Phase 1 - Installation and Configuration

Phase 1 - Installation and Configuration

To be successful, you will need to design, articulate, and follow a rollout plan. This plan should document milestones, timeframes, and responsible stakeholders.

  1. Create a success plan
    Success starts with defining what you need to accomplish to be successful. Start by documenting your desired outcomes and why you purchased Lifecycle. You will want to make this clear to all stakeholders so that they share your vision.

  2. Identify key stakeholders
    Include the stakeholders in the success plan and make it public to the organization. Get the key individuals on the same page before they become roadblocks to the process. Executive sponsorship is required to drive early adoption.

  3. Set project timelines and scope
    Decide your milestone dates early and document when they need to be pushed and why. Socialize and celebrate your milestones to keep stakeholders engaged with the process.

  4. Determine metrics to track for success
    Start tracking your baseline metrics tied to your desired outcomes early. They will help you set reasonable goals to encourage real change in the organization. Share your metrics with all stakeholders so they are part of the success story.

Installation

  1. Provision your hardware architecture
  2. Install the IQ Server
  3. Initialize Lifecycle

System Configuration

  1. Configure user access
  2. Determine notification strategy
  3. Schedule maintenance plan

Application & Policy Configuration

  1. Catalog your applications
    Map out the applications you want to scan with Sonatype Lifecycle.

  2. Define appropriate Categories
    Group your applications into categories based on acceptable risk levels and user access.

  3. Adjust your policies
    Change the policies for your lifecycle Organizations for that group's acceptable level of risk.

  4. Set up proprietary components
    Sonatype won't have information on components developed by your teams. This lets you tell Lifecycle which components you've developed to remove noise from your scan results.

  5. Ensure that your license threat groups are appropriate
    Adjust your License threat groups to suit your organization's legal standards. Note: this will need to be done in conjunction with your legal team.

  6. Enhance your policies using labels
    Set up labels to help identify, track, and remediate components causing policy violations.

  7. Test scan in sandbox organization/application
    Scan an application in your Sandbox Organization to ensure the software is set up correctly.

  8. Legacy application policy waivers
    Decide on a strategy for dealing with the policy violations already present in your application.

Search results

No results found