Application Vulnerability Response user groups and roles
Before you can successfully remediate vulnerabilities with Application Vulnerability Response (AVR), you must assign users to user groups.
Roles define what you and your groups can see and do in Application Vulnerability Response, Performance Analytics for Vulnerability Response, and third-party integrations with Application Vulnerability Response.
User groups
- App-Sec Manager: Contains security managers. Starting from Application Vulnerability Response v15.0, it will also contain application owners who manage the penetration test assessment requests.
- Security Champion: Contains liaisons between the development group and security managers.
- Developer: Contains individual contributors.
- V15.0: Ethical Hacker: Contains members of the ethical hacking team who perform penetration testing of applications.
The system admin [admin] role is required to assign users to the Application Vulnerability Response default user groups, using the User Administration module,
Assigning AVR users to the Application Vulnerability Response user groups for Application Vulnerability Response is not available in the Vulnerability Response Setup Assistant feature. Only Vulnerability Response roles are assigned there.
The following table lists the available Application Vulnerability Response user groups and the roles associated with them. Use this table to determine which users should be assigned which groups.
| User Group | Roles in this group |
|---|---|
Security Champion Members of this group can:
|
|
App-Sec Manager Members of this group can:
|
|
Developer Members of this group can:
|
|
| V15.0: Ethical Hacker Members of this group can:
|
|
Assign users to user groups in Application Vulnerability Response
Assign users to groups using the User Administration module in your instance.
시작하기 전에
Role required: admin