Managing issues
With IBM® Guardium® Exposure Manager, you can monitor and manage issues that occur when assets of a data store or endpoint devices violate policies that are associated with data stores' projects or the endpoint devices' cohorts.
An issue is a detected policy violation in which data store assets or endpoint devices fail to comply with the policies that are assigned to their projects or cohorts.
To view issues that IBM Guardium Exposure Manager has discovered, go to Issues from the main menu. On the Issues page, you can filter the issues table by selecting one of the following status cards:
- Open
- Pending scan
- Resolved
You can also click the Filter icon to apply filters on the display of issues in the table.
You can interact with an issue in the following ways:
- To open the workbench and the side panel, click the issue ID. The workbench displays a visual representation of the issue, including all the assets involved, the data flow permitted between assets, and any policy violations caused by that data flow and access.
- To open only the side panel with more details, click anywhere in the issue's row other than the ID.
Through the side panel, you can perform the following tasks:
- In the Violation details section of the side panel, you can view more details about the violations associated with the issue. You can also click the policy link to view more details about the policy or to edit the policy associated with the issue.
- In the Remediation details section of the side panel, you can view details about remediation actions associated with the issue.
- In the Asset involved section of the side panel of a Workload issue, you can click the data store and scope link to view more details about the data store and the scope associated with the issue. The Asset involved section of the side panel of a Workforce issue shows more details about the endpoint assets and you can click an asset link to view more information about an individual asset.
- In the Affected resources section of the side panel, you can click View details to view more details about the resources affected by the issue.
- In the Assignee section of the side panel, you can do any of the following tasks:
- View the name and email address of the person assigned to resolve the issue.
- Click the Add icon, enter the Name and Email address of the person to whom you want to assign the issue, and then click Save to add an assignee for the issue.
- Click the Delete icon, and then click Remove to remove the assignee for the issue.
- In the Timeline section of the side panel, you can view chronological record of all system detections, updates, and user interactions for the issue.
- Click Open Workbench on the side panel to open the workbench or the visual representation of the issue that provides insights into the violations related to data flow and data access.
Remediation actions for the issue
In IBM Guardium Exposure Manager, you can remediate the issues related to your data stores or endpoint devices by doing any of the following actions for the issues:- Mark as done
- On the side panel of an issue, if you click , enter an optional comment, and then click Mark as done the following updates are done for the issue:
- As Workload policy updates are based on scheduled runs, the following updates happen for a Workload issue shortly after policy update, but not immediately:
- The Status of the Workload issue changes to Pending scan on the side panel and in the table of the Issues page.
- The count of the Pending scan card on the Issues page increases by one.
- As Workforce policy updates are constantly monitored, the following updates happen for a Workforce immediately:
- The Status of the Workforce issue changes to Resolved on the side panel and in the table of the Issues page.
- The count of the Resolved card on the Issues page increases by one.
- After the policy associated with the issue runs according to the scheduler, the status can change to Open if violations of the policy exist.
- The Remediation details section of the side panel is updated with details of the remediation actions done for the issue.
- The Timeline section of the side panel is updated with chronological records of the actions done for the issue.
- As Workload policy updates are based on scheduled runs, the following updates happen for a Workload issue shortly after policy update, but not immediately:
- Allow data
- On the side panel of an issue, if you click , enter an optional comment, select I confirm this update to the project policy, and then click Update policy the following updates are done for the issue:
Note: The Workforce issues do not have the Allow data remediation action.
- The policy associated with the issue is updated to allow the type of data in the data stores or endpoint devices that was not allowed by the policy. As the policy is updated to allow the data, there are no policy violations and the data stores or endpoint devices do not report any issue.
Note: If the policy applies to multiple projects or cohorts, the updates to the policy can affect the data type allowed in all the projects and cohorts associated with the policy.
- The Status of the issue changes to Pending scan on the side panel and in the table of the Issues page. The count of the Pending scan card on the Issues page increases by one. After the policy associated with the issue runs according to the scheduler, the status can change to Resolved if there are no violations of the policy.
- The Remediation details section of the side panel is updated with details of the remediation actions done for the issue.
- The Timeline section of the side panel is updated with chronological records of the actions done for the issue.
- The policy associated with the issue is updated to allow the type of data in the data stores or endpoint devices that was not allowed by the policy. As the policy is updated to allow the data, there are no policy violations and the data stores or endpoint devices do not report any issue.
- Delegate
- On the side panel of an issue, if you click , select the integration type as Jira or ServiceNow, select the integration, select the integration template, and then click Delegate the following updates are done for the issue:
- A Jira or ServiceNow ticket is created for the issue and a link to the ticket is provided in the Remediation details section of the side panel. The Remediation details section of the side panel is updated with details of the remediation actions done for the issue.
- The Timeline section of the side panel is updated with chronological records of the actions done for the issue.
Note: You must integrate Jira or ServiceNow with IBM Guardium Exposure Manager to be able to delegate tickets for issues.