM-046: IAM Support Role: Updated the rule title from 'Support Role' to 'IAM Support
                  Role'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_d28_e38">
<li class="li">IAM-056: IAM CreateLoginProfile detected: Updated the rule title from 'CreateLoginProfile
                  Detected' to 'IAM CreateLoginProfile detected'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_ce9_546">
<li class="li">IAM-066: IAM Groups with Administrative Privileges: Updated the rule title from 'AWS
                  IAM Groups with Admin Privileges' to 'IAM Groups with Administrative Privileges'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_500_259">
<li class="li">KMS-007: Monitor AWS KMS Configuration Changes: Updated the rule title from 'AWS Key
                  Management Service (KMS) Configuration Changes' to 'Monitor AWS KMS Configuration
                  Changes'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_45a_3b2">
<li class="li">CFM-004: CloudFormation Stack Failed Status: Updated the rule title from 'Stack Failed
                  Status' to 'CloudFormation Stack Failed Status'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_650_49c">
<li class="li">ES-008: Total Number of OpenSearch Cluster Nodes: Updated the rule title from 'OpenSearch
                  Instance Counts' to 'Total Number of OpenSearch Cluster Nodes'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_da9_96c">
<li class="li">ES-009: OpenSearch Desired Instance Type(s): Updated the rule title from 'OpenSearch
                  Desired Instance Type' to 'OpenSearch Desired Instance Type(s)'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_05a_29f">
<li class="li">ES-013: OpenSearch Domains Encrypted with KMS CMKs: Updated the rule title from 'OpenSearch
                  Domain Encrypted with KMS CMKs' to 'OpenSearch Domains Encrypted with KMS CMKs'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_39c_330">
<li class="li">SageMaker-002: Notebook Data Encrypted With KMS Customer Managed Keys: Updated the
                  rule title from 'Notebook Data Encrypted With KMS Customer Master Keys' to 'Notebook
                  Data Encrypted With KMS Customer Managed Keys'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_90c_5f7">
<li class="li">SageMaker-004: Disable Direct Internet Access for Notebook Instances: Updated the
                  rule title from 'Notebook Direct Internet Access' to 'Disable Direct Internet Access
                  for Notebook Instances'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_af3_29a">
<li class="li">SageMaker-007: Disable Root Access for SageMaker Notebook Instances: Updated the rule
                  title from 'SageMaker Notebook Root Access' to 'Disable Root Access for SageMaker
                  Notebook Instances'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_63a_426">
<li class="li">Neptune-005: IAM Database Authentication for Neptune: Updated the rule title from
                  'IAM Database Authentication' to 'IAM Database Authentication for Neptune'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_0f8_158">
<li class="li">ECR-003: Enable Automated Scanning for Amazon ECR Container Images: Updated the rule
                  title from 'Enable Scan on Push for ECR Container Images' to 'Enable Automated Scanning
                  for Amazon ECR Container Images'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_29f_f28">
<li class="li">Backup-001: Use AWS Backup Service in Use for Amazon RDS: Updated the rule title from
                  'Snapshot Backup Service' to 'Use AWS Backup Service in Use for Amazon RDS'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_d06_bfc">
<li class="li">StorageGateway-001: Use KMS Customer Master Keys for AWS Storage Gateway File Shares:
                  Updated the rule title from 'File Shares Encrypted With CMK' to 'Use KMS Customer
                  Master Keys for AWS Storage Gateway File Shares'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_f25_502">
<li class="li">ECS-001: Monitor Amazon ECS Configuration Changes: Updated the rule title from 'ECS
                  Configuration Changes' to 'Monitor Amazon ECS Configuration Changes'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_a52_e8c">
<li class="li">ECS-002: Amazon ECS Task Log Driver in Use: Updated the rule title from 'ECS Task
                  Log Driver In Use' to 'Amazon ECS Task Log Driver in Use'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_374_291">
<li class="li">WellArchitected-001: AWS Well-Architected Tool in Use: Updated the rule title from
                  'AWS Well-Architected Tool Is In Use' to 'AWS Well-Architected Tool in Use'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_10c_789">
<li class="li">Bedrock-007: Configure Sensitive Information Filters for Amazon Bedrock Guardrails:
                  Updated the rule title from 'Guardrail set to mask or block PII' to 'Configure Sensitive
                  Information Filters for Amazon Bedrock Guardrails'.</li>
</ul><div class="p">Azure</div><ul class="ul" id="whatsnew_763_108_8f6__ul_5f9_b23">
<li class="li">StorageAccounts-001: Enable Secure Transfer in Azure Storage: Updated the rule title
                  from 'Secure Transfer for Azure storage account' to 'Enable Secure Transfer in Azure
                  Storage'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_272_ed4">
<li class="li">StorageAccounts-003: Enable Logging for Azure Storage Queue Service: Updated the rule
                  title from 'Storage Logging For Queue Service' to 'Enable Logging for Azure Storage
                  Queue Service'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_889_d34">
<li class="li">StorageAccounts-005: Allow Shared Access Signature Tokens Over HTTPS Only: Updated
                  the rule title from 'Shared Access Signature Tokens Are Allowed Only Over Https' to
                  'Allow Shared Access Signature Tokens Over HTTPS Only'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_3a1_c8a">
<li class="li">SecurityCenter-002: Enable Automatic Provisioning of the Monitoring Agent: Updated
                  the rule title from 'Automatic Provisioning Of The Monitoring Agent' to 'Enable Automatic
                  Provisioning of the Monitoring Agent'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_a90_50b">
<li class="li">MySQL-001: Enable In-Transit Encryption for MySQL Servers: Updated the rule title
                  from 'SSL Connection' to 'Enable In-Transit Encryption for MySQL Servers'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_160_afe">
<li class="li">PostgreSQL-001: Enable 'LOG_CHECKPOINTS' Parameter for PostgreSQL Servers: Updated
                  the rule title from 'Log Checkpoints' to 'Enable 'LOG_CHECKPOINTS' Parameter for PostgreSQL
                  Servers'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_656_87b">
<li class="li">PostgreSQL-002: Enable In-Transit Encryption for PostgreSQL Database Servers: Updated
                  the rule title from 'SSL Connection' to 'Enable In-Transit Encryption for PostgreSQL
                  Database Servers'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_571_627">
<li class="li">PostgreSQL-003: Enable 'LOG_CONNECTIONS' Parameter for PostgreSQL Servers: Updated
                  the rule title from 'Log Connections' to 'Enable 'LOG_CONNECTIONS' Parameter for PostgreSQL
                  Servers'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_9e5_401">
<li class="li">PostgreSQL-004: Enable 'LOG_DISCONNECTIONS' Parameter for PostgreSQL Servers: Updated
                  the rule title from 'Log Disconnections' to 'Enable 'LOG_DISCONNECTIONS' Parameter
                  for PostgreSQL Servers'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_ceb_6f6">
<li class="li">PostgreSQL-005: Enable 'LOG_DURATION' Parameter for PostgreSQL Servers: Updated the
                  rule title from 'Log Duration' to 'Enable 'LOG_DURATION' Parameter for PostgreSQL
                  Servers'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_935_a75">
<li class="li">PostgreSQL-006: Enable 'CONNECTION_THROTTLING' Parameter for PostgreSQL Servers: Updated
                  the rule title from 'Connection Throttling' to 'Enable 'CONNECTION_THROTTLING' Parameter
                  for PostgreSQL Servers'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_5a7_be3">
<li class="li">PostgreSQL-007: Check for PostgreSQL Log Retention Period: Updated the rule title
                  from 'Log Retention Days' to 'Check for PostgreSQL Log Retention Period'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_217_f1c">
<li class="li">PostgreSQL-008: Use Microsoft Entra Admin for PostgreSQL Authentication: Updated the
                  rule title from 'Microsoft Entra Admin' to 'Use Microsoft Entra Admin for PostgreSQL
                  Authentication'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_67b_e71">
<li class="li">Sql-001: Enable Auditing for SQL Servers: Updated the rule title from 'Auditing' to
                  'Enable Auditing for SQL Servers'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_b77_41b">
<li class="li">Sql-002: Configure 'AuditActionGroup' for SQL Server Auditing: Updated the rule title
                  from 'Audit Action Groups' to 'Configure 'AuditActionGroup' for SQL Server Auditing'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_6d9_dda">
<li class="li">Sql-003: SQL Auditing Retention: Updated the rule title from 'Auditing Retention'
                  to 'SQL Auditing Retention'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_531_863">
<li class="li">Sql-004: Use Microsoft Entra Admin for SQL Authentication: Updated the rule title
                  from 'Microsoft Entra Admin' to 'Use Microsoft Entra Admin for SQL Authentication'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_772_f0c">
<li class="li">Sql-007: Enable All Types of Threat Detection on SQL Servers: Updated the rule title
                  from 'Enable All Threat Detection Types' to 'Enable All Types of Threat Detection
                  on SQL Servers'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_711_421">
<li class="li">Sql-009: Enable Classic Vulnerability Assessment Email Notifications for Admins and
                  Subscription Owners: Updated the rule title from 'Enable Vulnerability Assessment
                  Email Notifications for Admins and Subscription Owners' to 'Enable Classic Vulnerability
                  Assessment Email Notifications for Admins and Subscription Owners'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_c89_db1">
<li class="li">AppService-006: Enable HTTPS-Only Traffic: Updated the rule title from 'Check that
                  the Azure App is only using HTTPS' to 'Enable HTTPS-Only Traffic'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_01f_b00">
<li class="li">AppService-007: Check for TLS Protocol Latest Version: Updated the rule title from
                  'Check that the Azure App is using the latest TLS version' to 'Check for TLS Protocol
                  Latest Version'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_c40_7c0">
<li class="li">Network-008: Check for Unrestricted MS SQL Server Access: Updated the rule title from
                  'Check for Unrestricted MS SQL Database Access' to 'Check for Unrestricted MS SQL
                  Server Access'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_e4e_535">
<li class="li">KeyVault-003: Set Azure Secret Key Expiration: Updated the rule title from 'Set Secret
                  Key Expiration' to 'Set Azure Secret Key Expiration'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_7a7_fd8">
<li class="li">APIManagement-009: Unrestricted API Access: Updated the rule title from 'Restrict
                  Caller IPs' to 'Unrestricted API Access'.</li>
</ul><div class="p">GCP</div><ul class="ul" id="whatsnew_763_108_8f6__ul_f1c_94e">
<li class="li">CloudKMS-003: Detect Google Cloud KMS Configuration Changes: Updated the rule title
                  from 'Detect GCP Cloud KMS Configuration Changes' to 'Detect Google Cloud KMS Configuration
                  Changes'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_fbf_f76">
<li class="li">CloudSQL-027: Enable 'cloudsql.enable_pgaudit' and 'pgaudit.log' Flags for PostgreSQL
                  Database Instances: Updated the rule title from 'Enable 'cloudsql.enable_pgaudit'
                  Flag for PostgreSQL Database Instances' to 'Enable 'cloudsql.enable_pgaudit' and 'pgaudit.log'
                  Flags for PostgreSQL Database Instances'.</li>
</ul><ul class="ul" id="whatsnew_763_108_8f6__ul_960_a6d">
<li class="li">CloudPubSub-001: Detect Google Cloud Pub/Sub Configuration Changes: Updated the rule
                  title from 'Detect GCP Pub/Sub Configuration Changes' to 'Detect Google Cloud Pub/Sub
                  Configuration Changes'.</li>
</ul>]]></description>
    <pubDate>Wed, 11 Dec 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-azure-and-gcp-rules-fo</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New AWS Lambda rule enforces least privilege by restricting role sharing</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-lambda-rule-enforces-least</link>
    <description><![CDATA[<div class="p">December 12, 2024, Conformity—New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_537_5a1_509__ul_005_aa2">
<li class="li">Lambda-014: Lambda Functions Should not Share Roles that Contain Admin Privileges:
                  This rule ensures that your Amazon Lambda functions do not share execution roles that
                  contain admin privileges in order to promote the Principle of Least Privilege (POLP)
                  and provide your functions the minimal amount of access required to perform their
                  tasks.</li>
</ul>]]></description>
