Skip to content

Commit 6618b2b

Browse files
skywalke34paulOsinskiMaffooch
authored
docs: Add Pro vs OSS comparison for cross-product risk acceptances (#13703)
* docs: Add Pro vs OSS comparison for cross-product risk acceptances * Update risk_acceptances.md - correct scope b/w Pro and OSS Corrected risk acceptance scope at engagement level for OSS. * Update docs/content/en/working_with_findings/findings_workflows/risk_acceptances.md --------- Co-authored-by: Paul Osinski <42211303+paulOsinski@users.noreply.github.com> Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
1 parent f01d0c2 commit 6618b2b

File tree

1 file changed

+13
-0
lines changed

1 file changed

+13
-0
lines changed

docs/content/en/working_with_findings/findings_workflows/risk_acceptances.md

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,19 @@ Any Findings associated with a Full Risk Acceptance will be set to **Inactive**,
2525

2626
Generally, any Risk Acceptances should follow your internal security policy and be re\-examined at an appropriate time. As a result, Risk Acceptances also have expiration dates. Once a Risk Acceptance expires, any Findings will be set to Active again.
2727

28+
### DefectDojo Pro vs Open Source: Cross-Product Risk Acceptances
29+
30+
**DefectDojo Pro** provides enhanced Risk Acceptance capabilities that aid in managing risk decisions at scale:
31+
32+
* **Cross-Product Risk Acceptances**: In DefectDojo Pro, you can apply a single Risk Acceptance across multiple Products. For example, if CVE-2024-1234 appears in 10 different products, you can create one Risk Acceptance that governs all instances of that CVE across your entire portfolio.
33+
* **Bulk CVE Management**: Search for all Findings with a specific CVE or vulnerability ID, then apply a Risk Acceptance to all instances simultaneously, regardless of which Product they belong to.
34+
35+
**DefectDojo Open Source** implements Risk Acceptances at the Engagement level:
36+
37+
* **Product-Scoped Risk Acceptances**: Risk Acceptances are restricted to individual Products. If CVE-2024-1234 appears in 10 different products, you need to create 10 separate Risk Acceptances—one for each Engagement.
38+
39+
Both approaches follow the same Risk Acceptance workflow described below, but the scope differs based on your DefectDojo edition.
40+
2841
### Add a new Full Risk Acceptance
2942

3043
Risk Acceptances can be added to a Finding in two ways:

0 commit comments

Comments
 (0)