The Security Dashboard home page

The security standard tiles on the Security Dashboard home page and what each one counts

Overview

The Security Dashboard home page leads with industry security standards. Each tile counts the violations of the rules belonging to one standard, for the most recent snapshot of the application:

The security standard tiles

Tile Counts violations of
Risk Model The application’s critical violations overall, as in Engineering
CWE-2024 The CWE Top 25 most dangerous software weaknesses
PCI-DSS-V3.2.1 The Payment Card Industry Data Security Standard
ISO-5055-SECURITY The security characteristic of ISO/IEC 5055
OWASP-2021 The OWASP Top 10, 2021 edition

These tiles are built from industry standards, so they depend on the corresponding index extensions being installed before the snapshot was generated.

The critical violations filter changes these counts

Turning the critical violations filter on and off changes the number on each standard tile, because it changes which violations are counted:

Technologies Overview

Violations broken down by technology, for the selected Health Measure. Clicking the tile opens Risk investigation with that technology already selected. Drill-down is disabled where the tile shows N/A.

The rest of the home page

The remaining tiles, and everything about arranging the home page - moving and resizing, bookmarking a rule, tile colours, resetting, and the top and side menu bars - work exactly as described for the Engineering Dashboard home page.

The one exception is the Architecture Model Violations tile, which the Security Dashboard does not have.