    <pubDate>Thu, 12 Dec 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-lambda-rule-enforces-least</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Linux support for Deep Security Agent self-protection introduced</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-linux-support-for-deep-security-ag</link>
    <description><![CDATA[<div class="p">December 13, 2024, Workload Security—Deep Security Agent self-protection is now supported
               on Linux. This requires Deep Security Agent version 20.0.0-5953 (20 LTS Update 2022-11-22)
               or later.</div>]]></description>
    <pubDate>Fri, 13 Dec 2024 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-linux-support-for-deep-security-ag</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Malware scan configurations now ignore excluded processes for non-real-time scans</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-malware-scan-configurations-now-ig</link>
    <description><![CDATA[<div class="p">January 06, 2025, Workload Security—Any configurationType other than REAL_TIME(0)
               ignores the `excludedScanProcessFileListID` column provided in a payload. This affects
               REST requests that add or update malware scan configurations for MANUAL(1) or SCHEDULED(2):</div><ul class="ul" id="whatsnew_bb4_c8e_d6f__ul_ad2_2ee">
<li class="li">`POST {{c1ws_rest}}/policies/antimalware/scanConfigs`</li>
<li class="li">`PUT {{c1ws_rest}}/policies/antimalware/scanConfigs/{scanConfigId}`</li>
</ul>]]></description>
    <pubDate>Mon, 06 Jan 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-malware-scan-configurations-now-ig</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>AWS CloudFront now enforces Origin Access Control for S3 origins</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-cloudfront-now-enforces-origin</link>
    <description><![CDATA[<div class="p">January 14, 2025, Conformity—New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_6b0_649_1e2__ul_bdd_c0e">
<li class="li">CF-013: Enable Origin Access Control For Distributions with S3 Origin: This rule ensuress
                  that the Origin Access Control (OAC) feature is enabled for all your Amazon CloudFront
                  distributions that utilize an S3 bucket as an origin in order to restrict any direct
                  access to your objects through Amazon S3 URLs.</li>
</ul>]]></description>
    <pubDate>Tue, 14 Jan 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-cloudfront-now-enforces-origin</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated Conformity AWS Custom Policy and New Rule for Inspector2-002 Integration</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-conformity-aws-custom-poli</link>
    <description><![CDATA[<div class="p">January 15, 2025, Conformity—AWS Custom Policy Update</div><div class="p">The Conformity AWS custom policy has been updated. The new custom policy version is
               1.70 and the permissions added are:</div><ul class="ul" id="whatsnew_24b_c79_d3e__ul_ca6_1a3">
<li class="li">inspector2:ListFindings</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div><div class="p">New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_24b_c79_d3e__ul_a4d_900">
<li class="li">Inspector2-002: Amazon Inspector 2 Findings: Amazon Inspector is an AWS service that
                  helps improve the security and compliance of your AWS resources.</li>
</ul>]]></description>
    <pubDate>Wed, 15 Jan 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-conformity-aws-custom-poli</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Auto-Upgrade for GKE Cluster Nodes in GCP with New Rule GKE-006</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-auto-upgrade-for-gke-cluste</link>
    <description><![CDATA[<div class="p">January 15, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_625_120_697__ul_a75_6d9">
<li class="li">GKE-006: Enable Auto-Upgrade for GKE Cluster Nodes: This rule ensures that the Auto-Upgrade
                  feature is enabled for all the nodes running within your Google Kubernetes Engine
                  (GKE) clusters. This feature helps you keep your cluster nodes up to date with the
                  latest supported version of Kubernetes.</li>
</ul>]]></description>
    <pubDate>Wed, 15 Jan 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-auto-upgrade-for-gke-cluste</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Shielded GKE Cluster Nodes rule added for enhanced security in Conformity</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-shielded-gke-cluster-nodes-rule-ad</link>
    <description><![CDATA[<div class="p">January 20, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_f60_3dd_5fc__ul_e97_eed">
<li class="li">GKE-004: Use Shielded GKE Cluster Nodes: This rule ensures that your Google Kubernetes
                  Engine (GKE) cluster pool nodes are shielded to provide a strong cryptographic identity.</li>
</ul>]]></description>
    <pubDate>Mon, 20 Jan 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-shielded-gke-cluster-nodes-rule-ad</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Automate GKE Cluster Version Upgrades with Release Channels</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automate-gke-cluster-version-upgra</link>
    <description><![CDATA[<div class="p">January 21, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_370_2de_aad__ul_dd9_d7a">
<li class="li">GKE-009: Automate Cluster Version Upgrades using Release Channels: This rule ensures
                  that the version management is automated for your Google Kubernetes Engine (GKE) clusters
                  using Release Channels.</li>
</ul>]]></description>
    <pubDate>Tue, 21 Jan 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-automate-gke-cluster-version-upgra</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Secure Boot for Cluster Nodes in GKE with New GCP Rule</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-secure-boot-for-cluster-nod</link>
    <description><![CDATA[<div class="p">January 21, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_fb4_f06_cd0__ul_2d3_6d9">
<li class="li">GKE-005: Enable Secure Boot for Cluster Nodes: Ensure that Secure Boot is enabled
                  for your Google Kubernetes Engine (GKE) cluster nodes.</li>
</ul>]]></description>
    <pubDate>Tue, 21 Jan 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-secure-boot-for-cluster-nod</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Expanded Template Scanner now supports additional AWS resources</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-expanded-template-scanner-now-supp</link>
    <description><![CDATA[<div class="p">January 22, 2025, Conformity—Template Scanner Updates</div><div class="p">New Resources Support</div><div class="p">Template Scanner Github App for Terraform templates now supports the following resources:</div><ul class="ul" id="whatsnew_77e_811_620__ul_788_c4a">
<li class="li">APIGateway RestApi</li>
<li class="li">AutoScaling Group</li>
<li class="li">CloudFormation Stack</li>
<li class="li">CloudTrail Trail</li>
<li class="li">EC2 Network Interface</li>
<li class="li">EC2 Security Group</li>
<li class="li">EC2 Volume</li>
<li class="li">EC2 VPC</li>
<li class="li">EC2 VPC Endpoint</li>
<li class="li">ECR Repository</li>
<li class="li">EFS File System</li>
<li class="li">ElasticCache</li>
<li class="li">Elasticsearch Domain</li>
<li class="li">ELB Classic Load Balancer</li>
<li class="li">EMR Cluster</li>
<li class="li">IAM Group</li>
<li class="li">IAM Managed Policy</li>
<li class="li">IAM Role</li>
<li class="li">Kinesis Stream</li>
<li class="li">KMS Key</li>
<li class="li">Lambda Function</li>
<li class="li">RDS DB Cluster</li>
<li class="li">RDS DB Instance</li>
<li class="li">Redshift Cluster</li>
<li class="li">VPC NAT gateways</li>
<li class="li">VPC Network ACL</li>
<li class="li">Workspaces</li>
</ul>]]></description>
    <pubDate>Wed, 22 Jan 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-expanded-template-scanner-now-supp</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Integrity Monitoring enabled for Google Kubernetes Engine cluster nodes</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-integrity-monitoring-enabled-for-g</link>
    <description><![CDATA[<div class="p">January 23, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_d35_918_c7b__ul_fe4_eb6">
<li class="li">GKE-008: Enable Integrity Monitoring for Cluster Nodes: This rule ensures that the
                  Integrity Monitoring feature is enabled for all your Google Kubernetes Engine (GKE)
                  cluster nodes.</li>
</ul>]]></description>
    <pubDate>Thu, 23 Jan 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-integrity-monitoring-enabled-for-g</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Auto-Repair for GKE Cluster Nodes with New GCP Rule</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-auto-repair-for-gke-cluster</link>
    <description><![CDATA[<div class="p">January 23, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_de1_5d9_eaa__ul_bb3_376">
<li class="li">GKE-007: Enable Auto-Repair for GKE Cluster Nodes: This rule ensures that the Auto-Repair
                  feature is enabled for all your GKE cluster nodes.</li>
</ul>]]></description>
    <pubDate>Thu, 23 Jan 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-auto-repair-for-gke-cluster</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Restrict Network Access for GKE with New Rule GKE-013</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-restrict-network-access-for-gke-wi</link>
    <description><![CDATA[<div class="p">January 24, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_8af_ef1_a17__ul_ff7_1dd">
<li class="li">GKE-013: Restrict Network Access: Ensure that your Google Kubernetes Engine (GKE)
                  clusters are configured with master authorised networks.</li>
</ul>]]></description>
    <pubDate>Fri, 24 Jan 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-restrict-network-access-for-gke-wi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Template Scanner now supports direct scanning of Terraform HCL templates from `.zip` files</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-supports-dire</link>
    <description><![CDATA[<div class="p">January 28, 2025, Conformity—Template Scanner Updates</div><div class="p">Template Scanner API now supports Terraform HCL (`.tf`) templates.</div><div class="p">Previously, Terraform HCL (`.tf`) templates were required to be transformed into HCL
               plan (.json) files before scanning.</div><div class="p">With the latest API, Terraform HCL (`.tf`) templates can now be scanned directly by
               scanning a `.zip` file of HCL templates.</div><div class="p">You can now use the `template-scanner/archive-scan` endpoint to POST a ZIP file containing
               your Terraform templates to be scanned. For more information please visit <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Template-scanner#paths-~1template-scanner~1archive-scan-post" target="_blank">the Template Scanner API documentation</a></div>]]></description>
    <pubDate>Tue, 28 Jan 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-supports-dire</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Real-time process image file list now part of exclusion list in Workload Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-real-time-process-image-file-list</link>
    <description><![CDATA[<div class="p">January 31, 2025, Workload Security—In Trend Cloud One - Endpoint &amp; Workload Security,
               the process image file list is now part of the inheritance exclusion list and is applied
               to real-time exclusions. The setting is available through Anti-Malware &gt; Exclusions
               &gt; Real-time &gt; Process Image File List.</div>]]></description>
    <pubDate>Fri, 31 Jan 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-real-time-process-image-file-list</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>New GCP Rule: Prevent Alpha GKE Clusters for Production Workloads</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rule-prevent-alpha-gke-clu</link>
    <description><![CDATA[<div class="p">February 03, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_a83_87d_3cb__ul_636_478">
<li class="li">GKE-012: Check for Alpha Clusters in Production: This rule ensures that the Alpha
                  GKE clusters are not used for production workloads.</li>
</ul>]]></description>
    <pubDate>Mon, 03 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rule-prevent-alpha-gke-clu</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity releases CIS AWS Foundations Benchmark 6.0</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-cis-azure-6</link>
    <description><![CDATA[<div class="p"></div><div class="p">January 04, 2026—Trend Cloud One - Conformity has released the following new compliance
               standard.</div><div class="p"><b class="b">CIS Foundations Benchmarks - CIS AWS Foundations Benchmark v6.0.0</b>: Conformity has updated the CIS AWS compliance standard to the latest version to
               meet the Center of Internet Security (CIS) Foundations Benchmarks for Amazon Web Services.
               You can now filter Checks and download Compliance Reports to ensure your cloud environment
               complies with the latest CIS Foundations Benchmarks. - CIS AWS Foundations Benchmark
               v6.0.0. </div><div class="p"><b class="b">Deprecation Notice</b>: Conformity has deprecated the CIS AWS Foundations Benchmark v4.1.0 for removal on
               <b class="b">April 27 2026</b>. It will no longer be accessible in the filters, preventing the creation of new reports
               or report-configurations with this outdated benchmark. If any existing report configurations
               include deprecated compliance standards, it will not be possible to generate new PDF/CSV
               reports. However, the list of previously generated PDF/CSV reports remains available.
