Creating custom goals

Create custom goals from predefined templates to monitor security objectives that are specific to your organization.

You can create additional goals to monitor security and compliance objectives beyond the predefined SLA goals that are included with IBM Concert. Custom goals are created from supported goal templates. Depending on the selected template, you can configure evaluation criteria such as environments, application tiers, asset types, remediation timeframes, and automated actions.

To create a custom goal:
  1. Click Goals in the navigation pane.
  2. Click Create goal.
  3. Select the goal template that you want to use.

    The available templates depend on the goal types that are supported by your IBM Concert deployment.

  4. Enter a Goal name.
  5. Optional: Enter a Description for the goal.
  6. Configure the goal evaluation criteria.
    Depending on the selected goal template, you can configure one or more of the following settings:
    • Environment to specify where the goal is evaluated, such as Production or Test.
    • Application tier to limit evaluation to specific application tiers.
    • Asset type to evaluate container workloads, virtual machines, or both.
    • Remediation timeframe (SLA) to specify the number of days allowed to remediate identified violations.
  7. Configure the actions that IBM Concert performs when the goal no longer meets its configured criteria.

    Depending on the selected template, supported actions can include notifications or other automated remediation workflows.

  8. Enable the goal.
  9. Click Create.

After the goal is created, IBM Concert continuously evaluates the goal against the configured criteria. The goal is displayed on the Goals page together with the predefined goals.

Goal evaluation

After you create the goal, IBM Concert continuously evaluates it against the configured criteria by using the applicable security findings.

Depending on the evaluation results, the goal can have one of the following statuses:
  • Yet to be evaluated indicates that IBM Concert has not yet evaluated the goal. This status can occur immediately after the goal is created or before sufficient security findings are available for evaluation.
  • Met indicates that the goal satisfies its configured criteria.
  • At risk indicates that the configured criteria are not currently satisfied, but the configured remediation timeframe has not yet been exceeded.
  • Unmet indicates that the configured remediation timeframe has been exceeded.