An alarm matching policy defines the alarms for which security control policies are executed. When the alarm module receives an alarm, the system determines whether the alarm is a concerned one for the Security Control Center (SCC) according to the alarm matching policy. The system provides alarm matching policies for SecCenter attack alarms by default. You are allowed to define concerned alarms, alarm variable matching rules, and action/alarm variable mappings, and modify existing alarm matching policies. Alarm variable matching rules help SCC component identify the user-defined alarms. When an alarm arrives, the SCC component determines whether to pay attention to the alarm according to the alarm OID and then determines whether the alarm is a concerned one according to the configured regular expression. If the alarm matches the regular expression, SCC component considers it as a concerned alarm. Then, the SCC component assigns a value to the action according to the action/alarm variable mapping, matches a security control policy, and performs the action according to the matched policy. For automatic execution, SCC component automatically triggers the action. For manual execution, SCC does not act until you trigger the action.