               Trend Cloud One - Conformity recommends updating your report configurations to use
               the latest versions of CIS AWS Foundations Benchmark before <b class="b">April 27 2026</b>.</div>]]></description>
    <pubDate>Tue, 04 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-cis-azure-6</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Binary Authorization for GKE clusters with new GCP rule</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-binary-authorization-for-gk</link>
    <description><![CDATA[<div class="p">February 04, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_15d_cc0_cb1__ul_746_481">
<li class="li">GKE-014: Enable Binary Authorization: This rule ensures that the Binary Authorization
                  feature is enabled for GKE clusters.</li>
</ul>]]></description>
    <pubDate>Tue, 04 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-binary-authorization-for-gk</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable and Configure Cluster Logging for GKE with New GCP Rule</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-and-configure-cluster-loggi</link>
    <description><![CDATA[<div class="p">February 04, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_9a2_bf2_a4b__ul_4ca_3aa">
<li class="li">GKE-016: Enable and Configure Cluster Logging: This rule ensures that logging is enabled
                  for your Google Kubernetes Engine (GKE) clusters to collect logs emitted by your Kubernetes
                  applications and the GKE infrastructure that runs your applications.</li>
</ul>]]></description>
    <pubDate>Tue, 04 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-and-configure-cluster-loggi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Discontinuation of Cloud One Template Scanner (Preview) on GitHub</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-discontinuation-of-cloud-one-templ</link>
    <description><![CDATA[<div class="p">February 04, 2025, Conformity—Cloud One Template Scanner (Preview) Removal Notice</div><div class="p">The Cloud One Template Scanner (Preview) Github application has been discontinued
               and disabled on GitHub.</div><div class="p">We encourage former users of the preview app to use the <a class="xref" href="https://github.com/apps/trend-micro-cloud-one" target="_blank">Trend Micro Cloud One</a> GitHub application going forward.</div><div class="p">For more details, please visit <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-template-scanner-github-app-" target="_blank">our help documentation</a>.</div>]]></description>
    <pubDate>Tue, 04 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-discontinuation-of-cloud-one-templ</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Custom Check Public API Rule Title Update and Immutability Enforcement</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-check-public-api-rule-title</link>
    <description><![CDATA[<div class="p">February 04, 2025, Conformity—Custom Check Public API Update</div><div class="p">To avoid a rule title mismatch for custom checks, `ruleTitle` used in custom check
               must now match the existing rule title for the specified `ruleId`. Additionally `ruleTitle`
               is now an immutable field and cannot be modified once a custom check is created. For
               more information, see the <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-api-reference-tag-Checks#paths-~1checks~1%7BcheckId%7D-patch" target="_blank">Update Check</a> endpoint.</div>]]></description>
    <pubDate>Tue, 04 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-check-public-api-rule-title</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Intranode Visibility in GKE Clusters with New Rule GKE-018</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-intranode-visibility-in-gke</link>
    <description><![CDATA[<div class="p">February 05, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_576_047_fe7__ul_863_98a">
<li class="li">GKE-018: Enable Intranode Visibility: This rule ensures that intranode visibility
                  is enabled for your GKE clusters.</li>
</ul>]]></description>
    <pubDate>Wed, 05 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-intranode-visibility-in-gke</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Workload Vulnerability Scanning in GKE clusters for enhanced security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-workload-vulnerability-scan</link>
    <description><![CDATA[<div class="p">February 06, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_893_ebf_82a__ul_b9b_ae6">
<li class="li">GKE-011: Enable Workload Vulnerability Scanning: This rule ensures that the Workload
                  Vulnerability Scanning feature is enabled for your Google Kubernetes Engine (GKE)
                  clusters.</li>
</ul>]]></description>
    <pubDate>Thu, 06 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-workload-vulnerability-scan</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Template Scanner now supports Terraform HCL templates for easier scanning</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-supports-terr</link>
    <description><![CDATA[<div class="p">February 06, 2025, Conformity—Template Scanner Updates</div><div class="p">Template Scanner now supports Terraform HCL (`.tf`) templates.</div><div class="p">Previously, Terraform HCL (`.tf`) templates were required to be converted into Terraform
               plans (.json) files before scanning.</div><div class="p">With the latest feature, Terraform HCL (`.tf`) templates can now be scanned directly
               by uploading a ZIP file of HCL templates.</div><div class="p">Use the "Template Scanner" menu and click on the Terraform tab, to upload a ZIP file
               containing HCL templates. For more information please visit <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-template-scanner-#scanning-terraform-hcl-templates" target="_blank">the Template Scanner documentation</a></div>]]></description>
    <pubDate>Thu, 06 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-now-supports-terr</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhance GKE Security with Metadata Server Enabled in GCP</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhance-gke-security-with-metadata</link>
    <description><![CDATA[<div class="p">February 07, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_1d6_bd8_83e__ul_bc2_673">
<li class="li">GKE-020: Enable GKE Metadata Server: This rule ensures that GKE Metadata Server is
                  enabled for your Google Kubernetes Engine (GKE) cluster nodes in order to enhance
                  security by restricting workload access to sensitive instance information.</li>
</ul>]]></description>
    <pubDate>Fri, 07 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhance-gke-security-with-metadata</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Limit on Organisation-Level Communication Settings Implemented for Stability</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-limit-on-organisation-level-commun</link>
    <description><![CDATA[<div class="p">February 10, 2025, Conformity—Organisation-Level Communication Settings Limit</div><div class="p">To ensure reliable service, organisations are now limited to a maximum of 10 active
               organisation-level communication settings.</div>]]></description>
    <pubDate>Mon, 10 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-limit-on-organisation-level-commun</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP Rules for GKE Clusters: Legacy Authorization Disabled, Private Nodes Enabled</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rules-for-gke-clusters-leg</link>
    <description><![CDATA[<div class="p">February 10, 2025, Conformity—New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_e94_67c_b09__ul_018_21d">
<li class="li">GKE-015: Disable Legacy Authorization: This rule ensures that legacy authorization
                  (also known as Attribute-Based Access Control or ABAC) is disabled for your Google
                  Kubernetes Engine (GKE) clusters  to guarantee compatibility with Role-Based Access
                  Control (RBAC).</li>
</ul><ul class="ul" id="whatsnew_e94_67c_b09__ul_8c2_574">
<li class="li">GKE-017: Enable Private Nodes: Ensure that your Google Kubernetes Engine (GKE) clusters
                  are configured to provision all nodes with only internal IP addresses (i.e., private
                  nodes).</li>
</ul>]]></description>
    <pubDate>Mon, 10 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rules-for-gke-clusters-leg</guid>
    <category>Conformity</category>
</item>
<item>
    <title>AWS Lambda IAM Role Rule Severity Updated for Better Flexibility</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-lambda-iam-role-rule-severity</link>
    <description><![CDATA[<div class="p">February 13, 2025, Conformity—Rule Update</div><div class="p">AWS</div><ul class="ul" id="whatsnew_d5a_5bc_46e__ul_d7a_d5c">
<li class="li">Lambda-006: Using An IAM Role For More Than One Lambda Function: We've updated the
                  Rule Severity from `HIGH` to `MEDIUM` to cover more scenarios and allow better flexibility
                  for IAM Roles.</li>
</ul>]]></description>
    <pubDate>Thu, 13 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-aws-lambda-iam-role-rule-severity</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP Rules for Google Kubernetes Engine Cluster Monitoring and VPC-Native Traffic Routing</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rules-for-google-kubernete</link>
    <description><![CDATA[<div class="p">February 17, 2025, Conformity—New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_398_c2c_06c__ul_5f4_333">
<li class="li">GKE-019: Enable and Configure Cluster Monitoring: This rule ensures that Cloud Monitoring
                  is enabled for your Google Kubernetes Engine (GKE) clusters.</li>
</ul><ul class="ul" id="whatsnew_398_c2c_06c__ul_10c_aae">
<li class="li">GKE-022: Enable VPC-Native Traffic Routing: This rule ensures that VPC-native traffic
                  routing is enabled for your Google Kubernetes Engine (GKE) clusters.</li>
</ul>]]></description>
    <pubDate>Mon, 17 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-rules-for-google-kubernete</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GKE Rule: Use Sandbox with gVisor for Enhanced Container Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gke-rule-use-sandbox-with-gvis</link>
    <description><![CDATA[<div class="p">February 18, 2025, Conformity—New Rule</div><div class="p">GCP</div><ul class="ul" id="whatsnew_bf3_d64_b6b__ul_6f6_653">
<li class="li">GKE-023: Use Sandbox with gVisor for GKE Clusters Nodes: GKE Sandbox provides an extra
                  layer of isolation between containers and the underlying host kernel, mitigating the
                  risk of container escape vulnerabilities.</li>
</ul>]]></description>
    <pubDate>Tue, 18 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gke-rule-use-sandbox-with-gvis</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GKE Rules for Enhanced Security and Control in Google Kubernetes Engine</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gke-rules-for-enhanced-securit</link>
    <description><![CDATA[<div class="p">February 19, 2025, Conformity—New Rules</div><div class="p">GCP</div><ul class="ul" id="whatsnew_894_3fa_257__ul_0bd_67d">
<li class="li">GKE-021: Use GKE Clusters with Private Endpoints Only: This rule ensures to restrict
                  the control plane access to your Google Kubernetes Engine (GKE) clusters to private
                  endpoints only, effectively disabling external access to the Kubernetes API.</li>
</ul><ul class="ul" id="whatsnew_894_3fa_257__ul_ec3_1c5">
<li class="li">GKE-024: Use Container-Optimized OS for GKE Clusters Nodes: This rule ensures that
                  your Google Kubernetes Engine (GKE) cluster nodes use the Container-Optimized OS (cos_containerd),
                  a managed, optimized, and hardened base OS provided by GKE to limit the host's attack
                  surface.</li>
</ul>]]></description>
    <pubDate>Wed, 19 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gke-rules-for-enhanced-securit</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP account permission `container.clusters.get` added for enhanced access control</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permission-contain</link>
    <description><![CDATA[<div class="p">February 19, 2025, Conformity—Updated GCP account permission list</div><div class="p">We've added the following new GCP account permission:</div><ul class="ul" id="whatsnew_af0_163_9e6__ul_15e_fae">
<li class="li">`container.clusters.get`</li>
</ul><div class="p">For a full list of GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">Add a GCP Account</a>.</div>]]></description>
    <pubDate>Wed, 19 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permission-contain</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced recommendation scan for optimized security rule identification</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-recommendation-scan-for-o</link>
    <description><![CDATA[<div class="p">February 24, 2025, Workload Security—The enhanced recommendation scan improves upon
               the classic recommendation scan by optimizing efficiency, reliability, and accuracy
               when identifying security rules for Intrusion Prevention, Integrity Monitoring, and
               Log Inspection. Based on your system's required security rules, the scan delivers
               recommendations with optimized performance and fewer limitations. Whether run manually
               or scheduled for automated scanning, enhanced recommendation scan can apply recommended
               rules for regular protection with minimal disruption and reduced strain on system
               resources. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security-reco-scan-enhance" target="_blank">Enhanced recommendation scan</a>.</div>]]></description>
    <pubDate>Mon, 24 Feb 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-recommendation-scan-for-o</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>RTM introduces GKE security rules for enhanced cluster protection</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rtm-introduces-gke-security-rules</link>
    <description><![CDATA[<div class="p">March 10, 2025, Conformity—RTM for GCP</div><div class="p">RTM now supports the following rules:</div><ul class="ul" id="whatsnew_2e4_2d9_3fe__ul_3fe_17e">
<li class="li">GKE-004: Use Shielded GKE Cluster Nodes: This rule ensures that your Google Kubernetes
                  Engine (GKE) cluster pool nodes are shielded to provide a strong cryptographic identity.</li>
<li class="li">GKE-005: Enable Secure Boot for Cluster Nodes: Ensure that Secure Boot is enabled
                  for your Google Kubernetes Engine (GKE) cluster nodes.</li>
<li class="li">GKE-006: Enable Auto-Upgrade for GKE Cluster Nodes: This rule ensures that the Auto-Upgrade
                  feature is enabled for all the nodes running within your Google Kubernetes Engine
                  (GKE) clusters. This feature helps you keep your cluster nodes up to date with the
                  latest supported version of Kubernetes.</li>
</ul>]]></description>
    <pubDate>Mon, 10 Mar 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rtm-introduces-gke-security-rules</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Deprecated Compliance Standards in Conformity Reports Starting 19 May 2025</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deprecated-compliance-standards-in</link>
    <description><![CDATA[<div class="p">March 17, 2025, Conformity—Standards and Compliance Reports</div><div class="p">On 19 May 2025, the following compliance standards will be deprecated:</div><ul class="ul" id="whatsnew_b0e_1e0_b64__ul_af8_061">
<li class="li">CIS Amazon Web Services Foundations Benchmark v1.5.0</li>
<li class="li">CIS Amazon Web Services Foundations Benchmark v2.0</li>
<li class="li">CIS Google Cloud Platform Foundation Benchmark v1.3.0</li>
</ul><div class="p">These deprecated compliance standards will be no longer accessible in the filters,
               preventing the creation of new reports or report-configurations with these outdated
               standards. If any existing report configurations include deprecated compliance standards,
               it will not be  possible to generate new PDF/CSV reports. However, the list of previously
               generated PDF/CSV reports remains available. We recommend updating your report configurations
               to use the latest versions of CIS Foundations Benchmark before 19 May 2025.</div>]]></description>
    <pubDate>Mon, 17 Mar 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deprecated-compliance-standards-in</guid>
    <category>Conformity</category>
</item>
<item>
    <title>RTM now supports enhanced GKE security and configuration rules</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rtm-now-supports-enhanced-gke-secu</link>
    <description><![CDATA[<div class="p">March 18, 2025, Conformity—RTM for GCP</div><div class="p">RTM now supports the following rules:</div><ul class="ul" id="whatsnew_f51_2ca_8de__ul_1c9_ae9">
<li class="li">GKE-001: Enable GKE Cluster Node Encryption with Customer-Managed Keys:  This rule
                  ensures that boot disk encryption with Customer-Managed Keys is enabled for GKE cluster
                  nodes.</li>
<li class="li">GKE-013: Restrict Network Access: Ensure that your Google Kubernetes Engine (GKE)
                  clusters are configured with master authorised networks.</li>
<li class="li">GKE-014: Enable Binary Authorization: This rule ensures that the Binary Authorization
                  feature is enabled for GKE clusters.</li>
<li class="li">GKE-015: Disable Legacy Authorization: This rule ensures that legacy authorization
                  (also known as Attribute-Based Access Control or ABAC) is disabled for your Google
                  Kubernetes Engine (GKE) clusters  to guarantee compatibility with Role-Based Access
                  Control (RBAC).</li>
<li class="li">GKE-016: Enable and Configure Cluster Logging: This rule ensures that logging is enabled
                  for your Google Kubernetes Engine (GKE) clusters to collect logs emitted by your Kubernetes
                  applications and the GKE infrastructure that runs your applications.</li>
<li class="li">GKE-017: Enable Private Nodes: Ensure that your Google Kubernetes Engine (GKE) clusters
                  are configured to provision all nodes with only internal IP addresses (i.e., private
                  nodes).</li>
<li class="li">GKE-018: Enable Intranode Visibility: This rule ensures that intranode visibility
                  is enabled for your GKE clusters.</li>
<li class="li">GKE-019: Enable and Configure Cluster Monitoring: This rule ensures that Cloud Monitoring
                  is enabled for your Google Kubernetes Engine (GKE) clusters.</li>
<li class="li">GKE-020: Enable GKE Metadata Server: This rule ensures that GKE Metadata Server is
                  enabled for your Google Kubernetes Engine (GKE) cluster nodes in order to enhance
                  security by restricting workload access to sensitive instance information.</li>
<li class="li">GKE-021: Use GKE Clusters with Private Endpoints Only: This rule ensures to restrict
                  the control plane access to your Google Kubernetes Engine (GKE) clusters to private
