To evaluate the efficacy of scanning tools, we need to set up an environment. The current plan involves using scripts to pull data, docker containers for testing DefectDojo as an ASPM/database to parse the findings, and Apache Superset to compare and analyze the findings. For hosting, we can use WMCS for internal Security-Team evaluation.
Description
Description
| Status | Subtype | Assigned | Task | ||
|---|---|---|---|---|---|
| Open | None | T382500 [EPIC] Select and Tune Security Tools for Universal Security Dashboard | |||
| In Progress | None | T382534 Set up a test environment to evaluate the products |
Event Timeline
Comment Actions
The environments have been set up locally and is ready to be set up on WMCS, if needed
Comment Actions
DefectDojo and Apache Superset. I should have phrased it better to mean for deployment or hosting. Currently, it is set up as docker containers on my local environment
Comment Actions
Ok, so really just for a public deployment or, at most, internal Security-Team evaluation.
Comment Actions
Removing inactive assignee account. (Please do so as part of your team's offboarding process.)