What's the purpose of Auto-Close Stale Vulnerable Items ?

Scott58
Kilo Contributor

Could someone explain the purpose of the Auto-Close Stale Vulnerable Items feature?

I thought this was a big win for me on 2 different issues:

1.) CI's that are Decommissioned and thus no longer able to be validated by Qualys as remediated.  

2.) Vulnerabilities that are remediated thru removal of an offending application - at times Qualys does not mark these as Fixed since it can't verify it exists nor verify that it doesn't. 

I currently have this set to 15 days and my application teams are noticing that they are remediating vulnerabilities thru those methods above and the VITs are changing to Closed, however the corresponding Vulnerability Groups are remaining in a Resolved or Open state and not moving to Closed.

State-Reason:   Closed-Fixed will closed the VUL, but Closed-Stale does not effect the State of VUL.  

Why not?  Is there a setting I can check to Close VULs with Stale VITs?  Or am I completely off-base here.

thanks!

1 ACCEPTED SOLUTION

Check the Closed-fixed roll up to group level Business Rule on the VIT.  Base configuration only checks if the substate / reason is Fixed. 

Adding an Or clause for the Stale substate / reason should do the trick.

View solution in original post

8 REPLIES 8

Has anything changed in this regard with Paris or Quebec?

I don't know.  We only just started noticing this because we were wanting to use the auto-close stale VIs.  We don't use it yet, but were researching it.

We are on Quebec.

 

 

Scott58
Kilo Contributor

Thank you! 

I'm working with my group in Dev to make the change now so I can get the fresh view and compare to Prod.  I understand this is a fairly new feature, but can I suggest adding a reference to this in the article noted earlier by Chandra.

I would almost expect the Rule to be changed automatically, since this seems to be an improvement feature.  Leaving Groups Open with all Items Closed seems to go against a good 'workflow'.

Scott58
Kilo Contributor

Well, I know I'm just replying to my own comment but I won't know the results for a bit as my SN admins view this as a customization (which it seems to be) and are thus a little more apprehensive.  So it looks like it's story creation time.

Thanks again for help!