                  endpoints only, effectively disabling external access to the Kubernetes API.</li>
</ul>]]></description>
    <pubDate>Tue, 18 Mar 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rtm-now-supports-enhanced-gke-secu</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Deprecation of Outdated Compliance Standards on 26 May 2025</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deprecation-of-outdated-compliance</link>
    <description><![CDATA[<div class="p">March 26, 2025, Conformity—Standards and Compliance Reports</div><div class="p">On 26 May 2025, the following compliance standards will no longer be supported:</div><ul class="ul" id="whatsnew_e15_df1_3bb__ul_48f_670">
<li class="li">AusGov ISM March 2021</li>
<li class="li">NIS Europe OES-2019</li>
</ul><div class="p">These deprecated compliance standards will be no longer be accessible in the filters,
               preventing the creation of new reports or report-configurations with these outdated
               standards. If any existing report configurations include the deprecated compliance
               standard, it will not be  possible to generate new PDF/CSV reports. However, the list
               of previously generated PDF/CSV reports remains available. We recommend updating your
               report configurations to use the latest versions of standards by 26 May 2025.</div>]]></description>
    <pubDate>Wed, 26 Mar 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deprecation-of-outdated-compliance</guid>
    <category>Conformity</category>
</item>
<item>
    <title>RTM now supports enhanced GCP rules for secure and efficient GKE clusters</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rtm-now-supports-enhanced-gcp-rule</link>
    <description><![CDATA[<div class="p">March 27, 2025, Conformity—RTM for GCP</div><div class="p">RTM now supports the following rules:</div><ul class="ul" id="whatsnew_36e_2a6_79d__ul_136_0d0">
<li class="li">GKE-007: Enable Auto-Repair for GKE Cluster Nodes: This rule ensures that the Auto-Repair
                  feature is enabled for all your GKE cluster nodes.</li>
<li class="li">GKE-008: Enable Integrity Monitoring for Cluster Nodes: This rule ensures that Integrity
                  Monitoring is enabled for your Google Kubernetes Engine (GKE) cluster nodes.</li>
<li class="li">GKE-009: Automate Cluster Version Upgrades using Release Channels: This rule ensures
                  that Automate version management for your Google Kubernetes Engine (GKE) clusters
                  using Release Channels.</li>
<li class="li">GKE-010: Prevent Default Service Account Usage: This rule ensures that GKE clusters
                  are not configured to use the default service account.</li>
<li class="li">GKE-011: Enable Workload Vulnerability Scanning: This rule ensures that workload vulnerability
                  scanning is enabled for Google Kubernetes Engine (GKE) clusters.</li>
<li class="li">GKE-012: Check for Alpha Clusters in Production: This rule ensures that Alpha GKE
                  clusters are not used for production workloads.</li>
<li class="li">GKE-022: Enable VPC-Native Traffic Routing: This rule ensures that VPC-native traffic
                  routing is enabled for Google Kubernetes Engine (GKE) clusters.</li>
<li class="li">GKE-023: Use Sandbox with gVisor for GKE Clusters Nodes: This rule ensures that your
                  cluster nodes are using GKE Sandbox with gVisor to isolate untrusted workloads to
                  enhance security in the multi-tenant Google Kubernetes Engine (GKE) environments,</li>
<li class="li">GKE-024: Use Container-Optimized OS for GKE Clusters Nodes: This rule ensures that
                  your Google Kubernetes Engine (GKE) cluster nodes use the Container-Optimized OS (cos_containerd),
                  a managed, optimized, and hardened base OS provided by GKE to limit the host's attack
                  surface.</li>
</ul>]]></description>
    <pubDate>Thu, 27 Mar 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rtm-now-supports-enhanced-gcp-rule</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New AWS IAM Rule Identifies Users with Compromised Credentials</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-iam-rule-identifies-users</link>
    <description><![CDATA[<div class="p">March 31, 2025, Conformity—New Rule</div><div class="p">AWS</div><ul class="ul" id="whatsnew_04a_0fe_fa2__ul_629_1eb">
<li class="li">IAM-073: Check for IAM Users with Compromised Credentials: This rule checks for Amazon
                  IAM users with the "AWSCompromisedKeyQuarantine", "AWSCompromisedKeyQuarantineV2",
                  and/or "AWSCompromisedKeyQuarantineV3" managed policies in order to identify IAM users
                  with compromised or exposed credentials.</li>
</ul>]]></description>
    <pubDate>Mon, 31 Mar 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-aws-iam-rule-identifies-users</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Agent Process Wildcard Exclusion Supported on Windows and Linux Versions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-process-wildcard-exclusion-s</link>
    <description><![CDATA[<div class="p">March 31, 2025, Workload Security—The agent process wildcard exclusion is now supported.
               On Linux, this requires Deep Security Agent version 20.0.1-21510 or later. On Windows,
               this requires Deep Security Agent version 20.0.1-25770 or later.</div>]]></description>
    <pubDate>Mon, 31 Mar 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-agent-process-wildcard-exclusion-s</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Azure Database for PostgreSQL now enforces Transport Encryption for enhanced security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-database-for-postgresql-now</link>
    <description><![CDATA[<div class="p">April 03, 2025, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_ba9_0c2_749__ul_40f_a47">
<li class="li">PostgreSQL-015: Enable Transport Encryption for PostgreSQL Flexible Servers: This
                  rule ensures that the databases managed with Azure Database for PostgreSQL have the
                  Transport Encryption feature enabled.</li>
</ul>]]></description>
    <pubDate>Thu, 03 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-azure-database-for-postgresql-now</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Microsoft Defender for Cloud in Azure Resource Manager for enhanced security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-microsoft-defender-for-clou</link>
    <description><![CDATA[<div class="p">April 08, 2025, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_890_1b1_294__ul_cd7_be1">
<li class="li">SecurityCenter-044: Enable Microsoft Defender for Cloud for Azure Resource Manager:
                  This rule ensures that Microsoft Defender for Cloud is enabled for Azure Resource
                  Manager.</li>
</ul>]]></description>
    <pubDate>Tue, 08 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-microsoft-defender-for-clou</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Azure Rules for PostgreSQL and Virtual Machine Disk Security</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-rules-for-postgresql-and</link>
    <description><![CDATA[<div class="p">April 08, 2025, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_398_52d_3a4__ul_af6_ba8">
<li class="li">PostgreSQL-016: Enable Connection Throttling for PostgreSQL Flexible Servers: This
                  rule ensure that connection throttling is enabled for your Azure Database for PostgreSQL
                  flexible servers.</li>
</ul><ul class="ul" id="whatsnew_398_52d_3a4__ul_1c6_6a4">
<li class="li">VirtualMachines-043: Disable Public Network Access to Virtual Machine Disks: This
                  rule ensure that public network access (i.e., all network access) to Azure virtual
                  machine (VM) disks is disabled in order to enhance security by preventing unauthorized
                  access.</li>
</ul>]]></description>
    <pubDate>Tue, 08 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-rules-for-postgresql-and</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Custom Policy Updates: Azure Account API Permissions Updated</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-policy-updates-azure-accoun</link>
    <description><![CDATA[<div class="p">April 10, 2025, Conformity—Custom Policy Updates</div><ul class="ul" id="whatsnew_fb0_a61_11f__ul_2e0_5d5">
<li class="li">We've updated the Azure account API permission list.</li>
</ul>]]></description>
    <pubDate>Thu, 10 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-custom-policy-updates-azure-accoun</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Azure MySQL flexible server rules for transport encryption and audit logging</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-mysql-flexible-server-ru</link>
    <description><![CDATA[<div class="p">April 14, 2025, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_9be_77f_05c__ul_9c4_450">
<li class="li">MySQL-003: Enable Transport Encryption for MySQL Flexible Servers: This rule ensures
                  that "require_secure_transport" parameter is enabled for Azure MySQL flexible servers.</li>
</ul><ul class="ul" id="whatsnew_9be_77f_05c__ul_616_439">
<li class="li">MySQL-005: Enable Audit Logging for MySQL Flexible Servers: This rule ensures that
                  audit logging is enabled for Microsoft Azure MySQL flexible servers.</li>
</ul>]]></description>
    <pubDate>Mon, 14 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-mysql-flexible-server-ru</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Increased Maximum TTL for POST and PATCH Checks to 99 Years</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-increased-maximum-ttl-for-post-and</link>
    <description><![CDATA[<div class="p">April 14, 2025, Conformity—Update Checks Endpoints</div><ul class="ul" id="whatsnew_997_bb9_444__ul_269_6df">
<li class="li">POST and PATCH Checks: The maximum configurable TTL has been increased to 99 years
                  from the time of the request.</li>
</ul>]]></description>
    <pubDate>Mon, 14 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-increased-maximum-ttl-for-post-and</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Rule for PostgreSQL Flexible Servers Ensures Sufficient Log File Retention Period</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-rule-for-postgresql-flexible-s</link>
    <description><![CDATA[<div class="p">April 14, 2025, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_d70_b69_fb0__ul_539_403">
<li class="li">PostgreSQL-017: Check Log Files Retention Period for PostgreSQL Flexible Servers:
                  This rule ensures that  that there is a sufficient retention period configured for
                  log files for Azure PostgreSQL flexible database servers.</li>
</ul>]]></description>
    <pubDate>Mon, 14 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-rule-for-postgresql-flexible-s</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhanced AWS Cloud Account Scanning for Improved Resource Verification</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-cloud-account-scannin</link>
    <description><![CDATA[<div class="p">April 15, 2025, Conformity—As a part of our commitment to improving customer experience,
               we will release significant system enhancements for AWS cloud account scanning. These
               enhancements will be rolled out gradually over the next several months.</div><div class="p">Note: Some of these enhancements allow for more thorough and accurate scanning of
               account resources and verification, which may change the display of particular data
               with existing inconsistencies.</div>]]></description>
    <pubDate>Tue, 15 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-aws-cloud-account-scannin</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New GCP account permission added for compute.forwardingRules.list</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permission-added-f</link>
    <description><![CDATA[<div class="p">April 15, 2025, Conformity—Updated GCP account permission list</div><div class="p">We've added the following new GCP account permission:</div><ul class="ul" id="whatsnew_db1_23a_37b__ul_410_3bf">
<li class="li">`compute.forwardingRules.list`</li>
</ul><div class="p">For a full list of GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">Add a GCP Account</a>.</div>]]></description>
    <pubDate>Tue, 15 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-gcp-account-permission-added-f</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Restrict guest user access with new Azure rule ActiveDirectory-025</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-restrict-guest-user-access-with-ne</link>
    <description><![CDATA[<div class="p">April 15, 2025, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_cd4_47b_93a__ul_eb6_dc6">
<li class="li">ActiveDirectory-025: Restrict Guest User Access to Their Own Directory Data: This
                  rule ensures that guest user access is restricted to properties and memberships of
                  their own directory objects in Microsoft Entra ID.</li>
</ul>]]></description>
    <pubDate>Tue, 15 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-restrict-guest-user-access-with-ne</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Azure rule restricts tenant creation to admins and assigned users</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-rule-restricts-tenant-cr</link>
    <description><![CDATA[<div class="p">April 15, 2025, Conformity—New Rules</div><div class="p">Azure</div><ul class="ul" id="whatsnew_b3a_9f3_3c8__ul_966_2a4">
<li class="li">ActiveDirectory-026: Disable Tenant Creation for Non-Admin Users: This rule ensures
                  that only administrators or specifically assigned users (i.e., users with tenant creator
                  roles) have permission to create Microsoft Entra ID or Azure Active Directory B2C
                  tenants.</li>
</ul>]]></description>
    <pubDate>Tue, 15 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-rule-restricts-tenant-cr</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Install Trend Vision One Endpoint Security agent via Deep Security Agent integration</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-install-trend-vision-one-endpoint</link>
    <description><![CDATA[<div class="p">April 15, 2025, Workload Security—Trend Cloud One - Endpoint &amp; Workload Security and
               Trend
               Vision One - Endpoint Security Server &amp; Workload Protection can now install Trend
               Vision
               One Endpoint Security agent via Deep Security Agent. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security-agent-v1-install" target="_blank">Install Trend Vision One Endpoint Security agent via Deep
                  Security Agent</a>.</div>]]></description>
    <pubDate>Tue, 15 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-install-trend-vision-one-endpoint</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Enhanced Security for Open-Source Databases with Microsoft Defender for Cloud</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-for-open-source</link>
    <description><![CDATA[<div class="p">April 16, 2025, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_abb_08c_682__ul_270_585">
<li class="li">SecurityCenter-043: Enable Microsoft Defender for Cloud for Open-Source Relational
                  Databases: This rule ensures that Microsoft Defender for Cloud is enabled for open-source
                  relational databases such as Azure Database for PostgreSQL, Azure Database for MySQL,
                  and Azure Database for MariaDB.</li>
</ul>]]></description>
    <pubDate>Wed, 16 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhanced-security-for-open-source</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated GCP account permissions and APIs for enhanced access control</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-account-permissions-an</link>
    <description><![CDATA[<div class="p">April 28, 2025, Conformity—Updated GCP account permission and API list</div><div class="p">We've added the following new GCP account permission and API:</div><ul class="ul" id="whatsnew_1bd_015_34a__ul_eb7_394">
<li class="li">`pubsub.subscriptions.get`</li>
<li class="li">`networkconnectivity.hubs.getIamPolicy`</li>
<li class="li">`Bigtable Admin API`</li>
</ul><div class="p">For a full list of GCP permissions, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-add-a-gcp-account-#create-a-custom-role" target="_blank">Add a GCP Account</a>.</div>]]></description>
    <pubDate>Mon, 28 Apr 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-gcp-account-permissions-an</guid>
    <category>Conformity</category>
</item>
<item>
    <title>New Azure Security Rules for Machine Learning and Kubernetes Services</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-security-rules-for-machi</link>
    <description><![CDATA[<div class="p">May 05, 2025, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_5a6_706_699__ul_92b_e1e">
<li class="li">MachineLearning-006: Enable Network Isolation for Azure Machine Learning Registries:
                  This rule ensures that network isolation is enabled for your Azure Machine Learning
                  registries.</li>
</ul><ul class="ul" id="whatsnew_5a6_706_699__ul_f5a_322">
<li class="li">AKS-007: Enable Support for Network Policies: This rule ensure that your Azure Kubernetes
                  Service (AKS) clusters are using network policies to implement secure policy-based
                  access control.</li>
</ul>]]></description>
    <pubDate>Mon, 05 May 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-azure-security-rules-for-machi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Restrict Guest User Invites to Admins in Azure Active Directory</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-restrict-guest-user-invites-to-adm</link>
    <description><![CDATA[<div class="p">May 07, 2025, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_e8a_60c_f75__ul_480_6a5">
<li class="li">ActiveDirectory-027: Limit Guest User Invites to Administrators: This rule ensures
                  that only users with the 'User Administrator' or the 'Guest Inviter' roles can invite
                  guest users to your Microsoft Entra directory to collaborate on resources secured
                  by your organisation.</li>
</ul>]]></description>
    <pubDate>Wed, 07 May 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-restrict-guest-user-invites-to-adm</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated AWS Well-Architected Framework Compliance Standards and Deprecation Notice</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-well-architected-frame</link>
    <description><![CDATA[<div class="p">May 12, 2025, Conformity—Standards and Compliance Report</div><div class="p">We've updated the Amazon Web Services Well-Architected Framework Compliance Standard
               Report and the associated rule mappings by adding the latest version of Amazon Web
               Services Well-Architected Framework, released in March 2025.</div><div class="p">Deprecation Notice</div><div class="p">As of 01 June 2025, the Amazon Web Services Well-Architected Framework (updated October
               2023) Compliance Standard will no longer be available.</div><div class="p">This deprecated compliance standard will no longer be accessible in the filters, preventing
               the creation of new reports or report-configurations with this outdated standard.
