You can create new rules by cloning the existing ones with predefined NGL query definition, category, remediation steps, and description. You can edit the fields of the cloned rule and make your own version of the rule. This feature is beneficial when you want to modify an existing rule with minor changes, for example, by modifying a condition or category or if you want to change the severity of any existing rule. Clone rule feature will allow you to make these minor changes and create your own new rule.
To create a new SaaS security posture rule by cloning an existing rule, follow the procedure:
-
Log in to the Netskope tenant UI.
-
Navigate to Policies > SaaS Security Posture Management.
-
Navigate to Rules tab. The screen shows the list of rules supported by SSPM.
-
Select any rule by clicking on it. A side panel will be opened with the rule details.

-
Click Clone in the top right corner of the side panel. A New Custom Rule sidebar opens.

-
You can edit the rule name, severity, definition, category, and description of the cloned rule. The remediation steps are not copied, you can add remediation instructions in the tab.
-
Click Validate Definition in the Definition tab to validate the rule and fix any syntax errors.
-
Click Save.
-
The rule is displayed in the Rules tab.
-
View and Apply pending changes.

