Configuring lookup rules
By configuring lookup rules, you can map security exposure data to the correct configuration items (CIs) in the CMDB. This mapping is a critical function because associating exposure findings with the right assets is essential for proper risk assessment, assignment, and remediation workflows.
Create lookup rule
Create lookup rules to automatically and accurately associate incoming exposure findings data with the correct configuration items (CIs) in the Configuration Management Database (CMDB) This is essential for enabling the rest of the vulnerability management process to function correctly.
Antes de Iniciar
Por Que e Quando Desempenhar Esta Tarefa
Procedimento
Ignore CI classes
To ignore some configuration item (CI) classes, for example Load Balancer [cmdb_ci_lb], when running lookup rules, set the ignoreCIClass [sn_sec_cmn.ignoreCIClass] system property.
Antes de Iniciar
The ignoreCIClass system property is available starting with Vulnerability Response v9.0. However, the property functionality is not available upon upgrade from any previous version.
If you have upgraded from any Security Operations application, prior to version 9.0, see KB0788209 for instructions on how to enable this functionality.
Procedimento
Reapply lookup rules
Reapply lookup rules to ensure updated or existing rules are applied to relevant items. This helps maintain accurate data mapping and consistency after rule changes or additions.
Antes de Iniciar
Role required: sn_vul.vulnerability_admin, sn_vul_cmn.usem_admin, sn_vul.app_sec_manager, sn_vul_container.admin, sn_vulc.admin
Por Que e Quando Desempenhar Esta Tarefa
- Look-up rules are updated or newly created.
- Findings were previously unassigned or incorrectly assigned.
- You must reassign ownership based on updated business logic or CI ownership changes.
Procedimento
Reapply lookup rules on selected discovered items
Reapply the lookup rules on selected discovered items from the discovered item list view select actions. If the configuration item (CI) changes after you reapply the rules, the discovered items are updated with the new CI and impacted detections. Vulnerable items are also updated.
Antes de Iniciar
Roles required: admin
Por Que e Quando Desempenhar Esta Tarefa
For more information, see CI changes for discovered items.
For more information on the concepts of CI matching and the CMDB, discovered item lookup, rule-based identification, see the CI matching in Vulnerability Response [KB0998706] article in the HI Knowledge Base.