Vulnerability management
There is a general consensus that any system has vulnerabilities; some of them are known and some are not identified yet. Vulnerability management is the process of identifying and managing known vulnerabilities, which means having plans in place to remediate or mitigate the impact of the vulnerabilities. Navigate to Vulnerability Management | Dashboard to see what this feature looks like:
Figure 12.31 – Vulnerability management
Through this feature, you can walk through all the vulnerabilities detected by ACS and decide what actions to take:
- Remediate the vulnerability either by removing the vulnerable software package from the application or updating it with a more recent version in which the vulnerability is already fixed.
- Accept the risk.
- Mark it as a false positive.
Vulnerabilities are detected and grouped in terms of the following:
- Components: Software packages used by containers. This group...