Mitigation Library
In a POAM, there is a tab called Mitigations. This is a space where the user (typically SA or ISSO) can specify the mitigations that reduce the risk of the vulnerability. In an ideal world, all SA and ISSO would be technical experts on vulnerabilities and mitigations. But this is not an ideal world and we need to find easy ways to leverage existing knowledge. The Mitigation Library enables knowledge sharing by providing users with existing examples of Mitigations for the same vulnerability on other Systems.
- Go to POAM Task Queue
- Expand a row.
- Click on Mitigations tab.
- Click Edit Mitigations button.
- Click Show Suggestions
The dialog will show example Mitigation Statements for this vulnerability in other Systems within Ryskview. User can click on one of these example Mitigation statements and edit as appropriate.
Additionally, you will see a voting icon (like/dislike). These allow users to up-vote good Mitigations and down-vote bad Mitigations. The more up-votes a Mitigation gets, the higher on the list of Suggestions and the more down-votes, the lower on the list.