How to create a third-party scanning workflow?
Steps:
- Proxy into the Enterprise Account
- Create the Application Profile
- Assign the Policy you want the 3rd Party Vendor to scan against
- Under “Submission of Scan Data”, select the radio button “Application is developed/maintained by a third party, the third party will submit the scan data”
- Click in “Request new vendor”. Enter in the required fields marked with a red asterisk
- When adding the “Account Name”, use the naming convention “Vendor (Enterprise)”, this way a 3rd Party Vendor account stays unique and can quickly be associated with a particular Enterprise and not cause confusion if the Vendor is used by multiple Enterprises. Click “OK” when done
- Determine whether or not the Enterprise is allowing the 3rd Party Vendor to rescan their application before publishing their results to the Enterprise. If Vendor rescanning is allowed, then check the box “Enable Vendor Rescanning”. **Note: This is a feature switch that must be enabled on the Enterprise Account in order to see this on the Application Profile level.
- Once the Application Profile is created click on “Save and Continue”
- Support needs to accept the 3rd Part Vendor as a new organization
- Once accepted, proxy into the Enterprise, select the new 3rd Party Vendor Application and click on “Request a Scan” dropdown and select “Request a Static and/or Dynamic Scan”
This will send a platform email to the 3rd Party Vendor that there is a scan request waiting for them from the Enterprise.
- Send a “Getting Started Guide” email to the 3rd Party Vendor
- The 3rd Party Vendor needs to proxy into their account and click on the Application Profile and click on the “Accept Request” button
and check off that they have read the “Assessment Agreement” and click on “Continue” to begin scanning
- The 3rd Party Vendor continues to upload and scan normally. Once the scan is completed, they will have options outlined by their Enterprise for next steps. See common questions below that are asked that will determine what feature switches should be turned on the Enterprise account.
- Does Enterprise allow Vendor rescanning?
- Does the Vendor have to pass Enterprise Policy before “Publishing”?
- Do mitigations have to be in TSRV Format?
- Are 3rd Party Vendors allowed to approve their own mitigations?
- The last step is for the Vendor to click on the “Publish to Enterprise”
button when the 3rd Party Vendor clicks on the Application profile. This will send the results to the Enterprise and close the loop with the 3rd Party Vendor. The 3rd Party Vendor can no longer scan unless a request is triggered by the Enterprise again.
Topics (2)
Related Articles
Not able to Promote a Sandbox Scan to the Policy Scan 1.63KNumber of Views Maximum number of keywords in Discovery Scan 404Number of Views Why is no source code info displayed for certain scans under Triage Flaw? 921Number of Views Report saying that not all modules were scanned 1.55KNumber of Views What does "The following modules were not selected for a full scan" mean in the PDF report for the scan? 2.85KNumber of Views
This topic isn't available in this community.
Related Topics
Ask the Community
Get answers, share a use case, discuss your favorite features, or get input from the Community.
.png)