Analytics GroupKP7766 (Community Member) asked a question.

In the Scans Explore, is there a way to limit the "Average Flaws per MB - Analysis Size v1" measure to calculate only including policy-disallowed flaws?

Looking for a way to tailor this metric to calculate the Average Flaws per MB flaw density for only the flaws that are disallowed by an application's policy. The "Fix for Policy" dimension available in the Findings explore is not available in the Scans explore (the only place with the Average Flaws per MB). Any way around this to produce the result of a flaw density measure that produces policy-disallowed flaws flaws/MB?


  • Hi KP7766,

    That is a good point. We don't currently support that use-case today. I added something to the team's backlog for providing a count of flaws that are disallowed by policy on a per scan basis to the scan explore. The team is focused on a few other things right now so it may be a bit before we can get to that.

     

    I'm guessing you are asking this b/c your policy is more complicated than just disallowing findings by severity or OWASP - which are currently available the scans explore.

     

    To get around this gap, you could filter your scans to the most recent policy scan per application ("Is the Most Recent Scan by Type (Yes/No)") and include in your table, the dimension "Application Name" and the measure "Total Analysis Size - Analysis Size V1". Download the table to excel. Then go to the findings explore, filter to Findings Status = Open and Policy Rule Passed (Yes/No) = No, and in the data table include the dimension "Application Name" and the measure "Total Number of Findings - Application". Then download this table to excel as well. Now you can merge the two spreadsheets based on Application Name and divide you total number of findings (already filtering to only include those findings that impact policy and are currently open) by the analysis size for the most recent scan. This will give you flaw density for only policy affecting findings though it is only for your most recent scans.

    Expand Post
  • KP7766 (Community Member)

    Thanks, Anne, appreciate the detailed response. Will look into the Excel workaround, but the interest is primarily being able to represent this directly within the Analytics dashboards we've built out. Our policies are indeed more complex than just disallowed severities (things like the SANS Top 20/OWASP Top 10 are also in there, which occasionally introduce disallowed flaws from the lowest severities).

     

    Our development teams have raised this concern because the current metric is telling an incorrect story to leadership, who monitor this "flaw density" metric closely; if the policy mandates fixing only X flaws, the teams shouldn't be penalized for the density of flaws that fall outside that range (at least not in this core measure of how they are performing against policy - the all-inclusive flaw density is of course still helpful for additional app health insight).

     

    Can you send through an update when work begins on this enhancement?

    Expand Post

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.