Change the SLAs for Vulnerability Findings¶
Goal¶
Configure custom SLA processing times for vulnerability findings based on their severity.
Outcome¶
An ODG instance that tracks vulnerability findings according to your custom SLAs
Prerequisites¶
A running ODG instance
Access to the findings configuration
Steps¶
Update the vulnerability findings configuration¶
Consider an initial vulnerability configuration:
- type: finding/vulnerability
categorisations:
- id: FALSE_POSITIVE
display_name: False Positive
value: 0
rescoring: manual
- id: FINDING
display_name: Finding
value: 1
allowed_processing_time: 120
rescoring: [manual, automatic]
selector:
cve_score_range:
min: 0.0
max: 10.0
As all CVEs have a CVSSv3 score between 0.0 and 10.0, this configuration maps all findings to the FINDING category with an allowed_processing_time of 120 days. To apply custom SLAs based on severity, you can introduce additional categorisations with fine-grained CVE range selectors. Ensure the ranges do not overlap to prevent ambiguity.
The following configuration replaces the generic Finding category with severity-based groups:
- type: finding/vulnerability
categorisations:
- id: NONE
display_name: False Positive
value: 0
rescoring: manual
- id: LOW
display_name: Low
value: 1
allowed_processing_time: 120
rescoring: [manual, automatic]
selector:
cve_score_range:
min: 0.0
max: 3.9
- id: MEDIUM
display_name: Medium
value: 2
allowed_processing_time: 90
rescoring: [manual, automatic]
selector:
cve_score_range:
min: 4.0
max: 6.9
- id: HIGH
display_name: High
value: 4
allowed_processing_time: 30
rescoring: manual
selector:
cve_score_range:
min: 7.0
max: 10.0
Apply the updated configuration¶
This is a breaking change. Existing findings in ODG will not be automatically updated. They will continue to be tracked according to the previous configuration. Only newly created will use the new configuration.
To apply this change to existing findings, you must manually patch the database entries. See Run custom SQL commands in ODG.