What vulnerabilities are for
Your auditor needs to see that you identify, prioritize, and fix security vulnerabilities within defined timelines. The Vulnerabilities module centralizes all findings from connected security tools and lets you track remediation progress with full audit history.How vulnerabilities are collected
Vulnerabilities flow into DSALTA from two sources:- Integration-sourced — Eight integrations sync findings automatically — Wiz, SentinelOne, AWS (Security Hub findings), Azure (Microsoft Defender for Cloud assessments), GCP (Security Command Center findings), Microsoft Defender for Endpoint, GitHub (Dependabot alerts) and GitLab (project vulnerability findings); the table under Integrations that feed Vulnerabilities below has the detail. Each vulnerability shows the integration name as its source.
- Manual — Log a finding yourself with Add Manual Finding, supplying the CVE or finding ID, affected asset, severity, status, source label, package or component, CVSS score, and an optional SLA due date.
Viewing your vulnerabilities
Each vulnerability displays:
Click any vulnerability to open its detail panel, which has two tabs:
- Summary — the Description, Remediation, CVSS vector, and package and scoring sections, plus the Status dropdown you use to move the finding through its workflow.
- Impacted Assets — every asset the finding applies to.
Working with vulnerabilities
When a new vulnerability appears:- Review the severity and CVSS score to understand the risk.
- Identify the affected asset(s) and their classification level.
- Update the status from the Status dropdown in the detail panel as work progresses: Open → In progress → Resolved.
- If the finding is not a real issue, set it to False positive. If you are knowingly living with it, set it to Accepted. There is no “on hold” status.
The SLA column flags a finding as due soon three days before that deadline, and as overdue once it passes. Findings in Resolved, False positive, or Accepted are excluded from SLA tracking.
Integrations that feed Vulnerabilities
Eight integrations sync findings into DSALTA. Each row names the integration you connect, and the feed DSALTA reads from it:
To connect an integration, go to Integrations in the DSALTA sidebar.
GitHub code-scanning and secret-scanning alerts are tracked by their own compliance checks: Code scanning alerts should be resolved and Secret scanning alerts should be resolved.Findings from a scanner you connect elsewhere can be recorded against the relevant control as manual evidence.
.png?fit=max&auto=format&n=tsMQJyneJ1xquFUo&q=85&s=4d401cc03b547d99b6f75a6bd170c334)