Applying advanced filters
Advanced filtering helps you visualize applications that require attention to satisfy security and regulatory compliance standards. You can apply advanced filtering by industry standard (OWASP Top 10 and the CWE/SANS Top 25) or by issue type. Apply it on one business unit or on all of the business units in the portfolio. After you apply the filtering to fine-tune the list, copy the URL into an email and send it to the team member who is responsible for fixing the issues.
Applying advanced filtering from the dashboard
- Top Issue TypesNote: Beginning with v9.0.3, you can drill through the Top Issue Types chart to see which apps contain the top issues in your portfolio.
- OWASP Top 10
- CWE/SANS Top 25
Drill through from the Top Issue Types chart
- If the issues do not apply to the Standard and Section that is selected, the portfolio view doesn't display anything in the list.
- To remove advanced filtering, click the “Advanced filtering enabled?
message link. You have three choices now:
- Click to remove ALL advanced filters.
- Select ‘None’ in the Standards list, then click Save.
- Select .
Issue types that are identified by a Compliance Standard filter can highlight training that might be needed for your developers.
Drill through from a Standard chart
Let’s assume that the OWASP Top 10 chart has 15 apps in the Injection category. Drill through to the Portfolio tab and click the “Advanced filtering enabled? message link, switch to the Issue Attributes tab and add more filtering by issue type. You can also filter by the issue status.
- The results might be a smaller list of applications, or if no issues apply to the Standard and Section that is selected, the portfolio view does not display any apps in the list.
- To remove advanced filtering, click the “Advanced filtering enabled?
message link. You have two choices now:
- Click to remove ALL advanced filters.
- Select ‘None’ in the Standards list, then click Save.
Applying advanced filtering from the Portfolio
Procedure
- Open the Advanced Filtering dialog by clicking .
- Click the tab for the type of filter you want to apply, make your selections, and click Save.
Results
- The results might be a smaller list of applications, or if no issues apply to the standard and section that is selected, the portfolio view does not display any apps in the list.
- To remove advanced filtering, click the “Advanced filtering enabled?
message link. You have two choices now:
- Click to remove ALL advanced filters.
- Select ‘None’ in the Standards list, then click Save.
Applying filtering on applications
- IssuesQuery
- properties: The IDs and the aliases to be used in the
properties parameter are available by calling these REST APIs:
- GET /standards
- GET /standards/{standardId}/sections
You can also generate detailed security reports to HTML and PDF from the Monitor view in the UI.