# Security Risk Trends

## About the Data

**Data Refresh Frequency:** Updated daily at around 20:15 UTC. New violation data can take up to 24 hours to appear.

**Displays Data for:** All open violations (regardless of the date they were opened) and resolved violations on or after January 1, 2024. For new installations, data will be visible within a week after the first scan.

To view historical data (generated before January 1, 2024) version 188 or higher is required.

**Minimum Requirements:** Applications must be scanned at least once, after upgrade to version 184. The dashboard currently shows data related to violations and remediations that are discovered _after_ upgrade to version 184.

## Overview

The Security Risk Trends dashboard is a valuable tool to monitor the health and security posture of your applications that rely on the open source software components. The trends displayed on this dashboard are based on the data collected during the policy violation detection and remediation activities performed by _Sonatype Lifecycle_ for your on-boarded applications at multiple stages of development. By examining your organization’s risk remediation activities over time, you can establish benchmarks for Fix Rate and MTTR (mean time to remediate) for your teams to maintain a healthy security posture.

The dashboard provides visibility into the number of violations and the time it takes to remediate (MTTR) them in your applications. The threat levels of the policy violations in conjunction with the number of violations gives comprehensive insight into the overall security risk.

Based on this data (e.g. if MTTR is within acceptable limits,) you can set the [policy actions](https://help.sonatype.com/en/policy-actions.html "Policy Actions") for the related _Lifecycle_ policies to **Warn** versus **Fail**, to prevent blocking production releases. You can assess the pending violations and the associated threat levels to prioritize your remediation strategy.

A deeper analysis into the MTTR can reveal the effectiveness of your remediation strategy. It can be used to gain an understanding of your response processes in addressing the highest risk against the most common vulnerabilities found in the open-source components used in your applications.

The Security Risk Trends dashboard displays the following metrics:

- [Daily Open Violation Counts](https://help.sonatype.com/en/security-risk-trends.html#daily-open-violation-counts "Daily Open Violation Counts")
- [Daily Active Waivers](https://help.sonatype.com/en/security-risk-trends.html#UUID-9e223e5f-14d5-bfec-30c4-f42d4a8eb616_N1750191753986)
- [Violations Over Time](https://help.sonatype.com/en/security-risk-trends.html#violations-over-time "Violations Over Time")
- [Monthly Violation Activity](https://help.sonatype.com/en/security-risk-trends.html#monthly-violation-activity-337394 "Monthly Violation Activity")
- [Mean Time to Triage](https://help.sonatype.com/en/security-risk-trends.html#UUID-9e223e5f-14d5-bfec-30c4-f42d4a8eb616_N1750196688277)
- [Triage Rate](https://help.sonatype.com/en/security-risk-trends.html#UUID-9e223e5f-14d5-bfec-30c4-f42d4a8eb616_N1750196700942)
- [Total Violations Waived](https://help.sonatype.com/en/security-risk-trends.html#UUID-9e223e5f-14d5-bfec-30c4-f42d4a8eb616_N1750199290319)
- [Active Waivers by Waiver Reason](https://help.sonatype.com/en/security-risk-trends.html#active-waivers-by-waiver-reason "Active Waivers by Waiver Reason")

## Get to Know Your Security Risk Trends Dashboard

The interactive dashboard provides multiple filter options to view the security risks in your applications. You can filter on date range, organization, sub orgs, application, application category, policy threat level, stage, violation type, security policy name, component type, remediation status and waiver reason.

Violation Types available for filtering are _Legacy Violations_ and _Non-Legacy Violations_.

Remediation Statuses available for filtering are _fixed_, _open_ and _waived_.

Waiver reasons available are acknowledged violation, mitigated externally, no upgrade path, not reachable, not exploitable, researching and other. Refer to [Waiver Reasons](https://help.sonatype.com/en/waivers.html#idp287622) for more information.

Stages available for filtering are release, stage-release, build, compliance and source. The build stage is selected by default.

### Downloading Dashboard and Table Data

You can download dashboard and table data using the dashboard export options.

For instructions on exporting dashboards, tables, and scheduling deliveries, see [Exporting Dashboards and Table Data](https://help.sonatype.com/en/data-insights.html#exporting-dashboards-and-table-data).

**Saved Filters:**

The Enterprise Reporting Sonatype Default filter set is always available and cannot be changed or removed. To adjust filters, save your selections as a new _saved filter_ set. Any saved sets you create can be edited or deleted as needed. Scheduled deliveries that reference a saved set use the values that were saved at the time of scheduling and will not update automatically if the saved set is edited later.

_Saved Filters_ capture a named set of the dashboard’s current filter selections so you can quickly reopen the dashboard scoped to that view. Use the following steps below to create, apply, edit, set a default, delete, and schedule _saved filter_ sets.

- Apply the filters you want for the view (date range, Organization, Sub Orgs, Application, Threat Level, Component Name, etc.).
- Open _Saved Filters_ and choose Save As to create a named saved set; the UI validates the name as you type.

- To update a set, apply it and choose Save to overwrite, or Save As to create a variation. An asterisk in the filter name indicates unsaved changes.
- Make any saved set your personal default with Make My Default. Sonatype Default is always available and protected; deleting a personal default reverts to Sonatype Default.

- To delete a saved set, select it and confirm. Deletion removes the set from your account only and, if it was your default, resets the default to Sonatype Default.