               If any existing report configurations include the deprecated compliance standard,
               it will not be possible to generate new PDF/CSV reports. However, the list of previously
               generated PDF/CSV reports remains available. We recommend updating your report configurations
               to use the latest versions of the Amazon Web Services Well-Architected Framework by
               01 June 2025.</div>]]></description>
    <pubDate>Mon, 12 May 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-well-architected-frame</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enable Confidential Computing for Azure Virtual Machines with New Rule</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-confidential-computing-for</link>
    <description><![CDATA[<div class="p">May 14, 2025, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_b58_8f6_0a7__ul_636_804">
<li class="li">VirtualMachines-044: Enable Confidential Computing for Azure Virtual Machines:This
                  rule ensures that Azure Virtual Machines (VMs) have Confidential Computing enabled
                  to protect data in use with hardware-based Trusted Execution Environments (TEEs).</li>
</ul>]]></description>
    <pubDate>Wed, 14 May 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enable-confidential-computing-for</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Trend Cloud One Documentation Portal Migrating to New Site on June 7, 2025</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-cloud-one-documentation-port</link>
    <description><![CDATA[<div class="p">May 16, 2025, Workload Security—The <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--" target="_blank">Trend Cloud One™ Documentation</a> portal will migrate to a new site on June 7, 2025.</div><div class="p">To centralize knowledge resources and improve customer experience finding information
               about Trend Micro products, Trend Cloud One documentation will be migrated to the
               <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/" target="_blank">Trend Micro Online Help Center</a>. As part of this migration, Trend Cloud One API references are being moved to the
               <a class="xref" href="https://automation.trendmicro.com/cloudone/home/" target="_blank">Trend Micro Automation Center</a>.</div><div class="p">Existing external links to the Trend Cloud One documentation portal will be redirected
               to the corresponding content in the Online Help Center.</div><div class="p">Trend Cloud One console links will be updated to point directly to the new documentation
               locations.</div><div class="p">If you have any questions or concerns about this transition, please contact your Trend
               Micro Representative or our Trend Micro Technical Support.</div><div class="p">For more information, see: <a class="xref" href="https://success.trendmicro.com/en-US/solution/KA-0019683" target="_blank">Trend Cloud One™ Documentation Portal Notice of Migration</a></div>]]></description>
    <pubDate>Fri, 16 May 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-trend-cloud-one-documentation-port</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Deprecated Compliance Standards Removed for Improved Report Generation</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deprecated-compliance-standards-re</link>
    <description><![CDATA[<div class="p">May 19, 2025, Conformity—Standards and Compliance Reports</div><div class="p">As of 19 May 2025, the following compliance standards have been deprecated:</div><ul class="ul" id="whatsnew_78a_97d_d27__ul_82e_fb9">
<li class="li">CIS Amazon Web Services Foundations Benchmark v1.5.0</li>
<li class="li">CIS Amazon Web Services Foundations Benchmark v2.0</li>
<li class="li">CIS Google Cloud Platform Foundation Benchmark v1.3.0</li>
</ul><div class="p">These deprecated compliance standards are no longer accessible in the filters, preventing
               the creation of new reports or report-configurations with these outdated standards.
               If any existing report configurations include deprecated compliance standards, it
               will not be  possible to generate new PDF/CSV reports. However, the list of previously
               generated PDF/CSV reports remains available. We recommend updating your report configurations
               to use the latest versions of CIS Foundations Benchmark.</div>]]></description>
    <pubDate>Mon, 19 May 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deprecated-compliance-standards-re</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Enhance Kubernetes Security with Private Nodes in Azure AKS</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhance-kubernetes-security-with-p</link>
    <description><![CDATA[<div class="p">May 19, 2025, Conformity—New Rule</div><div class="p">Azure</div><ul class="ul" id="whatsnew_265_a0c_6d2__ul_1a5_a0a">
<li class="li">AKS-005: Kubernetes Clusters with Private Nodes: This rule ensures that your Azure
                  Kubernetes Service (AKS) clusters are deployed with private nodes in order to enhance
                  your Kubernetes workload's security and isolation.</li>
</ul>]]></description>
    <pubDate>Mon, 19 May 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-enhance-kubernetes-security-with-p</guid>
    <category>Conformity</category>
</item>
<item>
    <title>IoT enabled by default for Deep Security Agents version 20.0.2-4960 and</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-iot-enabled-by-default-for-deep-se</link>
    <description><![CDATA[<div class="p">May 19, 2025, Workload Security—In Trend Cloud One - Endpoint &amp; Workload Security,
               IoT is now enabled by default for every IoT-capable Deep Security Agent version 20.0.2-4960
               and later. This means it is no longer required to have Activity Monitoring enabled
               on these agents.</div><div class="p">Fully-qualified domain names (FQDN) requested by IoT must be allowed. For details,
               see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-workload-security--workload-security-communication-ports-urls-ip-#Deep3" target="_blank">Required Workload Security IP addresses and port numbers</a>.</div>]]></description>
    <pubDate>Mon, 19 May 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-iot-enabled-by-default-for-deep-se</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Support for Red Hat Enterprise Linux 9 on Arm architecture</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-red-hat-enterprise-lin</link>
    <description><![CDATA[<div class="p">May 26, 2025, Workload Security—Deep Security Agent version 20.0.2-7600 (20 LTS Update
               2025-04-16) and later supports Red Hat Enterprise Linux 9 (64-bit Arm (aarch64)).
               This requires Deep Security Manager version 20.0.1047 (20 LTS Update 2025-05-12) or
               later.</div>]]></description>
    <pubDate>Mon, 26 May 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-red-hat-enterprise-lin</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Reports API bug fix improves filtering by report configuration ID</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-reports-api-bug-fix-improves-filte</link>
    <description><![CDATA[<div class="p">May 28, 2025, Conformity—Bug Fixes</div><div class="p">Reports API</div><ul class="ul" id="whatsnew_3da_703_392__ul_e31_686">
<li class="li">Fixed an issue where the GET Reports API would incorrectly ignore the reportConfigId
                  parameter when provided by itself in query requests. The API now properly returns
                  reports associated with the specified report configuration ID.</li>
</ul>]]></description>
    <pubDate>Wed, 28 May 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-reports-api-bug-fix-improves-filte</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated Azure Custom Role permissions for Azure Key Vaults scanning</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-azure-custom-role-permissi</link>
    <description><![CDATA[<div class="p">May 29, 2025, Conformity—Updated Azure Custom Role permission list</div><div class="p">We've added the following permissions to <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-azure-introduction-and-guide-#create-a-custom-role" target="_blank">Add an Azure Account - Create a Custom Role</a>:</div><ul class="ul" id="whatsnew_49f_cf5_7a5__ul_86f_0f4">
<li class="li">`Microsoft.KeyVault/vaults/keys/read`</li>
<li class="li">`Microsoft.KeyVault/vaults/secrets/read`</li>
</ul><div class="p">These permissions are required for Conformity to scan the Azure Key Vaults that use
               the role-based access control model as the authorization system.</div>]]></description>
    <pubDate>Thu, 29 May 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-azure-custom-role-permissi</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Deprecated AWS Compliance Standard</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deprecated-standard</link>
    <description><![CDATA[<div class="p">June 26, 2025, Conformity—Standards and Compliance Reports As of 19 June 2025, AWS
               Well-Architected Framework (updated October 2023) has been deprecated and is no longer
               accessible in the filters, preventing the creation of new reports or report configurations
               with this outdated standard. If any of the existing report configurations include
               a deprecated compliance standard, generating new PDF/CSV reports will not be possible.
               However, the list of previously generated PDF/CSV reports remains available. We recommend
               updating your report configurations to use the latest versions of the AWS Well-Architected
               Framework.</div>]]></description>
    <pubDate>Thu, 26 Jun 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-deprecated-standard</guid>
    <category>Conformity</category>
</item>
<item>
    <title>File Storage Security now supports Malaysia region on AWS</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fss-now-supports-malaysia</link>
    <description><![CDATA[<div class="p">July 14, 2025, File Storage Security—File Storage Security now supports the Malaysia
               (ap-southeast-5) region on AWS. For more information, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-file-storage-security-supported-aws" target="_blank">What's supported in AWS</a>.</div>]]></description>
    <pubDate>Mon, 14 Jul 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fss-now-supports-malaysia</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Support for Red Hat Enterprise Linux 10</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-rhel-10</link>
    <description><![CDATA[<div class="p">July 16, 2025, Workload Security—Deep Security Agent version 20.0.2-14431 (20 LTS
               Update 2025-07-09) and later supports Red Hat Enterprise Linux 10 (64-bit), including
               SELinux, Secure Boot, and FIPS mode. This requires Deep Security Manager version 20.0.1054
               (20 LTS Update 2025-06-11) or later.</div>]]></description>
    <pubDate>Wed, 16 Jul 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-rhel-10</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Scheduled maintenance for Trend Cloud One services on July 26, 2025</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-c1-maintenance-2025-07-26</link>
    <description><![CDATA[<div class="p">July 17, 2025, General—System maintenance for Trend Cloud One is scheduled for all
               regions (us-1, ca-1, de-1, gb-1, in-1, sg-1, au-1, jp-1) between 03:00 and 10:00 UTC
               on Saturday, July 26, 2025. During this maintenance period, console and API access
               for some Trend Cloud One services will be unavailable. For more information or to
               be notified of scheduled maintenance, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-maintenance-schedule" target="_blank">Trend Cloud One Maintenance</a>.</div>]]></description>
    <pubDate>Thu, 17 Jul 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-c1-maintenance-2025-07-26</guid>
    <category>General</category>
</item>
<item>
    <title>File Storage Security scanner now updated with library-requests version 2.32.4</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fss-scanner-update-lib-req-v2324</link>
    <description><![CDATA[<div class="p">August 4, 2025—File Storage Security scanner is updated with library-requests version
               2.32.4 to resolve <a class="xref" href="https://nvd.nist.gov/vuln/detail/CVE-2024-47081" target="_blank">CVE-2024-47081</a>.</div>]]></description>
    <pubDate>Mon, 04 Aug 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fss-scanner-update-lib-req-v2324</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Updated AWS Custom Policy 1.71</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy</link>
    <description><![CDATA[<div class="p">August 05, 2025, Conformity—The Conformity AWS custom policy has been updated to the
               latest version - 1.71, and the new permission added is: - iam:ListGroupsForUser. </div><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Tue, 05 Aug 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity Updates - Week Ending 5 September 2025</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-updates-05-sept-2025</link>
    <description><![CDATA[<div class="p"></div><div class="p"></div><section class="section" id="WN_29_08_2025_6d26acdf_301d_4977_94db_44605d25c3ee_Copy__gcp_rules">
<h3 class="section-title">GCP Rules</h3>
<ul class="ul">
<li class="li"><b class="b">ComputeEngine-021: Check for Publicly Shared Disk Images:</b> This rule ensures that your virtual machine disk images are not publicly shared with
                     all other Google Cloud Platform (GCP) accounts in order to avoid exposing sensitive
                     or confidential data.</li>
<li class="li"><b class="b">GKE-030: Use Confidential GKE Cluster Nodes:</b> This rule ensures that your Google Kubernetes Engine (GKE) cluster node pools use
                     confidential GKE nodes to encrypt all running workloads.</li>
<li class="li"><b class="b">CloudRun-011: Check for the Maximum Number of Container Instances</b>: This rule prevents uncontrolled scaling, resource exhaustion, and unexpected costs
                     when auto-scaling.</li>
<li class="li"><b class="b">CloudRun-001: Check for the Minimum Number of Container Instances:</b> This rule ensures that your Google Cloud Run services have a sufficient number of
                     container instances configured to minimize cold start latency and enhance performance.</li>
<li class="li"><b class="b">CloudRun-003: Enable Automatic Runtime Security Updates:</b> This rule ensures that automatic runtime security updates are enabled for your Cloud
                     Run services in order to keep the services secure and protected against vulnerabilities
                     without manual intervention.</li>
<li class="li"><b class="b">CloudSQL-036: Enable "log_checkpoints" Flag for PostgreSQL Database Server Configuration</b>: This rule ensures that "log_checkpoints" database flag is enabled for all PostgreSQL
                     database instances available within your Google Cloud Platform (GCP) account.</li>
<li class="li"><b class="b">SecretManager-003: Enable Rotation Schedules for Secret Manager Secrets:</b> This rule ensures that rotation periods are configured for all Secret Manager secrets
                     available within your Google Cloud Platform (GCP) account to minimize the risk of
                     unauthorized access or misuse of secrets.</li>
<li class="li"><b class="b">CloudSQL-035: Enable "slow_query_log" Flag for MySQL Database Servers:</b> This rule ensures that the "slow_query_log" database flag is enabled for your Google
                     Cloud MySQL database instances.</li>
<li class="li"><b class="b">CloudSQL-039: Enable Automatic Storage Increase:</b> This rule ensures that Automatic Storage Increase feature is enabled for your production
                     Google Cloud SQL database instances.</li>
</ul>
</section><section class="section" id="WN_29_08_2025_6d26acdf_301d_4977_94db_44605d25c3ee_Copy__azure_rules">
<h3 class="section-title">Azure Rules</h3>
<ul class="ul">
<li class="li"><b class="b">CosmosDB-009: Use Managed Identities for Azure Cosmos DB Accounts</b>: This rule ensures that your Microsoft Azure Cosmos DB accounts are using system-assigned
                     and/or user-assigned managed identities to allow secure access to other cloud protected
                     resources such as Azure Storage accounts.</li>
</ul>
</section>]]></description>
    <pubDate>Sat, 09 Aug 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-updates-05-sept-2025</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity Updates - Week Ending 12 September 2025</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-updates-12-sept-2025</link>
    <description><![CDATA[<div class="p"></div><section class="section" id="WN_12_09_2025__section_d5w_j2s_qgc">
<h3 class="section-title">Updated Compliance Standards - CIS Foundations Benchmarks</h3>
<div class="p">We've updated our compliance standards to meet the Center of Internet Security (CIS)
                  Foundations Benchmarks. You can now filter Checks and download Compliance Reports
                  to ensure your cloud environment complies with the latest CIS Foundations Benchmarks.
