Integrating IBM Security AppScan Enterprise with IBM Data Risk Manager

You can configure IBM Data Risk Manager to communicate with IBM Security AppScan Enterprise to use its sensitive risk information in IBM Data Risk Manager for assessments.

About this task

The Business Context Modeler (BCM) component of IBM Data Risk Manager provides Enterprise Integration Wizard to integrate IBM Security AppScan Enterprise with IBM Data Risk Manager.

Procedure

  1. Log in to IBM Data Risk Manager Application Suite with administrator privileges.
  2. Click the application menu icon Menu icon.
  3. Go to Business Context Modeler > Enterprise Integration Wizard > Integration > Adapter Configuration.
  4. In the Adapter Configuration section, click the Add Integration Adapter icon Add integration adapter icon.
  5. Select IBM AppScan from the list.
  6. To add an IBM Security AppScan Enterprise instance, select IBM AppScan from the Adapter Configuration list.
  7. In the Integration Instances section, click the Add Instance icon Add instance icon.
  8. Set the following options.
    Option Description
    Name Specify a name for IBM Security AppScan Enterprise instance.
    URL Specify the URL to access IBM Security AppScan Enterprise, for example https://<appscan application-IP/host name:Port>.
    Microservice Instance Select the agent that is needed for integration.
    User Name Specify the IBM Security AppScan Enterprise user name with administrator role.
    Password Specify the password for the user name.
    AppScan Feature Key Specify the key to establish connection with IBM Security AppScan Enterprise.
    Classifier and Vulnerability Assessment Specify the configuration file to import data from integration server to IBM Data Risk Manager for data classification and vulnerability assessments.
  9. Click Save to save the configuration details.

What to do next

For the adapter instance that you created, you can test the connectivity. Select the instance from the Integration Instances list, and then click Test Connection to test whether the communication between IBM Security AppScan Enterprise instance and IBM Data Risk Manager server is successful.