Determining risk
Now that management and security analysts have a comprehensive view of the applications across the enterprise, it's time to get a complete picture of the application security risk. Use formulas to create rules for automated application asset classification. The automated calculation of an application security risk rating is based on the application's description and discovered vulnerabilities.
The first thing to do is create an application security risk rating. Next, set priorities based on application, vulnerability type, and by business unit. Security analysts can customize the formula for calculating application security risk rating to fit whatever is meaningful to your specific organization.