04 - Vulnerability Management
04 - Vulnerability Management
and Remediation
by TWN
No part of this publication may be reproduced, copied, transmitted in any
form or by any means, electronic, mechanical, photocopying, recording or
otherwise, without the prior written permission of nnSoftware GmbH
Our mission is enable individual engineers as well as companies to take advantage of the
recent developments in Cloud and DevOps fields, to use technologies and concepts in
order to create efficient, automated, streamlined DevSecOps processes in organisations.
How it works
Serves as an aggregator and provides a unified and streamlined view for security tools
Smart features to enhance and tune the results (merge findings, remember false
positives, distill duplicates)
Product:Engagement model
DefectDojo Structure
2 Types of Engagements
Interactive Engagement:
Findings are uploaded by the engineer via UI
CI/CD Engagement:
For automated integration with a CI/CD pipeline
Severity Information
Description
Exact Code
Snippet that
contains
vulnerability
We don’t want to manually upload report files. Pipeline may run multiple times per day
It’s essential to configure integration with DefectDojo to upload the scans automatically
1 - Authentication
Fixed code
Fixed code