Whitespots Wiki
Login
  • Home
  • 🔦Auditor
    • 📥Deployment
      • Installation
      • Update
    • 🎯Features
      • 🚀Run Audit
        • AppSec Portal cooperation
        • Direct use of Auditor
      • ⚙️Settings
        • AppSec Portal cooperation
        • Direct use of the Auditor
          • Cleaner
          • Docker Credentials
          • Workers
          • Personalization
        • Jobs
          • Technical Jobs
          • Scanner Jobs
          • Job configuration
    • 🗒️Release notes
    • 🩼Maintenance
  • 🖥️AppSec Portal
    • 📥Deployment
      • License obtaining
      • Installation
      • Get started with the AppSec Portal
        • Сonfiguration options
      • Update
      • Accessing the AppSec Portal API Endpoints
      • Database transfer guide
      • FAQ: typical errors in deployment process
    • ⚙️Post install Configuration
    • 🎯Features
      • 🎣Auto Validator
        • Rule creation
        • Rules view
      • Deduplicator
        • ⚙️Basic deduplicator rules
        • ⚙️Advance Deduplicator rules
      • 🔦Vulnerability discovery
        • ✔️Audits
        • ⚙️Auditor settings
          • Auditor config
          • Sequences
            • Sequences creating
            • Sequences setting
        • 🔎Run audit
          • Run Audit Manually
          • Scheduled Audit Run
      • 🎯Recommendations
      • Security Metrics
        • Severity Statistics Dashboard
        • WRT (Weighted Risk Trend)
        • How to work with WRT (for team leads)
        • Metrics settings
          • SLA
        • CVSS
          • CVSS Rule
      • Custom Reports
      • 📈Active tasks
      • 🧺Asset management
        • How to import repositories from version control
        • Default product
        • Adding a product asset
        • Asset Transfer Between Products
      • 🕷️Findings view
        • All findings view
        • Grouped findings as a result of
        • Grouping of findings into groups
        • Available bulk actions
        • Viewing specific findings
        • Usable filters and easy sorting
      • 📊Jira
        • Jira integration configuration
        • Setting up Jira webhook
      • 👾Move from DefectDojo
      • 🔬Scanners
        • 🔌Importing reports from scanners to AppSec Portal
          • 🖐️Manual Import using Report File
          • Importing reports via Terminal using a Report File
          • Importing reports via Lambda Function using a Report File
        • Scanner description
          • Code Scanners
            • Bandit
            • Brakeman
            • Checkov
            • CodeQL
            • ESLint
            • Gemnasium
            • Gosec
            • Hadolint
            • KICS
            • PHPCodeSniffer
            • Retire.js
            • Semgrep
            • SpotBugs
            • Terrascan
          • Secret Scanners
            • Gitleaks
            • Trufflehog3
          • Image and code dependency Scanners
            • Trivy
            • Trivy vulners.com plugin
            • Snyk
          • Web Scanners
            • Arachni Scan
            • Acunetix
            • Burp Enterprise Scan
            • OWASP Zap
          • Infrastructure Scanners
            • AWS Security Hub Scan
              • Importing reports via AWS Lambda Function within AWS Security Hub
            • Prowler
            • Subfinder
            • Nessus
            • Nuclei
          • Mobile Security Scanners
            • MobSFScan
          • Other Scanners
            • Dependency-Track
            • Whitespots Portal
      • 📦Working with products
        • Product Creation
        • Product options
        • Finding groups
        • Risk assessment
        • Product Asset
    • 🛠️General Portal settings
      • Version Control Integration
      • Profile
      • Managing user roles and access control
        • User management
        • Creating and editing roles
      • SSO settings
        • GitLab SSO
        • Microsoft SSO
        • Okta SSO
      • Scanner settings
        • Auto Closer
        • Group findings by
        • Custom Jira description
        • Custom severity mapping
        • Auditor Job Config
      • Notification settings
        • Integration
        • Criteria & Schedule
        • Status change notification
        • Manage notification schedule
      • Repository Link Configs
      • CWE list
      • Tag screen
    • 🗒️Release notes
  • To be described
    • Documentation backlog
Powered by GitBook
On this page

Was this helpful?

