Introduction

The Platform’s Issue Suppression feature allows you to choose which issues or affected instances managed in the platform you'd like to prevent from being reported as open/published/active issues. This feature is useful in a variety of situations, some examples being:

IMPORTANT NOTE: Issue Suppression does not work retrospectively and works from the point at which you invoke suppression. Therefore, when you suppress an issue or an affected instance of an issue, the platform will not suppress historic or existing issues, only future issues that are imported.

Suppression Types: Issue-Level vs Instance-Level

There are two types of Issue Suppression you can utilise in the platform:

  1. Issue-Level Suppression - this will suppress an entire issue regardless of the affected instances/hosts for the issue. Any future scans/tests that contain a matching issue will be suppressed. By performing Issue-level suppression, the platform will update the issue's status to "Suppressed" and consider the whole issue as 'Closed'.

  2. Instance-Level Suppression will suppress only an affected instance for an issue - For example, if an issue contains multiple affected instances (e.g hosts), you can choose to suppress only certain instances affected by the issue. Any future scans/tests that contain both a matching issue & instance combination will be suppressed. The platform will consider the issue as 'Open', but the affected instance/host will have their status updated to "Suppressed"

Issue Level Suppression

Suppression Time: Indefinite vs Date-Based

Both Issue-Level and Instance-Level suppression allow suppression to occur indefinitely or until a specified date in the future.

Suppressing an Issue

Issue-Level suppression is performed from within a scan/phase only.

  1. Navigate to the relevant Project, then the relevant scan/phase within that Project

  2. Under the "Issues Overview" tab within a scan/phase, identify the issue you'd like to suppress, click the three-dots to the right of the issue and select "Suppress Issue"

  1. In the window, you have options to specify the scope of the suppression:

  2. Optionally, after selecting the scope, the “Suppress until” field will appear where you can choose to set a date in the future for Date-Based Suppression, or leave the date field blank for Indefinite Suppression

  3. Reason - a reason for suppression is mandatory and must be entered here before committing the action to the platform

  4. Click ‘Submit’ to save the suppression instruction

Suppressing an Instance

Instance-Level suppression is performed from within an Issue only.

  1. Navigate to the relevant Project, then the relevant scan/phase within that Project

  2. Under the "Issues Overview" tab within a scan/phase, identify and click into an issue that contains an affected instance you;d like to suppress, click the three-dots to the right of the affected instance and select "Suppress Issue Host"

  1. In the window, you have options to specify the scope of the suppression:

  2. Optionally, you can choose to set a date in the future for Date-Based Suppression, or leave the date field blank for Indefinite Suppression

  3. Reason - a reason for suppression is mandatory and must be entered here before committing the action to the platform

  4. Click ‘Submit’ to save the suppression instruction

Issue Rules: Suppressed Issues

For each suppression instruction committed to the platform, an entry under the “Issue Rules” will appear that describes the suppression instruction

You can access Issue Rules as follows:

  1. Navigate to “Results” → “Issue Rules”

  2. Select the “Suppressed Issues” tab:

  3. You can use the Cogs in the column headers to toggle between different data for the displayed Issue Rules