                  </div>
<ul class="ul" id="WN_12_09_2025__ul_dr3_w2s_qgc">
<li class="li">CIS Alibaba Foundations Benchmarkv2.0.0 </li>
<li class="li">CIS AWS Foundations Benchmark v5.0.0 </li>
<li class="li">CIS Azure Foundations Benchmark v3.0.0 </li>
<li class="li">CIS GCP Foundations Benchmark v4.0.0</li>
<li class="li">CIS OCI Foundations Benchmark v3.0.0 </li>
</ul>
<div class="p">You can view the CIS certifications awarded to Trend Micro Vision One - Cloud Posture
                  on the <a class="xref" href="https://www.cisecurity.org/partner/trend-micro" target="_blank">CIS partner website </a>and learn more about <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-vision-one-compliance-in-cloud-posture/" target="_blank">Compliance and Conformity</a>.</div>
</section><section class="section" id="WN_12_09_2025__gcp_rules">
<h3 class="section-title">New GCP Rules</h3>
<ul class="ul">
<li class="li">
<div class="p"><b class="b">CloudRun-002: Use Labels for Resource Management</b>: This rule ensures that user-defined labels are being used to tag, collect, and organize
                        Cloud Run services within your Google Cloud Platform (GCP) projects.</div>
</li>
<li class="li">
<div class="p"><b class="b">CloudRun-004: Enable End-to-End HTTP/2 for Cloud Run Services</b>: This rule ensures that end-to-end HTTP/2 support is enabled for your Cloud Run services.</div>
</li>
<li class="li">
<div class="p"><b class="b">CloudSQL-034: Allow SSL/TLS Connections Only</b>: This rule ensures that all incoming connections to your Cloud SQL database instances
                        are encrypted with SSL/TLS.</div>
</li>
<li class="li"><b class="b">CloudFunction-008: Use Customer-Managed Encryption Keys for Functions Encryption:</b> This rule ensures that your Google Cloud functions use Customer-Managed Encryption
                     Keys (CMEK) instead of Google-managed encryption keys.</li>
<li class="li"><b class="b">CloudRun-008: Use Customer-Managed Encryption Keys for Services Encryption</b>: This rule ensures that your Cloud Run services use Customer-Managed Encryption Keys
                     (CMEK) instead of Google-managed encryption keys.</li>
<li class="li"><b class="b">SecretManager-004: Use Customer-Managed Encryption Keys for Secret Manager Secret
                        Encryption</b>: This rule ensures that your Google Cloud Secret Manager secrets are encrypted using
                     Cloud KMS Customer-Managed Encryption Keys (CMEKs).</li>
<li class="li"><b class="b">CloudRun-006: Enable Binary Authorization </b>This rule ensures that Binary Authorization is enabled for Google Cloud Run services.</li>
<li class="li"><b class="b">SecretManager-002: Enable Destruction Delay for Secret Versions:</b> This rule ensures that a delayed destruction policy is configured for Google Secret
                     Manager secrets.</li>
<li class="li"><b class="b">CloudRun-007: Cloud Run Services with Inactive Service Accounts:</b> This rule ensures that your Cloud Run services are referencing existing, active service
                     accounts in order to prevent execution failures and operational disruptions.</li>
<li class="li"><b class="b">CloudSQL-038: Enable Cloud SQL Instance Encryption with Customer-Managed Keys</b>: This rule ensures that your Google Cloud SQL database instances are encrypted with
                     Customer-Managed Keys (CMKs).</li>
<li class="li"><b class="b">CloudRun-009: Enable Cloud SQL Instance Encryption with Customer-Managed Keys:</b> This rule ensures that Google Cloud Run services are not publicly accessible.</li>
<li class="li"><b class="b">CloudLogging-010: Configure Retention Policies with Bucket Lock: </b>This rule ensures that all the retention policies attached to your Google Cloud log
                     sink buckets are configured with the Bucket Lock feature.</li>
<li class="li"><b class="b">CloudFunction-011: Cloud Logging Permissions for Google Cloud Functions</b>: This rule ensures that Cloud Logging API has sufficient permissions to write logs
                     for your Google Cloud functions.</li>
<li class="li"><b class="b">NetworkConnectivity-001: Enable Cloud NAT for Private Subnets</b>: This rule ensures that Cloud NAT is enabled for all private VPC subnets that require
                     outbound access.</li>
<li class="li"><b class="b">ResourceManager-011: Prevent Service Account Creation for Google Cloud Organizations:</b> This rule ensure that the creation of Cloud IAM service accounts is prevented within
                     your Google Cloud organization through the "Disable Service Account Creation" organization
                     policy</li>
<li class="li"><b class="b">ResourceManager-008: Require OS Login</b>: This rule ensure that "Require OS Login" constraint policy is enforced at the GCP
                     organization level in order to enable OS Login feature on all newly created Google
                     Cloud projects within your organization. The OS Login provides you with centralized
                     and automated SSH key pair management.</li>
<li class="li"><b class="b">ResourceManager-013: Enforce Detailed Audit Logging Mode</b>: This rule checks that "Google Cloud Platform - Detailed Audit Logging Mode" policy
                     is enforced at the organization level in order to enable Detailed Audit Logging feature
                     for the supported Cloud Storage resources available within your GCP organization.</li>
</ul>
</section><section class="section" id="WN_12_09_2025__azure_rules">
<h3 class="section-title">New Azure Rules</h3>
<ul class="ul">
<li class="li"><b class="b">CosmosDB-012: Enable Microsoft Defender for Azure Cosmos DB Accounts</b>: This rule ensures that Microsoft Defender for Azure Cosmos DB is enabled at the
                     resource level.</li>
<li class="li"><b class="b">RedisCache-006: Configure Update Channel:</b> This rule ensure that your Microsoft Azure Cache for Redis servers are using the
                     "Stable" update channel.</li>
<li class="li">
<b class="b">RedisCache-008: Disable Access Keys Authentication for Azure Cache for Redis Servers</b>: This rule ensure that your Microsoft Azure Cache for Redis servers are configured
                     to use Microsoft Entra ID for authentication rather than access keys.</li>
<li class="li"><b class="b">ResourceManager-012: Disable Serial Port Access Support at Organization Level:</b> This rule checks that "Disable VM serial port access" constraint policy is enabled
                     for your Google Cloud Platform (GCP) organizations.</li>
<li class="li"><b class="b">RedisCache-005: Enable Data Persistence for Azure Cache for Redis Servers</b>: This rule checks that data persistence is enabled for your Microsoft Azure Cache
                     for Redis servers to ensure resilience against unexpected cache node failures.</li>
</ul>
</section>]]></description>
    <pubDate>Mon, 15 Sep 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-updates-12-sept-2025</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated AWS Custom Policy V1.72</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v-1-72</link>
    <description><![CDATA[<div class="p">September16, 2025, Conformity—The Conformity AWS custom policy has been updated to
               the latest version - 1.72, and the new permissions added is:</div><ul class="ul" id="WN_05082025_Updated_Custom_Policy_6e0c91a7_83a7_4355_a875_3b7ccec3707d_Copy__ol_fz5_snj_pgc">
<li class="li">inspector2:BatchGetAccountStatus </li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Tue, 16 Sep 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v-1-72</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Log Inspection now supports glob character in directory names</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-log-inspection-wildcard-dir</link>
    <description><![CDATA[<div class="p">September 17, 2025, Workload Security—In Log Inspection, in addition to the glob character
               support in file names, the glob character (wildcard) is now supported when used in
               the directory portion of the path no more than twice.</div>]]></description>
    <pubDate>Wed, 17 Sep 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-log-inspection-wildcard-dir</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Support for Oracle Linux 10</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-oracle-linux-10</link>
    <description><![CDATA[<div class="p">September 24, 2025, Workload Security—Deep Security Agent version 20.0.2-20480 (20
               LTS Update 2025-09-24) and later supports Oracle Linux 10 (64-bit), including SELinux,
               Secure Boot, and FIPS mode. This requires Deep Security Manager version 20.0.1081
               (20 LTS Update 2025-09-15) or later.</div>]]></description>
    <pubDate>Wed, 24 Sep 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-oracle-linux-10</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Updated AWS Custom Policy V1.73</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v173</link>
    <description><![CDATA[<div class="p">September 29, 2025, Conformity—The Conformity AWS custom policy has been updated to
               the latest version - 1.73, and the new permissions added is:</div><ul class="ul" id="WN_29092025_Updated_Custom_PolicyV73_4904a714_ce31_4ae2_9887_d6e5335eb334__ol_fz5_snj_pgc">
<li class="li"> eks:DescribeAddon</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Mon, 29 Sep 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v173</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated AWS Custom Policy V1.74 and V1.75</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v174-v175</link>
    <description><![CDATA[<div class="p">October 29, 2025, Conformity—The Conformity AWS custom policy has been updated to
               the latest version - 1.75 along with an interim update to version 1.74: </div><ul class="ul" id="WN_29_09_2025_Updated_Custom_PolicyV75_cf1e445b_ba2e_406b_889e_81bb0e5e8abf__ul_cmy_tzz_chc">
<li class="li">The new permissions added for V 1.74 are:
                  <ul class="ul" id="WN_29_09_2025_Updated_Custom_PolicyV75_cf1e445b_ba2e_406b_889e_81bb0e5e8abf__ul_cjt_xzz_chc">
<li class="li">sagemaker:ListTrainingJobs </li>
<li class="li">sagemaker:DescribeTrainingJob </li>
<li class="li">sagemaker:ListTags </li>
<li class="li">bedrock:GetModelInvocationLoggingConfiguration </li>
<li class="li">bedrock:ListModelCustomizationJobs </li>
<li class="li">bedrock:GetModelCustomizationJob</li>
</ul>
</li>
</ul><ul class="ul" id="WN_29_09_2025_Updated_Custom_PolicyV75_cf1e445b_ba2e_406b_889e_81bb0e5e8abf__ol_fz5_snj_pgc">
<li class="li">
<div class="p">The new permissions added for V1.75 are: </div>
<ul class="ul" id="WN_29_09_2025_Updated_Custom_PolicyV75_cf1e445b_ba2e_406b_889e_81bb0e5e8abf__ul_sss_tzz_chc">
<li class="li"> trustedadvisor:ListChecks</li>
<li class="li">trustedadvisor:ListOrganizationRecommendationAccounts</li>
<li class="li">trustedadvisor:ListOrganizationRecommendationResources</li>
<li class="li">trustedadvisor:ListOrganizationRecommendations</li>
<li class="li">trustedadvisor:ListRecommendationResources</li>
<li class="li">trustedadvisor:ListRecommendations</li>
<li class="li">trustedadvisor:GetRecommendation</li>
<li class="li">trustedadvisor:GetOrganizationRecommendation</li>
</ul>
</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Wed, 29 Oct 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v174-v175</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated AWS Custom Policy V1.76</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v176</link>
    <description><![CDATA[<div class="p">November 06, 2025, Conformity—The Conformity AWS custom policy has been updated to
               the latest version - 1.76.</div><ul class="ul" id="WN_05_11_2025_Updated_Custom_PolicyV76_41711509_9455_4501_b4c9_7d376915e9ba__ul_cmy_tzz_chc">
<li class="li">The new permissions added are
                  <ul class="ul" id="WN_05_11_2025_Updated_Custom_PolicyV76_41711509_9455_4501_b4c9_7d376915e9ba__ul_p24_rsy_2hc">
<li class="li">sagemaker:ListEndpointConfigs </li>
<li class="li">sagemaker:DescribeEndpointConfig</li>
</ul>
</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Thu, 06 Nov 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v176</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated IAU Update Module Version in GCP Pattern Update Function</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-wn-gcp-pattern-update-function</link>
    <description><![CDATA[<div class="p">November 12, 2025—The GCP pattern update function now uses an updated version of the
               Trend Core Common Module – IAU Update. This change ensures compatibility with recent
               modifications on the IAU Update server and maintains reliable delivery of scanning
               pattern updates.</div>]]></description>
    <pubDate>Wed, 12 Nov 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-wn-gcp-pattern-update-function</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity Releases New Template Scanner Resources</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-Template-Scanner-Update-1411</link>
    <description><![CDATA[<div class="p"></div><div class="p">November 14, 2025—Conformity released new Google Cloud resources for Template Scanner
               to enable comprehensive security and compliance checks across the cloud environment.
