Remediating container vulnerabilities
Monitoring remediation is a process that begins with reviewing status and ends with closing container vulnerable items (CVITs). Container Vulnerability Response offers tools and procedures to make that process more productive and efficient.
- Container Vulnerability Response calculator rules
Vulnerability calculators automate the calculation of initial values for the fields on container vulnerable items. The condition for each calculator is evaluated in order, and the first matching calculator is used. - Exception management in Container Vulnerability Response
When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to an container vulnerable item (CVIT) that cannot be remediated according to the policy. - Create, edit, and delete Container Vulnerability Response remediation task rules
You can create rules to automatically group container vulnerable items (CVIT) into remediation tasks (CVUL) based on filter conditions. These rules automatically group CVITs as they're imported or manually created. - Create auto-close rules for Container Vulnerability Response
Use auto-close rules to close older container vulnerable items (CVITs) automatically based on the filter conditions that you set. - Removing assignments from container vulnerable items and remediation tasks
You can clear the Assigned to and Assignment group fields on container vulnerable items directly from the container vulnerable item and remediation task records that you determine might be incorrectly assigned to you or your groups. - Close a remediation task
If you determine that the issue associated with an application remediation task can be immediately closed without further analysis, you can use the Close feature. Starting with v2.10 of Container Vulnerability Response, the Close button has been removed for an container remediation task. - IT Operations Management and pattern discovery
When discovery is enabled, information is received from the Information Technology Operations Management (ITOM) team. If the ITOM Discovery is enabled, you can see Kubernetes Namespaces, Kubernetes Clusters, and Kubernetes Services when you open a container vulnerable item (CVIT). Else, you can see Prisma payload information.