Policy Enforcement Best Practices

Policy Enforcement Best Practices

Policy action and enforcement parameters are rules that you set so that Lifecycle knows how to effectively deal with component policy violations occurring in your applications and repositories. Some approaches are better than others, of course. Sonatype has collected a list of the best practices for policy action and enforcement that have proven to be very effective for our most successful customers.

Enable continuous monitoring to regularly check for violations

Have a remediation plan in place to quash vulnerabilities efficiently and effectively

Analyze your metrics based on your organization's priorities and goals

Map and align your policy action/enforcement with the software development lifecycle/workflow

Strive to stop builds for specific threat levels...but only if you can deal with the disruption