Environments
Environments in ACE represent a distinct operational context or workspace, allowing users to apply scans that only apply to this space. They are also tied to RMF Boundaries, ensuring that the security and compliance requirements specific to each environment are properly managed and enforced. Each environment can have its own set of assets, and vulnerabilities and compliance checks on those assets.
Creation
To create a new environment in ACE, follow these steps:
- Navigate to the Environments section from the main menu.
- Click on the Create Environment button.
- Fill in the required details, such as the environment name, description, and associated RMF Boundary.
- Configure any additional settings as needed.
- Click Create to create the environment.
Details
Once an environment is created, you can view and manage its details by selecting it from the Environments list. The details page includes statistics such as the number of assets, scans uploaded, users assigned, who created the environment, and more.
Users
In the Users tab of an environment, you can view the list of users assigned to the environment. If you have admin privileges, you can manage users by clicking Modify Users, which allows you to add or remove users and assign roles within the environment. Assigned users can view information within the environment and upload scans.
Scans
In the Scans tab of an environment, you can view the list of scans uploaded to the environment. This includes information on the scan name, date uploaded, time the raw scan file will still be available to download, and the number of assets/vulnerabilities the scan created, updated, or failed to create. Clicking on the ID of an entry will navigate to the Scan details page. If you wish to upload a scan to the environment, navigate to the Scans page, select the environment, and follow the instructions for uploading a new scan.
For more information on Scans, refer to the Scan Ingestion documentation.
Assets
In the Assets tab of an environment, you can view assets associated with the environment. This will tell you their Lifecycle status, type, vulnerabilities and mitigations assigned, and the scan tools from which they are derived.
For more information on Assets, refer to the Assets documentation.
Snapshots
In the Snapshots tab of an environment, you can view snapshots of the environment, which capture the number of assets, vulnerabilities of each category, and number of remediations at a specific point in time. This allows you to track the security posture of the environment over time.
Sources/Bucket Ingestion
In the Sources tab of an environment, you can view and configure automatic scan ingestion from an S3 Bucket. An admin must have already created a Bucket Ingestion Configuration (BIC) in the System Settings. Once the BIC is created, the admin can link it to the environment by selecting Assign Bucket Configuration.
After assigning the bucket configuration, the environment will automatically ingest scan results from the specified S3 bucket according to the settings defined in the BIC. Users can enable and disable ingestion for the specific environment, see reports of past ingestion passes, and trigger a manual scan of the S3 bucket for scans.
For more information on Sources/Bucket Ingestion, refer to the Automated Scan Ingestion documentation.
Note: Only Admins can create Bucket Ingestion Configurations (BICs).
