Skip to content

Commit d75300d

Browse files
authored
add OS Findings documentation (#15235)
1 parent c39467a commit d75300d

10 files changed

Lines changed: 306 additions & 7 deletions

File tree

452 KB
Loading
600 KB
Loading
639 KB
Loading
665 KB
Loading
259 KB
Loading
325 KB
Loading
601 KB
Loading

docs/content/asset_modelling/engagements_tests/OS__engagements.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: "Understanding Engagements in DefectDojo OS"
44
audience: opensource
55
weight: 3
66
---
7-
Product Types → Products**ENGAGEMENTS** → Tests → Findings
7+
Organizations → Assets**ENGAGEMENTS** → Tests → Findings
88

99
## Overview
1010

docs/content/asset_modelling/engagements_tests/OS__findings.md

Lines changed: 299 additions & 0 deletions
Large diffs are not rendered by default.

docs/content/triage_findings/findings_workflows/intro_to_findings.md

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -32,11 +32,11 @@ The Finding Page contains various components. Each will be populated by the Impo
3232
3333
2. **Finding Overview:** This section contains five separate pages of relevant information for the Finding: Description, Mitigation, Impact, References and Notes. These fields can be populated automatically based on the incoming vulnerability data, or they can be edited by a DefectDojo user to provide additional context.
3434
35-
**\- Description** is a more detailed summary and explanation of the Finding in question.
36-
**\- Mitigation** is a suggested method for mitigating the Finding so that it is no longer present in your system.
37-
**\- Impact** describes the impact of the vulnerability on your security posture. This page might hold descriptive text, or it may include a [CVSS Vector String](https://qualysguard.qualys.com/qwebhelp/fo_portal/setup/cvss_vector_strings.htm), which is a shorthand way to communicate the vulnerability’s overall exploitability and with the consequences of an exploitation to your organization. Impact is closely related to a Finding’s Severity field.
38-
**\- References** will list any links or additional information relevant to this Finding if included.
39-
**\- Notes** is a page where you can record any other relevant information to this Finding. Notes are ‘DefectDojo\-only’ metadata, and they are not created at the time of import. Use this field to track your mitigation progress or to add more specific detail to the Finding.
35+
- **Description** is a more detailed summary and explanation of the Finding in question.
36+
- **Mitigation** is a suggested method for mitigating the Finding so that it is no longer present in your system.
37+
- **Impact** describes the impact of the vulnerability on your security posture. This page might hold descriptive text, or it may include a [CVSS Vector String](https://qualysguard.qualys.com/qwebhelp/fo_portal/setup/cvss_vector_strings.htm), which is a shorthand way to communicate the vulnerability’s overall exploitability and with the consequences of an exploitation to your organization. Impact is closely related to a Finding’s Severity field.
38+
- **References** will list any links or additional information relevant to this Finding if included.
39+
- **Notes** is a page where you can record any other relevant information to this Finding. Notes are ‘DefectDojo\-only’ metadata, and they are not created at the time of import. Use this field to track your mitigation progress or to add more specific detail to the Finding.
4040
4141
3. **Additional Details:** This section lists other details related to this Finding, if relevant:
4242

@@ -45,7 +45,7 @@ The Finding Page contains various components. Each will be populated by the Impo
4545
* Steps To Reproduce the vulnerability
4646
* Severity Justification where you can record a more detailed explanation of the severity or impact of the Finding.
4747
48-
48+
4949
4. **Metadata: This section contains filterable metadata related to the Finding:**
5050

5151

0 commit comments

Comments
 (0)