| Choose reference table |
Table that you use to define the risk score weightage.
You can select one of these options:
- Application Vulnerable Item:
Add fields that are directly dot-walkable from the
vulnerable item (VI).
- Application Vulnerable Item -
Configuration Item: Add dot-walkable
fields that are part of the base table extensions,
such as the Hardware table. These fields are not
part of the base table (cmdb_ci).
- Application Vulnerable Item -
Vulnerability: Add dot-walkable fields
that are part of the tables that extend the base
table, for example, Third-party Entry. These fields
are not part of the Vulnerability Entry base
table.
- Application Vulnerable Item Reference
Table: Add fields that are a part of
the Related tables (m2m) or tables that have a
reference to the vulnerable item. These fields are
not directly dot-walkable from the VI.
- Configuration Item Reference
Table: Add fields that are a part of
the Related tables (m2m) of cmdb_ci or tables that
have a reference to cmdb_ci. These fields are not
directly dot-walkable from the VI.
- Vulnerability Reference
Table: Add fields that are a part of the
Related tables (m2m) of sn_vul_entry or tables that
have a reference to sn_vul_entry. These fields are
not directly dot-walkable from the VI.
- Custom Conditions: Use this
option to assign weights to the rule by evaluating
the condition. For example, the Internet-facing
filter determines if a configuration item (CI) is
external or internal.
|
| Table |
Field that appears only when one of the following options
is selected from the Choose reference table:
- Application Vulnerable Item ->
Configuration Item
- Application Vulnerable Item ->
Vulnerability
- Application Vulnerable Item Reference
Table
- Configuration Item Reference
Table
- Vulnerability Reference
Table
|
| Field |
Field to be used for risk score calculation for this
rule. |
| Aggregation |
Field that appears only when a reference table is
selected from the Choose reference table. Select the minimum
or maximum value to be considered for calculations when
Field is selected from the Related tables (m2m). |
| Weight |
Weightage of this field within the risk rule. The value
must be an integer from 0 through 100. |
| Define Value Weightage |
Component to assign weights to each field value. For
numeric fields, field values can be defined as a range (for
example, 1–5). The weights must be integer between
0–100.Note: This field does not appear if the Custom
Conditions option is selected from the Choose reference
table. |
| Condition table |
Field that appears only when Custom conditions is
selected from the Choose reference table. Select a condition
from the list. |
| Field name |
Field that appears only when Custom conditions is
selected from the Choose reference table. Enter a name for
the risk criteria. |
| Condition |
Field that appears only when Custom conditions is
selected from the Choose reference table. Preview the items
in this table that match the defined conditions. |