- A saved set stores only filters that exist on the dashboard where it was created. Applying it to another dashboard uses only matching filters; unsupported filters are ignored. Use Save As to preserve every selection across dashboards.
- Scheduled exports or deliveries that reference a saved set use the values saved at schedule time; editing the saved set later does not change existing scheduled deliveries.

**Note**

Filter set names are validated as you type. Filter set name must be 1–35 characters and may not include special characters such as ^, &, %, or >. The UI shows an inline error for invalid characters or length violations and prevents saving until validation passes.

### Daily Open Violation Counts

The _Daily Open Violation Counts_ chart displays the number of non-waived violations present each day across all applications matching the selected filters.  Open violations are broken out by threat level.

This chart does not include violations that are discovered and remediated on the same day. For example: A violation that was detected (open) on 30/11/2023 and fixed/remediated on the same day (30/11/2023), will not appear in the chart.

**More Examples:**

1. A violation that was detected (open) on 30/11/2024 and still has not been fixed/waived, will count as 1 during 30/11/2024 until now.
2. A violation that was detected (open) on 30/11/2023 and waived/remediated on 30/11/2024, will count as 1 between these dates.
3. A violation that was detected (open) on 30/11/2023, waived on 30/12/2023 and fixed on 30/01/2024, will count as 1 between 30/11/2023 and 30/12/2023.

**How Quick Remediation Affects Daily Open Violation Counts**

The _Daily Open Violations Count_ chart shows the number of violations with status **open** at the end of 24 hour time period. If a violation is detected and has been remediated within the 24 hr time period, it will not be included in the _Daily Open Violation Counts_.

### Daily Active Waivers

The _Daily Active Waivers_ chart displays the count of waivers (manual and automatic) that are currently being applied to policy violations on that day. Since waivers can be scoped at different levels (root organization, organization, or application) and can have a _Waiver Reason_ associated with them, adjust the filters at the top of the dashboard to retrieve the count of active waivers that applies to your specific area of interest.

**More Waivers Means More Risk**

The count of waivers on a given day indicates the number of policy violations that are being suppressed that day. Although waivers unblock development workflows, they also increase the exposure to vulnerabilities, waiting to be exploited.

### Violations Over Time

The _Violations Over Time_ chart displays the number of violations (open, waived or both) as they exist on the last day of each month.

**How Does Waiving and Fixing Violations affect the Monthly Count**

The _Violations Over Time_ chart shows the number of violations for each status i.e **open, waived, open + waived** at the end of each month. The examples below describe different scenarios:

- If a violation was waived on Jan 20, 2024, and the corresponding waiver expired on Feb 20, 2024, and it was not fixed then it will be counted as 1 waived violation in January (it was waived as of Jan 31) and 1 open violation in February (it was open as of Feb 29.)
- If a violation was waived on Jan 20, 2024, and was fixed on Feb 20, 2024, it will be counted as 1 waived violation in January (it was waived as of Jan 31.) and will not contribute to the counts for February.
- If a violation was waived on Jan 20, 2024, and is still active (not fixed and waiver not expired), it will be counted as 1 waived violation for each month.

### Monthly Violation Activity

The _Monthly Violation Activity_ chart displays a comparison of violation statuses (open, waived, fixed) of violation detected at the end of each month (or as of the last calendar day when this report is generated, for the current month.)

It displays the number of violations categorized into:

- Opened: The total number of open violations existing in the given month.
- Waived: The total number of waived violations existing in the given month.
- Fixed: The number of violations that were remediated in that month.

The _Monthly Violation Activity_ chart provides insights into your teams' efforts in staying ahead of remediating violations and maintaining a good security posture.

### Mean Time to Triage

The _Mean Time to Triage_ chart represents the average time taken to waive or fix the violation. The time taken to triage measured as the period between the time when the policy violation was first detected and the time when the policy violation was either fixed or waived.

If the policy violation was first waived and then fixed, then the Mean Time to Triage is considered as the difference in time when the policy violation was first detected and the time when the policy violation was waived. The fix time is not considered in such cases.

### Triage Rate

The _Triage Rate_ chart represents the ratio of the number of policy violations that are waived/fixed to the total number of policy violations detected in a month.

### Total Violations Waived

The_Total Violations Waived_ chart shows the count of policy violations that were waived in a month.

### Active Waivers by Waiver Reason

The _Active Waivers by Waiver Reason_ chart shows a percentage wise breakdown each waiver reason for active waivers in a month. It can be used to gain insights into the rationale for applying waivers to policy violations and help uncover problem areas that are preventing a fix.

_Not Selected_ waiver reason may include waivers that were applied using Lifecycle instances prior to when Waiver Reasons feature was released (release 183).

## Troubleshooting

**Problem**

Clicking on the browser _Refresh_ button may give you the following error:

**Solution**

Click the _Back_ button on your browser, from the page where you see this error, to go back to the Landing page _Enterprise Reporting_. Select the dashboard you want to view, to reload the visualizations.

To refresh the page, click on the refresh icon on the top right, instead of the _Refresh_ button on your browser.

**Problem**

No data visible on the dashboard or any other issues with the dashboard.

**Solution**

Click on _Copy to Support Info to Clipboard_ button and contact support [support](https://support.sonatype.com/hc/en-us) with this information.
