Chuyển tới nội dung chính

ASPM v1.6.1

I. Thông tin nổi bật

FPT Smart Cloud bổ sung tính năng Export Open Findings trong AppSec v1.6.1 thuộc nền tảng FPT Security Platform (FSP).

Export Open Findings cho phép download toàn bộ danh sách open findings trong một workspace ra file CSV — hỗ trợ lọc theo khoảng thời gian phát hiện và mức độ nghiêm trọng, đồng thời kế thừa toàn bộ điều kiện search và filter đang áp dụng trên màn Workspace. Đội AppSec và DevSecOps có thể phân tích finding ngoài hệ thống, tổng hợp báo cáo bảo mật, ưu tiên remediation theo severity, và chia sẻ kết quả với các stakeholder mà không cần truy cập trực tiếp vào portal.


II. Tính năng released

1. Export Open Findings

a. Description

User có thể export toàn bộ open findings trong workspace ra file CSV trực tiếp từ màn Workspace (App Security → Workspace, tab All Assets). Dialog export cho phép cấu hình khoảng thời gian phát hiện và severity trước khi tải file về.

b. Feature

Nút "Export Open Findings" trên Workspace:

  • Nằm phía trên danh sách asset, bên phải label "Assets (N)", bên trái Sort dropdown
  • Luôn hiển thị kể cả khi workspace không có finding
  • Click → mở dialog Export Open Findings

Dialog "Export Open Findings":

  • Filter Issues in the last N days: dropdown chọn khoảng thời gian — 1 / 3 / 7 / 15 / 30 / 60 / 90 days; mặc định 7 days
  • Filter Severity: multi-checkbox Critical / High / Medium / Low; mặc định CriticalHigh được chọn
  • Nút Export to CSV bị disabled khi không có severity nào được chọn
  • Info note cố định: "Export results reflect the search and filters currently applied to the findings list. Export is limited to 100,000 rows — apply filters to narrow results if your findings exceed this limit."
  • Nút Cancel và icon X: đóng dialog, không thực hiện export
  • Dialog tự động đóng sau khi export thành công

File CSV export:

  • Tên file: AppSec-opened-Findings-YYYY-MM-DD.csv
  • Cấu trúc: 16 cột cố định — Severity Level, Severity Score, Scan Type, Issue, Status, Identifier, Location, Line, Platform, Current Version, Fixed Version, HTTP Method, Response, Description, Remediation, Detected At
  • Các cột conditional chỉ có giá trị với scan type tương ứng (SAST / Secret / IaC / Image / DAST); scan type khác để trống

c. Capacity

  • Áp dụng cho tất cả scan type: SAST, Secret Scanning, IaC, Container Image, DAST
  • Export scope: chỉ finding có status Open — finding Ignored / False Positive / Accepted Risk không được xuất
  • Kết quả export kế thừa toàn bộ điều kiện search và filter đang áp dụng trên màn Workspace
  • Giới hạn: 100,000 rows mỗi lần export
  • Nếu không có finding thỏa mãn điều kiện, file CSV chỉ chứa header row, không có data
  • Filter dialog reset về mặc định mỗi lần mở; không lưu lựa chọn của lần export trước