Continuous Monitoring Best Practices

Continuous Monitoring Best Practices

Continuous Monitoring (CM) is the capability to automatically check your applications for any new violations every night.

CM needs to be configured to a stage before monitoring will start.

Overview of the Continuous Monitoring (CM) Process

  1. Set CM to a specific stage to monitor

    • The release and operate stages are the most common

The release stage in the DevOps cycle is where the updated code should have been thoroughly tested and validated, before launch. Setting the CM at the release stage acts as gatekeeping and will inform you of the risks if there are any, to prevent delivery of a product ridden with vulnerabilities.

The operate stage is useful in scenarios involving integrations with deployment tools. Evaluations at this stage will not show up in the dashboard or reporting views.

For more information on selecting a stage to monitor, refer to Usage Suggestions for Each Stage.

  1. CM notifications are configured on each policy

    • Focus on critical violations

    • Send notifications to the appropriate role

  2. CM monitors the most recent Lifecycle evaluation

    • CM updates the latest report daily

    • CM creates a new report with every scan

  3. CM may be configured when to run.

    • Midnight on the installation server is the default
  4. Only new violations will trigger notifications

Use Continuous Monitoring to notify you of newly discovered vulnerabilities

Most Effective Not Effective
- currently deployed to production

- code that is not built frequently

- legacy applications

- third-party applications

- applications licensed under SBOM Manager
- when configured to a stage that is not scanned

- when notifications are not configured

- when applications are evaluated more than once a day

- evaluations from previous builds (not the latest scan)

- CM is not used for enforcement

Understand the impact of your Continuous Monitoring strategy

Purge Continuous Monitoring data after 30 days

Continuous Monitoring Decision Tree