Snyky Clues

12345678910111213141516171819202122
Across
  1. 3. Existing vulnerabilities not yet remediated
  2. 6. Action taken to remediate a vulnerability
  3. 9. Tool that scans code and dependencies for vulnerabilities
  4. 10. Security scanning for infrastructure defined through code
  5. 11. Backlog burndown target of ninety days for external exposures
  6. 14. Ticket opened for exception requests such as risk acceptance, SLA extensions, or complex fixes needing review
  7. 16. Reducing risk through controls or changes without fully fixing the vulnerability
  8. 17. Publicly exposed repositories require stricter SLAs
  9. 18. What engineers do to categorize repositories and determine applicable SLAs and priorities
  10. 19. Non-public repositories allow more context-based prioritization
  11. 20. Team that supports, reviews, and helps guide risk decisions and exceptions
  12. 21. Finding that appears to be a vulnerability but is not actually exploitable
Down
  1. 1. Formal decision to accept a risk instead of fixing it
  2. 2. Teams responsible for addressing vulnerabilities as part of the development workflow
  3. 4. Where fixes and vulnerability findings appear in development workflow
  4. 5. Individual or team accountable for evaluating and accepting a specific risk
  5. 7. High severity SLA in days for external exposures
  6. 8. Record used to document and track accepted risks over time
  7. 12. Backlog burndown target of sixty days for external exposures
  8. 13. Medium severity SLA in days for external exposures
  9. 14. Defined timeframe to address new vulnerabilities
  10. 15. Backlog burndown target of thirty days for external exposures
  11. 20. Critical severity SLA in days for external exposures
  12. 22. Security testing performed directly on application source code