Differences: Suppressing a Violation, Disabling a Policy, and Removing a Policy

A policy violation is the infringement of a policy rule. A policy rule is a condition or threshold that is tested against a set or parameters or defaults, and used to enforce a standard.

Suppressing a Violation

When you suppress a policy violation, by default the violation no longer displays on the console pages for the specified target. For example, the suppressed violation is not included in any displayed violation counts. However, the underlying policy rule is still being evaluated and violations are still being logged and cleared as appropriate. Note: From any of the policy-related console pages, it is possible to override the default display such that all violations, including suppressed violations, are shown. For example, from the Policy Violations page, you can view all the violations by deselecting the Ignore suppressed violations check box.

One of the advantages of suppressing a violation is that while you are working to solve the policy violation, the other administrators are not distracted by the visible reference to this policy violation. Note: At any time it is possible to remove the suppression tag for a violation.

For information on how to suppress a violation, see Suppressing Violations.

Disabling a Policy

When you disable a policy evaluation for a target, while the policy is still associated with a target, Enterprise Manager no longer evaluates the policy rule for that target. Note: Disabling a policy rule evaluation results in the removal of all violations against that policy for the target specified . If you enable a disabled policy, violations will not be detected or visible until the next evaluation occurs.

For information on how to disable a policy, see Disabling and Enabling a Policy Rule Evaluation for a Single Target.

Removing a Policy

When you remove a policy from a target, you are actually removing the association between the policy and the target. Removing the association results in the policy not being evaluated for that target.

To remove the association between the policy and the target, access the Policies tab on the Metric and Policy Settings page for a specific target. Select the policy rule from the list displayed in the table and click Remove. The policy rule will not be evaluated for that target.

Examples

When to Disable a Policy

You disable a policy when you want to temporarily stop evaluations of that policy rule. The following is an example.

The Profiles with Excessive Allowed Failed Login Attempts policy has been associated with the Human Resources Database Instance target. An administrator has customized the Profiles with Excessive Allowed Failed Login Attempts policy for that target by specifying parameter values, corrective actions, and excluded objects. The administrator does not want to lose the customizations but does want to temporarily disable the policy rule from being evaluated.

The administrator should disable the Profiles with Excessive Allowed Failed Login Attempts policy. The policy is still associated with the Human Resources Database Instance target but the policy rule is not evaluated. At any point in the future, the administrator can reenable the Profiles with Excessive Allowed Failed Login Attempts policy and all the previously specified customizations remain.

When to Remove a Policy Association

You remove a policy association when you no longer want to ensure compliance of a policy against a particular target. The following is an example.

The administrator removes the association of the Profiles with Excessive Allowed Failed Login Attempts policy with the Human Resources Database Instance target. When the administrator removes the association, all customizations are deleted.

If the administrator later decided to reenable the policy rule, the administrator would need to reassociate the policy rule and also respecify the desired customizations.

Summary

Administrators should disable a policy rule when they want to temporarily stop evaluations, but remove the policy association when they do not want to ensure compliance for that policy rule.

Related Topics

About Policies

Enterprise Manager Information Roadmap