Workflow examples for managing application security
These workflow examples explain how you can start to manage applications: depending on whether you are using AppScan® Enterprise for the first time or you want to associate existing scans with new applications. Pick the example that best suits your needs, or use parts of examples as a starting point to create your own workflow.
Creating applications and scans
If you are a new user or current user of AppScan Enterprise and you decide not to migrate existing scans, you can create new applications and new scans.
Procedure
- Set up an application
profile.
- Delete the predefined attributes that are not relevant to your organization.
- Create attributes that describe your applications.
- Create
formulas to define risk.
- Validate that the predefined formulas are relevant to your organization.
- Create formulas that reflect your interpretation of business risk.
- Create an application. If you already track your applications in a .csv file, import it.
- Assign permissions to users for the application.
- Create scans for the application or import issues from a 3rd-party scanner.
- Conduct issue triage on an application's issues.
- Resolve the discovered security issues.
- Evaluate the security risk of the application.
Migrating existing scans into an application view
This migration process gives you the chance to do some maintenance and remove any scans that are not needed. If you are an AppScan Enterprise customer, your scans and folders in the Folder Explorer view might be organized by business unit, application, or even by geographical location. This type of structure makes it easier to use the Monitor view because all of the relevant scans are already logically grouped.