The following steps describe the workflow for creating CI/CD compliance reports.
Step | Description |
|---|---|
Step 1. Create an Asset Group. | |
Step 2. Create an Assessment Profile. | |
Step 3. View reports. |
Create an Asset Group
Create an asset group to define a logical collection of your CI/CD assets (such as specific repositories or pipelines within a provider like GitHub). This step scopes your security assessments, ensuring that subsequent compliance checks and scans performed by an assessment profile are applied to the relevant resources.
Navigate to → → .
On the Create New Assets Group screen:
Provide a group name (required) and description.
From the Filter menu in the Assets table, select → .
Note
The CI/CD module supports GitHub and GitLab provider types.
Select , or select assets from the list that is displayed, and click .
Note
For more information about about Asset Groups, refer to Asset groups.
Create an Assessment Profile
Create an assessment profile, which configures the specific security standards and initiates the scans against the assets defined in your asset group.
Navigate to → → → .
On the General step of the wizard.
Provide a profile name (required) and description (optional), and select Generate a scheduled report.
Specify the email recipients for the report.
Set the Evaluation frequency (required).
Click .
On the Standards and Asset Group step of the wizard.
Select a standard.
Note
CIS GitLab Benchmark, CIS GitHub Benchmark, and the OWASP Top 10 CI/CD Risks standards are supported.
Select your asset group from the list and click .
Review the details on the Summary step of the wizard and click .
Note
For more information about assessment profiles, refer to Use an assessment profile to run compliance checks on your assets.
View and access reports
The email recipients defined in the assessment profile will receive the compliance report.
To view the compliance scan results:
Navigate to → → .
For more information about compliance assessment reports, refer to View and manage compliance assessments and reports.