               The following resources facilitate automated scanning and validation of infrastructure-as-code
               templates, ensuring that deployments adhere to best practices and organizational policies.
               For the full list of resources, see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-template-scanner-coverage" target="_blank">Template Scanner Coverage</a>.</div><div class="p"><b class="b">Google Cloud</b></div><div class="p">
<ul class="ul">
<li class="li">
<div class="p">ArtifactRegistry Repositories (<code class="codeph">artifactregistry-repositories</code>)</div>
</li>
<li class="li">
<div class="p">CloudIAM Service Accounts (<code class="codeph">cloudiam-service-accounts</code>)</div>
</li>
<li class="li">
<div class="p">CloudIAM Access Approval Settings (<code class="codeph">cloudiam-accessapproval-settings</code>)</div>
</li>
<li class="li">
<div class="p">CloudLoadBalancing Backends (<code class="codeph">cloudloadbalancing-backends</code>)</div>
</li>
<li class="li">
<div class="p">CloudLoadBalancing UrlMaps (<code class="codeph">cloudloadbalancing-urlmaps</code>)</div>
</li>
<li class="li">
<div class="p">BigQuery Datasets (<code class="codeph">bigquery-datasets</code>)</div>
</li>
<li class="li">
<div class="p">CloudLogging Log Buckets (<code class="codeph">cloudlogging-log-buckets</code>)</div>
</li>
<li class="li">
<div class="p">Dataproc Clusters (<code class="codeph">dataproc-clusters</code>)</div>
</li>
<li class="li">
<div class="p">Filestore Instances (<code class="codeph">filestore-instances</code>)</div>
</li>
<li class="li">
<div class="p">CertificateManager Certificates (<code class="codeph">certificatemanager-certificates</code>)</div>
</li>
<li class="li">
<div class="p">SecretManager Secrets (<code class="codeph">secretmanager-secrets</code>)</div>
</li>
</ul>
</div>]]></description>
    <pubDate>Fri, 14 Nov 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-Template-Scanner-Update-1411</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated AWS Custom Policy V1.77</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v177</link>
    <description><![CDATA[<div class="p">November 19, 2025, Conformity—The Conformity AWS custom policy has been updated to
               the latest version - 1.77.</div><ul class="ul" id="WN_19_11_2025_Updated_Custom_PolicyV77_20b9fa4d_1b2e_4419_a85d_0b6c688e4fa2__ul_cmy_tzz_chc">
<li class="li">The new permissions added are
                  <ul class="ul" id="WN_19_11_2025_Updated_Custom_PolicyV77_20b9fa4d_1b2e_4419_a85d_0b6c688e4fa2__ul_jfh_3ny_3hc">
<li class="li">amplify:ListResourcesForWebACL</li>
<li class="li">apprunner:DescribeWebAclForService</li>
<li class="li">apprunner:ListAssociatedServicesForWebAcl</li>
<li class="li">cloudfront:ListDistributionsByWebACLId</li>
<li class="li">cognito-idp:ListResourcesForWebACL</li>
<li class="li">cognito-idp:GetWebACLForResource</li>
<li class="li">ec2:DescribeVerifiedAccessInstances</li>
<li class="li">ec2:DescribeVerifiedAccessInstanceWebAclAssociations</li>
<li class="li">ec2:GetVerifiedAccessInstanceWebAcl</li>
<li class="li">wafv2:ListResourcesForWebACL</li>
</ul>
</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v177</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Support for Windows 11 25h2</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-suppport-for-windows-11-25h2</link>
    <description><![CDATA[<div class="p">Deep Security Agent 20.0.2-26670 and later supports Windows 11, version 25H2.</div>]]></description>
    <pubDate>Tue, 25 Nov 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-suppport-for-windows-11-25h2</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Support for Debian 13</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-debian-13</link>
    <description><![CDATA[<div class="p">Debian Linux 13 support: Deep Security Agent 20.0.2-26670 and later supports Debian
               Linux 13 including Secure Boot support and FIPS mode support. This requires Deep Security
               Manager 20.0.1112 or later.</div>]]></description>
    <pubDate>Tue, 25 Nov 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-debian-13</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Support for Rocky Linux 10</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-rocky-linux-10</link>
    <description><![CDATA[<div class="p">November 25, 2025—Deep Security Agent 20.0.2-26670 and later now supports Rocky Linux
               10, including SELinux, Secure Boot, and FIPS mode support.</div>]]></description>
    <pubDate>Tue, 25 Nov 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-support-for-rocky-linux-10</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Conformity Releases New CIS Azure and AWS compliance standards</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-cis-azure-aws-standards-12-12</link>
    <description><![CDATA[<div class="p"></div><div class="p">December 12, 2025—Trend Cloud One - Conformity has released the following new compliance
               standards</div><div class="p"><b class="b">CIS Foundations Benchmarks. - CIS Azure Foundations Benchmark v4.0.0</b>: Conformity has updated the CIS Azure compliance standard to the latest version to
               meet the Center of Internet Security (CIS) Foundations Benchmarks for Microsoft Azure.
               You can now filter Checks and download Compliance Reports to ensure your cloud environment
               complies with the latest CIS Foundations Benchmarks. - CIS Azure Foundations Benchmark
               v4.0.0. </div><div class="p"><b class="b">Deprecation Notice</b>: Conformity has deprecated the CIS Azure Foundations Benchmark v2.1.0 for removal
               on <b class="b">February 8 2026</b>. It will no longer be accessible in the filters, preventing the creation of new reports
               or report-configurations with this outdated benchmark. If any existing report configurations
               include deprecated compliance standards, it will not be possible to generate new PDF/CSV
               reports. However, the list of previously generated PDF/CSV reports remains available.
               Trend Cloud One - Conformity recommends updating your report configurations to use
               the latest versions of CIS Azure Foundations Benchmark before <b class="b">February 8 2026</b>.</div><div class="p"></div><div class="p"><b class="b">AWS Well-Architected Framework Generative AI Lens</b>: Trend Cloud One - Conformity has added support for the new Amazon Web Services Well-Architected
               Framework Generative AI Lens. Generative AI Lens is an extension of the AWS Well-Architected
               Framework, complementing the AWS WAF with Gen AI specific controls.</div>]]></description>
    <pubDate>Fri, 12 Dec 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-new-cis-azure-aws-standards-12-12</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity Releases New Template Scanner Azure Resources</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-update-12-12</link>
    <description><![CDATA[<div class="p"></div><div class="p">December 12, 2025—Trend Cloud One Conformity Template Scanner has added the following
               updates to support your Azure cloud infrastructure. For the full list of resources,
               see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-template-scanner-coverage" target="_blank">Template Scanner Coverage</a>.</div><ul class="ul" id="WN_12_12_2025_TemplateScannerNewAzureResources_567a5a36_416e_4938_b4c6_b057b095b2d6__ul_zzg_114_4hc">
<li class="li">New Azure resources
                  <ul class="ul" id="WN_12_12_2025_TemplateScannerNewAzureResources_567a5a36_416e_4938_b4c6_b057b095b2d6__ul_bhr_d14_4hc">
<li class="li">DNS Zones</li>
<li class="li">DNS Private Zones</li>
<li class="li">FrontDoor Profiles</li>
<li class="li">Access Control Roles</li>
<li class="li">Acccess Control Custom Roles</li>
<li class="li">MachineLearning Learning Workspaces</li>
<li class="li">SecurityCenter Tasks</li>
<li class="li">SecurityCenter Alerts</li>
<li class="li">SecurityCenter Pricings</li>
<li class="li">CosmosDB Servers</li>
</ul>
</li>
</ul><ul class="ul" id="WN_12_12_2025_TemplateScannerNewAzureResources_567a5a36_416e_4938_b4c6_b057b095b2d6__ul_hmx_d14_4hc">
<li class="li">API Management Management APIs</li>
</ul><ul class="ul" id="WN_12_12_2025_TemplateScannerNewAzureResources_567a5a36_416e_4938_b4c6_b057b095b2d6__ul_qnc_214_4hc">
<li class="li">SQL Servers</li>
</ul>]]></description>
    <pubDate>Fri, 12 Dec 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-update-12-12</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Support for Ubuntu 24.04 AWS Arm-based Graviton2</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-suppport-for-ubuntu24-arm-v8</link>
    <description><![CDATA[<div class="p">Ubuntu 24.04 (AWS Arm-based Graviton2) support: Deep Security Agent 20.0.2-29370 and
               later supports Ubuntu 24.04 (AWS Arm-based Graviton2). This requires Deep Security
               Manager 20.0.1123 or later.</div>]]></description>
    <pubDate>Fri, 19 Dec 2025 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-suppport-for-ubuntu24-arm-v8</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Updated AWS Custom Policy V1.78</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v178</link>
    <description><![CDATA[<div class="p">February 26, 2026, Conformity—The Conformity AWS custom policy has been updated to
               the latest version - 1.78.</div><ul class="ul" id="WN_26_02_2026_Updated_Custom_PolicyV78_b2c3d4e5_f6a7_8901_bcde_f12345678901__ul_aws_policy_v178">
<li class="li">The new permissions added are
                  <ul class="ul" id="WN_26_02_2026_Updated_Custom_PolicyV78_b2c3d4e5_f6a7_8901_bcde_f12345678901__ul_permissions_v178">
<li class="li">bedrock-agentcore:ListAgentRuntimes</li>
</ul>
</li>
</ul><div class="p"><a class="xref" href="https://adc.github.trendmicro.com/v1-cspm-conformity/util-custom-policy/blob/CPS-6112/CloudConformity.template" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Thu, 26 Feb 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v178</guid>
    <category>Conformity</category>
</item>
<item>
    <title>File Storage Security for AWS auto-cleans out-of-date Lambda versions</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fss-autoclean-outofdate-lambda</link>
    <description><![CDATA[<div class="p">February 26, 2026—File Storage Security now includes an auto-cleanup feature that
               removes older Lambda versions. You must redeploy your Client Stack to enable this
               feature as it requires additional IAM permissions.</div>]]></description>
    <pubDate>Thu, 26 Feb 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fss-autoclean-outofdate-lambda</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Conformity Releases Support for Oracle Cloud Infrastructure Well-Architected Framework</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-oci-well-architected</link>
    <description><![CDATA[<div class="p"></div><div class="p">March 02, 2026—Trend Cloud One - Conformity now supports the Oracle Cloud Infrastructure
               Well-Architected Framework (updated 2025). You can now sort OCI checks and generate
               reports based on this best practices framework to ensure their cloud environment aligns
               with Oracle's architectural guidance.</div>]]></description>
    <pubDate>Mon, 02 Mar 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-conformity-oci-well-architected</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Conformity Releases New Template Scanner AWS Resources</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-update-16-mar</link>
    <description><![CDATA[<div class="p"></div><div class="p">March 10, 2026—Trend Cloud One Conformity Template Scanner has added the following
               updates to support your AWS cloud infrastructure. For the full list of resources,
               see <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-conformity-template-scanner-coverage" target="_blank">Template Scanner Coverage</a>.</div><div class="p">The following AWS resources are now supported by Template Scanner in Terraform:</div><ul class="ul" id="WN_16_03_2026_TemplateScannerNewAWSResources_23f306a2_4925_4d56_8575_429dd388047c__ul_aws_bedrock">
<li class="li">Bedrock Agent</li>
<li class="li">Bedrock Custom Model</li>
<li class="li">Bedrock Guardrail</li>
<li class="li">Bedrock Knowledge Base</li>
<li class="li">Bedrock Model Invocation Logging Configuration</li>
</ul><ul class="ul" id="WN_16_03_2026_TemplateScannerNewAWSResources_23f306a2_4925_4d56_8575_429dd388047c__ul_aws_iam">
<li class="li">IAM Certificate</li>
<li class="li">IAM Account Password Policy</li>
<li class="li">IAM OpenID Connect Provider</li>
<li class="li">IAM SAML Provider</li>
<li class="li">IAM User</li>
</ul><ul class="ul" id="WN_16_03_2026_TemplateScannerNewAWSResources_23f306a2_4925_4d56_8575_429dd388047c__ul_aws_sagemaker">
<li class="li">SageMaker Domain</li>
<li class="li">SageMaker Endpoint</li>
<li class="li">SageMaker Endpoint Config</li>
<li class="li">SageMaker Model</li>
<li class="li">SageMaker Notebook Instance</li>
</ul>]]></description>
    <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-template-scanner-update-16-mar</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Upcoming EKS rule updates for enhanced security and network policy validation</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upcoming-eks-rule-updates-for-enha</link>
    <description><![CDATA[<div class="p">March 12, 2026, Conformity—Upcoming Rule Updates</div><div class="p">Release Date: March 18, 2026</div><div class="p">The following rules will be updated to align with the latest industry recommendations.
