As we reach the end of September 2024, ThreadFix version 3.x on-premises has officially reached its End-of-Life. Therefore, there is no longer support or updates for this version of the product. We have fully transitioned our product and development teams to focus ThreadFix SaaS and migrating all customers over from the on-premises versions. Our Customer Success and Support teams are here to help you in migrating to ThreadFix SaaS and maximizing the value you see from this improved offering from Coalfire. This is the next phase of ThreadFix and our team is looking forward to continuing to support you on this journey.
Notifications and Email Alerts 3.0
You will learn
How to enable or disable email notifications based on application policy status changes.
Prerequisites
Audience: IT Professional or End User
Difficulty: Basic
Time needed: Approximately 15 minutes
Tools required: N/A
The power of setting policies lies in the ability to create notifications that are triggered when an application’s policy status changes. These can be system notifications, email notifications, or both.
Enable notifications
Navigate to the Application menu on the sidebar, select the Customization sub-menu and click on the Policies page. Within the Filter Policies tab, on the policy row the Notifications option must be toggled to the On position.
Two selectable notification options are available, Policy Passing and Policy Failing. These must be toggled to the On position to be enabled.
Note: a user’s ability to see policy notifications depend on the user’s global notification settings being toggled to either On or Off. This can be accomplished in the Identity Management page, within the Manage Users tab under the Notification Settings section.With notifications turned on globally and enabled in the user’s notification settings, any changes in a policy’s status will appear in the Notifications drop-down list. ThreadFix will filter them based on the user’s role.
Add Email Addresses to Global Policy
ThreadFix can notify selected users or lists of users of a change in a policy’s status by email.
This requires that emails have been configured properly for the environment.
To configure ThreadFix to email policy status changes, click the Add Emails button. This will display a modal dialog. In the top text field enter the email address of the user to be notified if this policy changes then click the Add button.
Repeat this process for as many users as necessary. If any email lists have already been created, they will appear in the lower drop-down menu. Select the name of a list and click Add.
Â
After the email addresses and/or email lists have been added, they appear below each field. Click Close when finished. See examples below.
Add Notifications and Email Addresses Per Application
This requires that emails have been configured properly for the environment.
Users can apply a finer-grained control to policies by toggling notifications and email alerts per-application in the policy settings.
Click the global Notifications toggle for the application to Off. Then, open the policy application details by clicking the toggle arrow at the left of the policy name.
Â
In this example, the global notifications have been turned off for all the applications under the policy. Only the Document Example Application has had notifications toggled to On. All users with permissions for this team (and to view policy notifications) will see notifications when the policy status changes. ThreadFix checks for status changes when vulnerability data changes. Since notifications are off for the other applications, ThreadFix will not display policy change notifications.
Users can add separate email addresses and email lists to each application as well. The process is the same as it was for the addition of global emails and lists. Click the Add Emails button next to the application. A modal dialog is again displayed. Add the email addresses and lists, clicking the Add button each time. When finished, click the Close button.
Additional Resources:
Table of Contents
Â
www.threadfix.it | www.coalfire.com
Copyright © 2024 Coalfire. All rights reserved.
This Information Security Policy is CoalFire - Public: Distribution of this material is not limited.