Last updated 9 months ago

Was this helpful?

Severity Statistic view:

The timeline of the charts can be customized to show data for the last 3 days, last week, last month, or last year, providing flexibility in analyzing different time ranges.

Select the products for which you want to see data on the chart by selecting them from the Products to Select section. You can search, filter (by product type, included or excluded tag) and include or exclude selected products from the data display by moving the Exclude Selection slider.

Current Weighted Risk Trend

By regulary tracking the following global metrics, you can gain a better understanding of your security posture and make informed decisions to enhance your overall security strategy.

Severity statistics

Shows the number of verified findings grouped by severity.

Trend history

Shows the trend of verified fyndings.

Mean Time of Status Change

Customise the view of the metric view using the Findings Status Change Time Statistics section of the Metrics Settings.

  • Average Vulnerability Age (AVA) calculates the average age of vulnerabilities from creation to remediation. It helps to determine how long vulnerabilities pose a potential risk.

  • Mean Time to Detection (MTTD) measures the average time it takes to verify vulnerabilities from the moment they are created . A shorter MTTD indicates an effective and timely vulnerability detection process.

  • Mean Time to Rejection (MTR) measures the average time it takes for a finding to be rejected after creation. It provides insights into the speed of handling findings that are determined to be false positives.

  • Mean Time to Remediation (MTTR) calculates the average time it takes to remediate vulnerabilities from the moment they are verified. A shorter MTTR indicates an efficient vulnerability resolution process.

  • Mean Time to Product Task Assignment (MTTAp) measures the average time it takes for a validated finding to be assigned to a developer (assignee) in the Jira product space from the time it is validated. It helps to track the speed at which results are processed after validation and the initiation of the fixing process.

Mean Time to Security Task Assignment (MTTAs) measures the average time it takes for a validated finding to be assigned to a developer (assignee) in the Jira security space from the time it is validated. It helps to track the speed at which results are processed after validation and the initiation of the fixing process.

Findings count

Customise the view of the metric view using the Findings Count Statistics section of the Metrics Settings.

You can customise your dashboard based on your needs by clicking the Metrics button on the right panel:

metric empowers organizations to measure and track the state of security in a business-oriented manner. The General WRT is calculated by combining the WRT of each product, taking into account their respective severity weights, findings count, and business criticality assessments.

Note that the General Weighted Risk Trend displays the , risk appetite and severity weight values. Be sure to before viewing the graph. Otherwise, the graph may be distorted by incorrect weight values.

You can configure the trend display only by clicking on the cogwheel through this section. Trend history section will display data for the last month

By monitoring the Status change mean time graph in relation to the requirements, you can effectively manage and prioritize your remediation efforts, ensuring that critical vulnerabilities are promptly addressed and mitigated according to the established timelines.

Finding Discovery Rate (FDR) measures the rate at which new vulnerabilities are verified per day, either manually or automatically (through the Auto). It helps you evaluate the effectiveness of your Auto Validator's rules and security team.

False Positive Rate (FPR) quantifies the rate of reported vulnerabilities that are later determined to be false positives per day manually or by . A lower false positive rate indicates the accuracy of your vulnerability detection tools and methodologies.

Vulnerability Remediation Rate (VRR) tracks the rate at which vulnerabilities are resolved per day, either manually or automatically (through the ). This metric evaluates the efficiency of your vulnerability resolution process.

  1. 🖥️AppSec Portal
  2. 🎯Features
  3. Security Metrics

Severity Statistics Dashboard

PreviousSecurity MetricsNextWRT (Weighted Risk Trend)
  • Current Weighted Risk Trend
  • Severity statistics
  • Trend history
  • Mean Time of Status Change
  • Findings count
Weighted Risk Trend (WRT)
WRT
set the appropriate weights
SLA
Validator
Auto Validator
Current Weighted Risk Trend
Mean Time of Status Change
Findings count
FDR chart
FPR chart
VRR chart
Auto Closer