Phase 3 - Removing Risk

Phase 3 - Removing Risk

Remediating Component Risk

Once your risk has been prioritized, it's time to begin fixing it. The typical strategy for this is to upgrade to versions with less risk whenever possible, then waive non-applicable vulnerabilities, replace components that are vulnerable and cannot be upgraded, and finally accept any necessary risk.

Preventing Risk

Sonatype Lifecycle's automated policy enforcement tools let you keep components with the greatest risk from ever entering production. They're powerful and potentially disruptive. By this point your teams should be adept at remediating policy violations, and you are ready to begin automatically enforcing your policy standards. Policy enforcement can be done at the organization and application level. This enforcement should be introduced gradually.

Shifting Left

So where do we go from here? With enforcement enabled, it's time to begin making good component decisions and proactive choices earlier in your development process. This is called shifting left.