Docs
Assets

Assets

Guide for managing and configuring assets within the ACE platform.

Assets

Assets in ACE represent the various entities within your environment, such as servers, containers, or cloud resources. Each asset can have associated vulnerabilities and compliance checks, allowing for comprehensive tracking and management of your security posture. This guide will cover how to view and manage assets within the system.

Viewing Assets

To view the list of assets, navigate to the Assets page. The asset list provides an overview of all assets within the selected environment, including their type, IP address, hostname, and associated vulnerabilities.

Details

Clicking on a specific asset from the asset list will provide detailed information about that asset. This includes the vulnerabilities and compliance checks associated with the asset, as well as its relationships to other assets.

In the Vulnerabilities tab, one can see the list of vulnerabilities identified for the asset, along with their details such as severity, affected assets, and status.

In the Compliance tab, one can see the list of compliance checks performed for the asset, along with their details such as result (pass, fail, error, skip) and associated assets.

Note: The information available for each asset may vary depending on the scan tools used and the data ingested into the system.

Lifecycle

Mitigations

Mitigations in ACE allow users to apply security measures or fixes to address identified vulnerabilities and compliance issues for specific assets. This helps in reducing the risk associated with these assets and maintaining a secure environment. Mitigations are inferred from connected MITRE taxonomy remediations, attached guidance provided by the individual scans, and AI suggestions. AI suggested mitigations will be marked in purple. To apply a Mitigation, navigate to the Vulnerability Details page and note the Mitigations tab. From there, one can review the suggested mitigations and apply them to the asset. Afterwards, click on the Mitigation list entry: this will take you to Asset Mitigation creation form. Select the appropriate Environment, Asset, and Mitigation, then click Apply. Further vulnerabilities that fall under this mitigation will be automatically marked as remediated.

For more information on Mitigations, refer to the Mitigations documentation.

Note: This feature is outdated and work in progress.