Success Metrics: Program Health

Success Metrics: Program Health

About the Data

Data Refresh Frequency:  This dashboard is updated daily at around 13:45 UTC. New scan and violation data can take up to 24–36 hours to appear.

Minimum Requirements: Applications must be scanned at least once. You should be using version 204 or higher.

Overview

The Success Metrics: Program Health dashboard provides visibility into application onboarding, scanning activity, policy violations, remediation lifecycle efficiency, and risk trends across your organization.

Use filters and interactive visualizations to monitor onboarding and scan activity, track policy violations, measure remediation lifecycle efficiency, and identify areas where DevSecOps teams can improve delivery of secure and compliant releases.

The Program Health dashboard provides:

Get to Know Your Success Metrics: Program Health Dashboard

The interactive dashboard provides multiple filter options to view success metrics for your organization. You can filter dashboard results by Date Range, Organization, Sub Orgs, Application, Application Category, Policy Threat Level, Policy Type (Security, Quality, License, and Other), Stage, Component type, Remediation Status (fixed, open and waived) and Violation Type.

The selected filters are applied across all dashboard visualizations and tables.

Use the available filters to narrow dashboard results based on selected applications, policy types, threat levels, scan stages, and violation types.

Stages available for filtering include release, stage-release, build, compliance, and source. The build stage is selected by default.

Note

Downloading Dashboard and Table Data

You can download dashboard and table data using the dashboard export options.

For instructions on exporting dashboards, tables, and scheduling deliveries, see Exporting Dashboards and Table Data .

Saved Filters:

The Enterprise Reporting Sonatype Default filter set is always available and cannot be changed or removed. To adjust filters, save your selections as a new saved filter set. Any saved sets you create can be edited or deleted as needed. Scheduled deliveries that reference a saved set use the values that were saved at the time of scheduling and will not update automatically if the saved set is edited later.

Saved Filters capture a named set of the dashboard’s current filter selections so you can quickly reopen the dashboard scoped to that view. Use the following steps below to create, apply, edit, set a default, delete, and schedule saved filter sets.

Note

Filter set names are validated as you type. Filter set name must be 1–35 characters and may not include special characters such as ^, &, %, or >. The UI shows an inline error for invalid characters or length violations and prevents saving until validation passes.

Apps & Scans

The Apps & Scans section displays onboarding and scanning activity for applications within the selected filter range.

The metric cards display:

The Apps Onboarded and Scans Performed charts display onboarding and scanning activity trends over time.

The Component filter does not apply to the visualizations in the Apps & Scans section.

Are Your Applications Being Scanned at Required Stages?

By selecting a specific stage in the Stage filter, you can ensure that most of your applications are being scanned at that stage.

Violations Discovered

This section shows all discovered violations that match the criteria specified in the selected filters.

The charts display violations aggregated by:

Monthly Violation Activity

The Monthly Violation Activity chart displays monthly counts of open, waived, and fixed violations within the selected filter context.

Remediation Lifecycle Efficiency

The Remediation Lifecycle Efficiency chart displays the average number of days taken to waive, triage, or fix violations within the selected filter range.

The chart includes:

Violations Overview

This section displays policy violations aggregated at the application level.

The charts display:

The policy types displayed include Security, Quality, License, and Other.

The threat levels displayed include Low, Moderate, Severe, and Critical.

Applications can appear across multiple threat levels when violations of different severities are detected within the same application.

Risk Ratio

The Risk Ratio is calculated as the number of critical violations divided by the number of applications scanned within the selected date range.

Example: If 10 applications are scanned within the selected date range and 5 critical violations are detected, the Risk Ratio is 0.5.

Is Risk Ratio High?

A prolonged high risk ratio is not a good indicator of your security posture and may need intensive remediation efforts. However, a spike may just be an indicator that a critical violation that could have occurred due to a specific component, was fixed promptly by your team.

Drill Down for a Deeper Analysis

Click on any point on the trend lines to drill-down by a week-wise or day-wise chart.

The drill-down view offers a deeper analysis of the_risk ratio_ over the selected time period, for each threat level as shown below. You can select Table from the top to view the results in a tabular format, instead of the chart.

Troubleshooting

Problem:

Clicking on the browser Refresh button may give you the following error:

Solution:

Click the Back button on your browser, from the page where you see this error, to go back to the Landing page Enterprise Reporting. Select the dashboard you want to view to reload the visualizations.

To refresh the page, click on the refresh icon on the top right instead of the Refresh button on your browser.

Problem:

No data visible on the dashboard or any other issues with the dashboard.

Solution:

Click on Copy to Support Info to Clipboard and contact support with this information.