A security policy defined at the admin domain level is inherited by its child admin domains, and the resources—Sensor interfaces and sub-interfaces—within the child domains unless the policy is explicitly set during resource configuration. If you want to set another policy for a specific resource, you can select or create a different policy.
The policy inheritance order is shown below.
When you allocate Sensor interfaces to an admin domain (a process that is part of child admin domain creation), all of the interfaces automatically inherit the admin domain's policy. So, as part of the process of creating an admin domain, you assign the policy to be inherited by the allocated interfaces. If you want, you can then go into each allocated interface and assign a different policy.
Changing policies at higher levels (for example, admin domain level) once they have been applied at a lower level has no effect on the lower levels (for example, interface level).
Note
A custom policy defined at a child admin domain level can't be applied to a resource at the parent admin domain level.