Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Define SLAs for Vulnerability Findings

Prev Next

Who can use this feature

  • Available in the AppSec add-on for all plans

Scrut allows you to define SLAs to establish clear timeframes for addressing scan findings. In this guide, you can learn how to define the SLAs for findings based on severity.

What are SLAs?

SLAs (Service Level Agreements) in Scrut are predefined timeframes for resolving identified vulnerabilities (findings). Resolving vulnerabilities within specific timeframes ensures that you meet compliance objectives efficiently.

How To Edit SLAs

  1. Navigate to Vulnerability → Findings and click the Settings settings.png icon on the top right.

  2. This opens the Vulnerability Settings page with the SLA tab active by default.

  3. Scrut categorizes findings into four severity levels: Critical, High, Medium, and Low.

  4. Click the Edit button to enable the input fields.

  5. Enter the number of days for each severity level. This is the maximum number of days allowed for a finding to remain unaddressed, after which it will be marked accordingly.

  6. For example, if you set Critical to 7, any finding not resolved within 7 days after First Seen will be marked as Critical. If you set High to 14, any finding not resolved within 14 days after First Seen will be marked as High.

  7. Click Save.

Best Practices

Ensure that the defined SLAs are realistic and aligned with your team’s capacity to remediate the findings.