Some scanners ship a lot of findings, especially scanners which detect vulnerabilities as an agent on enrolled machines. (e.g. Wazuh, MS Defender or Checkov over a shared infrastructure).
These findings are then uploaded to one destination inside DefectDojo. It would be nice if the upload (import or reimport) would have an option to filter out results (e.g. Team ABC). Then, the result could be uploaded to different Engagements with different filters and the access could be managed on team level.
This would bring the benefit that these findings are not visible to a huge communitty and are also easier manageable.
A second scenario is that e.g. Harbor detects also findings which can't be remediated yet as there is no fix present. This could also be adjusted with a filter. Some teams would like to see these results to have a total overview about the security of their application, but some teams would not like to get these results as they only want to focus on issues they can remediate and see them as false positives.
Some scanners ship a lot of findings, especially scanners which detect vulnerabilities as an agent on enrolled machines. (e.g. Wazuh, MS Defender or Checkov over a shared infrastructure).
These findings are then uploaded to one destination inside DefectDojo. It would be nice if the upload (import or reimport) would have an option to filter out results (e.g. Team ABC). Then, the result could be uploaded to different Engagements with different filters and the access could be managed on team level.
This would bring the benefit that these findings are not visible to a huge communitty and are also easier manageable.
A second scenario is that e.g. Harbor detects also findings which can't be remediated yet as there is no fix present. This could also be adjusted with a filter. Some teams would like to see these results to have a total overview about the security of their application, but some teams would not like to get these results as they only want to focus on issues they can remediate and see them as false positives.