Notification

Daily Report Email

Sends a report by email for the entire group.

Timing Target
Every morning Everyone in the group

Report Content

Tasks that have exceeded the deadline

Reports if there are tasks that have exceeded the deadline set for the task.

Vulnerabilities set by special alert tags

Reports if vulnerabilities specified by the special alert tag have been detected within 24 hours.
Up to 10 reports per same special alert tag.

Vulnerabilities newly registered within 24 hours

Reports the number of vulnerabilities aggregated based on the following axes for “vulnerabilities of newly registered tasks within 24 hours from the time of email transmission”.

  • The number of vulnerabilities that belong to important unaddressed vulnerabilities.
  • The number of vulnerabilities that belong to other unaddressed vulnerabilities.
  • The number of vulnerabilities for each server.

Please note that the count targets “newly registered tasks” and not “vulnerabilities detected for the first time.”

For example, the following case will be counted.

CVE-2021-0001 has been detected on a server in the past.
A scanner was newly installed and scanned in other servers in the same group. CVE-2021-0001 was detected (registered as a new task).
CVE-2021-0001 will be counted on the Daily Report the next day.

Severity of vulnerabilities detected for each server

The aggregation rules for “severity of vulnerabilities detected for each server” in DailyReport email are as follows.

  • Select the highest score (max) among the scores of CVSS v2 / CVSS v3 for NVD / JVN / Red Hat / Microsoft.
  • Aggregate according to the following rules based on the max value.
Condition Severity
9.0 <= max CRITICAL
7.0 <= max < 9.0 HIGH
4 <= max < 7.0 MEDIUM
0.1 < max < 4 LOW
0 == max NONE

Others

In addition, Daily Report will not be sent to groups that have no tasks registered within 24 hours and no tasks that have exceeded the deadline. Also, for tasks whose task status is not new at the timing of the Report notification, they are not counted as newly registered tasks.

Slack Notification

By registering the Slack App, you can receive notifications from Slack at the following timings. Please refer to Slack APP for more details.

  • Daily Report
  • Topic creation notification
  • Alert tag creation notification
  • Error notification

Daily Report Slack Notification

Daily Report can also be notified to Slack via Webhook. Please refer to External integration slack notification setting for setting method.

Email notifications

Timing Target
Task update Users who are set as the main or sub responsible parties for the task
Topic posting For organization topics: all members of the organization; for group topics: all members of the group
Special alert tag All members of the group where the specified CVE-ID has been detected
User invitation Invited user
User withdrawal Withdrawing user
Withdrawal from organization Withdrawing user
Credit card registration Registered user
Scanner authentication error All members of the group
Scan error All members of the group
CloudOne error All members of the group

Default responsible party

By setting “Server > Default responsible party,” email notifications will be sent when a task is newly registered on that server.