               These updates introduce stricter evaluation criteria, which may result in changes
               to your compliance scores. It is recommended that you review the affected rules and
               any newly flagged resources ahead of the effective date.</div><div class="p"><b class="b">AWS</b></div><ul class="ul" id="WN_2026_03_12_a49d2915_331f_4065_8131_20a863001401__ul_eks_updates">
<li class="li"><b class="b">EKS-001: EKS Cluster Endpoint Public Access</b>: Now requires endpointPrivateAccess to be enabled. See <a class="xref" href="https://www.trendmicro.com/trendaivisiononecloudriskmanagement/knowledge-base/aws/EKS/endpoint-access.html" target="_blank">EKS-001 documentation</a> for further details.</li>
<li class="li"><b class="b">EKS-006: Enable Network Policies</b>: Now validates presence of the VPC CNI addon. See <a class="xref" href="https://www.trendmicro.com/trendaivisiononecloudriskmanagement/knowledge-base/aws/EKS/enable-network-policies.html" target="_blank">EKS-006 documentation</a> for further details.</li>
</ul>]]></description>
    <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upcoming-eks-rule-updates-for-enha</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated AWS Custom Policy V1.79</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v179</link>
    <description><![CDATA[<div class="p">March 16, 2026, Conformity—The Conformity AWS custom policy has been updated to the
               latest version - 1.79.</div><ul class="ul" id="WN_16_03_2026_Updated_Custom_PolicyV79_65ccc7de_6512_41ad_b3f6_ee6ac6ad44e0__ul_aws_policy_v179">
<li class="li">The new permissions added are
                  <ul class="ul" id="WN_16_03_2026_Updated_Custom_PolicyV79_65ccc7de_6512_41ad_b3f6_ee6ac6ad44e0__ul_permissions_v179">
<li class="li">eks:DescribeNodegroup</li>
<li class="li">eks:ListNodegroups</li>
<li class="li">ec2:DescribeLaunchTemplateVersions</li>
</ul>
</li>
</ul><div class="p"><a class="xref" href="https://us-west-2.cloudconformity.com/v1/policies" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v179</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Upcoming Azure rule updates for MFA scoring and Function App evaluation changes</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upcoming-azure-rule-updates-for-mfa</link>
    <description><![CDATA[<div class="p">March 19, 2026, Conformity—Upcoming Rule Updates</div><div class="p">Release Date: March 26, 2026</div><div class="p">The following rules will be updated to align with the latest industry recommendations.
               These updates introduce stricter evaluation criteria, which may result in changes
               to your compliance scores. It is recommended that you review the affected rules and
               any newly flagged resources ahead of the effective date.</div><div class="p"><b class="b">Azure</b></div><div class="p">The following MFA rules are now scored and will affect your compliance scores:</div><ul class="ul" id="WN_26_03_2026_AnnounceRuleUpdates_986eec1b_f653_4245_9678_da48f91741be__ul_mfa_rules">
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/azure/ActiveDirectory/multi-factor-authentication-for-all-privileged-users.html" target="_blank">ActiveDirectory-001: Enable Multi-Factor Authentication for Privileged Users</a></li>
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/azure/ActiveDirectory/multi-factor-authentication-for-all-non-privileged-users.html" target="_blank">ActiveDirectory-002: Enable Multi-Factor Authentication for Non-Privileged Users</a></li>
</ul><div class="p">The following rules no longer evaluate on Function Apps:</div><ul class="ul" id="WN_26_03_2026_AnnounceRuleUpdates_986eec1b_f653_4245_9678_da48f91741be__ul_function_app_rules">
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/azure/AppService/enable-incoming-client-certificates.html" target="_blank">AppService-008: Check that the Azure App requests incoming client certificates</a></li>
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/azure/AppService/enable-app-service-authentication.html" target="_blank">AppService-010: Enable App Service Authentication</a></li>
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/azure/AppService/disable-remote-debugging.html" target="_blank">AppService-011: Disable Remote Debugging</a></li>
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/azure/AppService/enable-automated-backups.html" target="_blank">AppService-013: Enable Automated Backups</a></li>
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/azure/AppService/enable-always-on.html" target="_blank">AppService-015: Enable Always On</a></li>
<li class="li"><a class="xref" href="https://www.trendmicro.com/cloudoneconformity/knowledge-base/azure/LogicApps/disable-public-network-access.html" target="_blank">LogicApps-001: Disable Public Network Access to Azure Logic Apps</a></li>
</ul>]]></description>
    <pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upcoming-azure-rule-updates-for-mfa</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Support for SUSE Linux Enterprise Server 16</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-suse-linux-16</link>
    <description><![CDATA[<div class="p">SUSE Linux Enterprise Server 16 (64-bit) support: Deep Security Agent 20.0.3-5660
               and later supports SUSE Linux Enterprise Server 16 (64-bit), including SELinux, Secure
               Boot, and FIPS mode.</div>]]></description>
    <pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-suse-linux-16</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Support for Red Hat Enterprise Linux 10 on Arm architecture</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rhel-10-arm</link>
    <description><![CDATA[<div class="p">Red Hat Enterprise Linux 10 (64-bit Arm (aarch64)) support: Deep Security Agent 20.0.3-5660
               and later supports Red Hat Enterprise Linux 10 (64-bit Arm (aarch64)), including SELinux
               and Secure Boot.</div>]]></description>
    <pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-rhel-10-arm</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Updated compliance standard: CIS Azure Foundations Benchmark v5.0.0</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cis-azure-foundations-v5</link>
    <description><![CDATA[<div class="p"></div><div class="p"><b class="b">Updated compliance standard: CIS Foundations Benchmarks</b></div><div class="p">We have updated our compliance standards to meet the Center for Internet Security
               (CIS) Foundations Benchmarks for Microsoft Azure. You can now filter Checks and download
               Compliance Reports to ensure your cloud environment complies with the latest CIS Foundations
               Benchmarks.</div><ul class="ul" id="WN_CIS_Azure_v5_bf092392_a1b1_47c2_9d70_23cbbdecc5af__ul_cis_azure_v5">
<li class="li">CIS Azure Foundations Benchmark v5.0.0</li>
</ul><div class="p"><b class="b">Removal notice</b></div><div class="p">CIS Azure Foundations Benchmark v3.0.0 will be removed on <b class="b">April 29, 2026</b>. After this date, it will no longer be accessible in filters, and you will not be
               able to create new reports or report configurations with this benchmark. Previously
               generated PDF and CSV reports will remain available. We recommend updating your report
               configurations to use CIS Azure Foundations Benchmark v5.0.0 before <b class="b">April 29, 2026</b>.</div><div class="p">You can view the CIS certifications awarded to Trend Micro on the <a class="xref" href="https://www.cisecurity.org/partner/trend-micro" target="_blank">CIS partner website</a> and find out more about <a class="xref" href="https://docs.trendmicro.com/en-us/documentation/article/trend-vision-one-compliance-in-cloud-posture/" target="_blank">compliance in Cloud Posture</a> in our documentation.</div>]]></description>
    <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-cis-azure-foundations-v5</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Upcoming Azure App Service rule updates</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upcoming-azure-appservice-rule-upda</link>
    <description><![CDATA[<div class="p">March 25, 2026, Conformity—Upcoming Rule Updates</div><div class="p">Release Date: March 31, 2026</div><div class="p">The following rules will be updated to align with the latest industry recommendations.
               These updates introduce stricter evaluation criteria, which may result in changes
               to your compliance scores. It is recommended that you review the affected rules and
               any newly flagged resources ahead of the effective date.</div><div class="p"><b class="b">Azure</b></div><div class="p">All App Service rules no longer consider Azure Function resources when performing
               checks. This
               may lead to a reduction in both success and failure checks, which could influence
               compliance
               scores. Consult the App Service and Function knowledge base articles for more information.</div>]]></description>
    <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-upcoming-azure-appservice-rule-upda</guid>
    <category>Conformity</category>
</item>
<item>
    <title>GCP Cloud functions runtime updated in the TrendAI Cloud One File Storage Security GCP template</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fss-gcp-cloud-template-updated</link>
    <description><![CDATA[<div class="p">March 31, 2026—<span class="tm">TrendAI™</span> Cloud One File Security Storage is upgrading the GCP Cloud Functions runtime from
               Node.js 20 to Node.js 22 in the <span class="tm">TrendAI™</span> Cloud One File Security Storage (GCP) template. Google Cloud has scheduled Node.js
               20 for deprecation on April 30, 2026. After this date, functions running on deprecated
               runtimes will no longer receive security patches and may be blocked from deployment.</div>]]></description>
    <pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-fss-gcp-cloud-template-updated</guid>
    <category>File Storage Security</category>
</item>
<item>
    <title>Support for AlmaLinux 10</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-almalinux-10</link>
    <description><![CDATA[<div class="p">AlmaLinux 10 (64-bit) support: Deep Security Agent 20.0.3-8130 and later supports
               AlmaLinux 10 (64-bit), including SELinux, Secure Boot, and FIPS mode.</div>]]></description>
    <pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-almalinux-10</guid>
    <category>Workload Security</category>
</item>
<item>
    <title>Updated AWS Custom Policy V1.82</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v182</link>
    <description><![CDATA[<div class="p">April 28, 2026, Conformity—The Conformity AWS custom policy has been updated to the
               latest version - 1.82.</div><ul class="ul" id="WN_27_04_2026_Updated_Custom_PolicyV82_b8567fd7_9ca4_46fa_b73f_f4c0c53daa09__ul_aws_policy_v182">
<li class="li">The new permissions added are
                  <ul class="ul" id="WN_27_04_2026_Updated_Custom_PolicyV82_b8567fd7_9ca4_46fa_b73f_f4c0c53daa09__ul_permissions_v182">
<li class="li">application-autoscaling:GetPredictiveScalingForecast</li>
<li class="li">application-autoscaling:ListTagsForResource</li>
</ul>
</li>
</ul><div class="p"><a class="xref" href="https://github.com/trend-crm/util-custom-policy/blob/CPS-6544/CloudConformity.template" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v182</guid>
    <category>Conformity</category>
</item>
<item>
    <title>Updated AWS Custom Policy V1.83</title>
    <link>https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v183</link>
    <description><![CDATA[<div class="p">May 05, 2026, Conformity—The Conformity AWS custom policy has been updated to the
               latest version - 1.83 and the permissions added are:</div><ul class="ul" id="WN_05_05_2026_Updated_Custom_PolicyV83_93eb1599_e6b2_481a_ac73_39b51b9367cc__ul_aws_policy_v183_bedrock">
<li class="li"><code class="codeph">bedrock-agentcore:ListAgentRuntimeEndpoints</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetAgentRuntimeEndpoint</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListTagsForResource</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetResourcePolicy</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListAgentRuntimeVersions</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListGateways</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetGateway</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListGatewayTargets</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetGatewayTarget</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListPolicyEngines</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetPolicyEngine</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListPolicyGenerations</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetPolicyGeneration</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListPolicies</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetPolicy</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListPolicyGenerationAssets</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListApiKeyCredentialProviders</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetApiKeyCredentialProvider</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListOauth2CredentialProviders</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetOauth2CredentialProvider</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetTokenVault</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListWorkloadIdentities</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetWorkloadIdentity</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListBrowsers</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetBrowser</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListBrowserProfiles</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetBrowserProfile</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListEvaluators</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetEvaluator</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListOnlineEvaluationConfigs</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetOnlineEvaluationConfig</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListCodeInterpreters</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetCodeInterpreter</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:ListMemories</code></li>
<li class="li"><code class="codeph">bedrock-agentcore:GetMemory</code></li>
</ul><div class="p"><a class="xref" href="https://github.com/trend-crm/util-custom-policy/blob/CPS-6552/CloudConformity.template" target="_blank">Click here</a> to access the new custom policy.</div>]]></description>
    <pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate>
    <guid isPermaLink="false">https://docs.trendmicro.com/en-us/documentation/article/trend-micro-cloud-one-main-updated-aws-custom-policy-v183</guid>
    <category>Conformity</category>
</item>
   </channel>
</rss>
