- Navigate to Application > Xray > Watches & Policies.
- In the Policies tab, click New Policy.
- Enter a Policy Name.
- (Optional) Add a Description explaining the policy's purpose.
- Under Select Policy Type, select Security, and hit Next.
The Create New Policy Rule window opens. - Enter a Rule Name.
- Under Rule Type, select Exposures.
- Under Select at least one category, select one or more exposure categories to be detected by the policy:
- Secrets
- Services
- Applications
- IaC
- From the Select minimal severity menu, select the severity level to trigger the policy violation.
- Under Then, define the policy actions, select Save Rule, and hit Next.
- Under Apply on Scope, select one or more policy watches and hit Save Policy.