Triage | GitLab Docs
https://docs.gitlab.com/user/application_security/triage/ • 37 KB fetched Open original page
Triage | GitLab Docs Skip to main content
Go to GitLab Docs homepage
What's new?
What's new?
Get free trial
Toggle menu
* Use GitLab
* GitLab Duo
* GitLab Orbit
* Extend
* Install
* Administer
* Subscribe
* Contribute
* Solutions
Getting started
Tutorials
Manage your organization
Organize work with projects
Plan and track work
Manage authentication and authorization
Use Git
Manage your code
Use CI/CD to build your application
Secure your application
Getting started
Tutorials
AI Governance
Application security
Compliance
Detect
Triage
Security center
Security dashboard
Vulnerability report
Risk assessment data
Severity levels
Analyze
Remediate
GitLab advisory database
CVE ID requests
Policies
Security glossary
Deploy and release your application
Manage your infrastructure
Monitor your application
Analyze GitLab usage
Release notes
Feature support
Find your GitLab version
* GitLab Docs
/
* Use GitLab
/
* Secure your application
/
* Triage
Help us learn about your current experience with the documentation. Take the survey .
Triage
Triage is the second phase of the vulnerability management lifecycle: detect, triage, analyze,
remediate.
Triage is an ongoing process of evaluating each vulnerability to decide which need attention now and
which are not as critical. High-risk vulnerabilities are separated from medium- or low-risk threats.
It may not be possible or feasible to analyze and remediate every vulnerability. As part of a risk
management framework, triage helps ensure resources are applied where they re most effective. It s
best to triage vulnerabilities often, so that the number of vulnerabilities per triage cycle is
small and manageable.
The objective of the triage phase is to either confirm or dismiss each vulnerability. A confirmed
vulnerability continues to the analysis phase but a dismissed vulnerability does not.
Use the data contained in the security dashboard, the security inventory, and the vulnerability
report to help triage vulnerabilities efficiently and effectively.
Scope
The scope of the triage phase includes all vulnerabilities that have not yet been assessed.
Filter the vulnerability report to identify vulnerabilities needing triage:
* Status : Needs triage
Risk analysis
You should conduct vulnerability triage according to a risk assessment framework.
Depending on your industry or geographical location, compliance with a framework might be
required by law. If not, you should use a respected risk assessment framework, for example:
* SANS Institute Vulnerability Management Framework
* OWASP Threat and Safeguard Matrix (TaSM)
If available, use the
Security Analyst Agent
to accelerate your vulnerability analysis. The agent efficiently triages, assesses, and remediates
security findings by providing insights, risk assessments, and remediation guidance.
Generally, the amount of time and effort spent on a vulnerability should be proportional to its
risk. For example, your triage strategy might be that only vulnerabilities of critical and high risk continue
to the analysis phase and the remainder are dismissed. You should make this decision according to your risk
threshold for vulnerabilities.
After you triage a vulnerability you should change its status to either:
* Confirmed : You have triaged this vulnerability and decided it requires analysis.
* Dismissed : You have triaged this vulnerability and decided against analysis.
When you dismiss a vulnerability you must provide a brief comment that states why it has been
dismissed. Dismissed vulnerabilities are ignored if detected in subsequent scans. Vulnerability
records are permanent but you can change a vulnerability s status at any time.
Triage strategies
Try these strategies to focus on the most important vulnerabilities first.
Prioritize vulnerabilities of significant risk
Prioritize vulnerabilities according to their risk.
* Use the Vulnerability Prioritizer CI/CD component
to help prioritize vulnerabilities. For example, vulnerabilities in the CISA Known Exploited
Vulnerabilities (KEV) catalogue should be analyzed and remediated as highest priority because
these are known to have been exploited.
* For each group, go to the Security inventory to visualize the assets you need to secure and to understand
the actions that need to be taken to improve your security posture.
* For each group, go to the Security dashboard and view the Project security status panel. This groups
projects by their highest-severity vulnerability. Use this grouping to prioritize triaging
vulnerabilities in each project.
* Prioritize vulnerability triage on your highest-priority projects - for example, applications
deployed to customers.
* For each project, view the vulnerability report. Group the vulnerabilities by severity and change
the status of all vulnerabilities of critical and high severity to Confirmed .
Dismiss vulnerabilities of low risk
Bulk triage low-risk vulnerabilities to focus on the most important ones.
* Vulnerabilities are sometimes detected but no longer detected in subsequent CI/CD pipelines. In
this instance the vulnerability s activity is labeled as No longer detected . You might choose
to dismiss these vulnerabilities if their severity is Low or Info . Use the filter
Activity: No longer detected in the vulnerability report to select them and change their
status to Dismissed . You can also automate this by using a
vulnerability management policy .
* Dismiss vulnerabilities by identifier. If a vulnerability is mitigated by controls outside the
application layer, you might choose to dismiss it. Use the Identifier filter in the
vulnerability report to select them and change their status to Dismissed .
* Scope
* Risk analysis
* Triage strategies
* Prioritize vulnerabilities of significant risk
* Dismiss vulnerabilities of low risk
* Facebook
* LinkedIn
* Twitter
* YouTube
Company
* About GitLab
* View pricing
* Try GitLab for free
Feedback
* View page source
* Edit in Web IDE
* Contribute to GitLab
* Suggest updates
Help & Community
* Get certified
* Get support
* Post on the GitLab forum
Resources
* Terms
* Privacy statement
* Use of generative AI
* Acceptable use of user licenses
*
Links found on this page
- Skip to main content [direct]
- Go to GitLab Docs homepage [direct]
- What's new? [direct]
- Get free trial [direct]
- Use GitLab [direct]
- GitLab Duo [direct]
- GitLab Orbit [direct]
- Extend [direct]
- Install [direct]
- Administer [direct]
- Subscribe [direct]
- Contribute [direct]
- Solutions [direct]
- Getting started [direct]
- Tutorials [direct]
- Manage your organization [direct]
- Organize work with projects [direct]
- Plan and track work [direct]
- Manage authentication and authorization [direct]
- Use Git [direct]
- Manage your code [direct]
- Use CI/CD to build your application [direct]
- Secure your application [direct]
- Getting started [direct]
- Tutorials [direct]
- AI Governance [direct]
- Application security [direct]
- Compliance [direct]
- Detect [direct]
- Security center [direct]
- Security dashboard [direct]
- Vulnerability report [direct]
- Risk assessment data [direct]
- Severity levels [direct]
- Analyze [direct]
- Remediate [direct]
- GitLab advisory database [direct]
- CVE ID requests [direct]
- Policies [direct]
- Security glossary [direct]
- Deploy and release your application [direct]
- Manage your infrastructure [direct]
- Monitor your application [direct]
- Analyze GitLab usage [direct]
- Release notes [direct]
- Feature support [direct]
- Find your GitLab version [direct]
- Take the survey [direct]
- SANS Institute Vulnerability Management Framework [direct]
- OWASP Threat and Safeguard Matrix (TaSM) [direct]
- Security Analyst Agent [direct]
- vulnerability management policy [direct]
- Facebook [direct]
- LinkedIn [direct]
- Twitter [direct]
- YouTube [direct]
- About GitLab [direct]
- View pricing [direct]
- Try GitLab for free [direct]
- View page source [direct]
- Edit in Web IDE [direct]
- Contribute to GitLab [direct]
- Suggest updates [direct]
- Get certified [direct]
- Get support [direct]
- Post on the GitLab forum [direct]
- Terms [direct]
- Privacy statement [direct]
- Use of generative AI [direct]
- Acceptable use of user licenses [direct]
|
|