Skip to content

Commit 8faceee

Browse files
authored
Update risk_acceptances.md - correct scope b/w Pro and OSS
Corrected risk acceptance scope at engagement level for OSS.
1 parent e0060ea commit 8faceee

1 file changed

Lines changed: 3 additions & 4 deletions

File tree

docs/content/en/working_with_findings/findings_workflows/risk_acceptances.md

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -27,15 +27,14 @@ Generally, any Risk Acceptances should follow your internal security policy and
2727

2828
### DefectDojo Pro vs Open Source: Cross-Product Risk Acceptances
2929

30-
**DefectDojo Pro** provides enhanced Risk Acceptance capabilities that allow you to manage risk decisions at scale:
30+
**DefectDojo Pro** provides enhanced Risk Acceptance capabilities that managing risk decisions at scale:
3131

3232
* **Cross-Product Risk Acceptances**: In DefectDojo Pro, you can apply a single Risk Acceptance across multiple Products. For example, if CVE-2024-1234 appears in 10 different products, you can create one Risk Acceptance that governs all instances of that CVE across your entire portfolio.
3333
* **Bulk CVE Management**: Search for all Findings with a specific CVE or vulnerability ID, then apply a Risk Acceptance to all instances simultaneously, regardless of which Product they belong to.
3434

35-
**DefectDojo Open Source** implements Risk Acceptances at the Product level:
35+
**DefectDojo Open Source** implements Risk Acceptances at the Engagement level:
3636

37-
* **Product-Scoped Risk Acceptances**: Risk Acceptances are restricted to individual Products. If CVE-2024-1234 appears in 10 different products, you need to create 10 separate Risk Acceptances—one for each Product.
38-
* **Asset-Level Control**: This approach provides granular control and ensures that risk decisions are made in the context of each specific asset or application.
37+
* **Product-Scoped Risk Acceptances**: Risk Acceptances are restricted to individual Products. If CVE-2024-1234 appears in 10 different products, you need to create 10 separate Risk Acceptances—one for each Engagement.
3938

4039
Both approaches follow the same Risk Acceptance workflow described below, but the scope differs based on your DefectDojo edition.
4140

0 commit comments

Comments
 (0)