Getting Started with Software Risk Manager

Software Risk Manager (SRM) is a complete application security posture management (ASPM) solution. SRM enables you to set up policy-driven workflows to orchestrate AST tools like Coverity and Black Duck, prioritize issues, and monitor compliance across your software assets.

Software Risk Manager allows you to do the following with your AppSec data:
  • Correlate results
  • Prioritize vulnerabilities
  • Track remediation
  • Centralize risk visibility

SRM also provides issue tracking functionality as well as policy management solutions.

About This Guide

This guide provides descriptions of SRM functionality and instructions to maximize SRM deployment. Additional information can be found in the following guides:

Conventions Used in this Guide

The following conventions are used in this guide:
  • Page names. The Software Risk Manager UI consists of a series of pages. The name of the page appears in the top-left corner of the screen. In this guide, the page name begins with a capital letter. For example, the Settings page.
  • Button names. Tasks are performed by clicking buttons. The button name begins with a capital letter. For example, Click Save.
  • Icons. Icons appear throughout the Software Risk Manager UI. Icons can provide a visual indication of a state or status, such as a policy violation. Icons can also serve as links to other pages. In this guide, the icons are indicated by the name of the icon, beginning with a capital letter. For example, Click the Settings icon.
  • Menu items. Several pages in Software Risk Manager include sub-pages, which are listed as menu items along the top or left of the screen. A menu item begins with a capital letter. For example, Select License from the top menu.
  • Dropdown configuration options. When working with certain elements, such as a project or finding, a configuration icon appears to the right of the page. The icon appears as three horizontal dots. Clicking this icon displays a dropdown list of options. Options appear in this guide by name, starting with a capital letter. For example, Click the project's dropdown configuration icon and select New Analysis.
  • Code strings and filenames. Code strings and filenames are shown in a mono-spaced font. For example, Enter the following command: run srm.install
    Note: A command that is designated as "code" needs to be entered exactly as shown.