<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>PSIRT on DefectDojo Documentation</title><link>https://docs.defectdojo.com/psirt/</link><description>Recent content in PSIRT on DefectDojo Documentation</description><generator>Hugo</generator><language>en</language><copyright>Copyright (c) 2020-2025 DefectDojo, Inc.</copyright><lastBuildDate>Mon, 01 Jan 0001 00:00:00 +0000</lastBuildDate><atom:link href="https://docs.defectdojo.com/psirt/index.xml" rel="self" type="application/rss+xml"/><item><title>Advisory Feeds</title><link>https://docs.defectdojo.com/psirt/feeds/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/psirt/feeds/</guid><description>&lt;p&gt;PSIRT&amp;rsquo;s advisory feeds bring publisher security advisories (CISA, NVD, Red Hat,
Debian, EUVD, and more) directly into your DefectDojo Pro instance, where they
are matched against your software inventory to answer one question: &lt;strong&gt;am I
vulnerable to this new advisory?&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Import SBOM</title><link>https://docs.defectdojo.com/psirt/import-sbom/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/psirt/import-sbom/</guid><description>&lt;p&gt;PSIRT answers &amp;ldquo;am I vulnerable to this advisory?&amp;rdquo; by comparing each advisory&amp;rsquo;s
affected version ranges against your dependency inventory. That inventory comes
from SBOMs, so getting them in is the first step.&lt;/p&gt;</description></item><item><title>Components</title><link>https://docs.defectdojo.com/psirt/components/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/psirt/components/</guid><description>&lt;p&gt;Components is the software inventory as PSIRT reads it: one row for each component
in each asset that carries it. The rows come from the SBOMs you import — this page
does not create inventory, it annotates it.&lt;/p&gt;</description></item><item><title>Feed Rules</title><link>https://docs.defectdojo.com/psirt/feed-rules/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/psirt/feed-rules/</guid><description>&lt;p&gt;A busy set of feeds produces tens of thousands of advisories, and on a new
instance none of them have matched anything yet. Column filters sort what you can
already describe; they cannot say &lt;em&gt;&amp;ldquo;from now on, anything claiming active
exploitation goes to the top&amp;rdquo;&lt;/em&gt;. Feed Rules is where you say that once.&lt;/p&gt;</description></item><item><title>Matching Rules</title><link>https://docs.defectdojo.com/psirt/matching-rules/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/psirt/matching-rules/</guid><description>&lt;p&gt;Most matching needs no configuration. When an advisory publishes machine-readable
affected-version ranges, PSIRT compares them against your inventory on its own,
and the match it produces carries that comparison as evidence.&lt;/p&gt;</description></item><item><title>Feed Findings</title><link>https://docs.defectdojo.com/psirt/feed-findings/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/psirt/feed-findings/</guid><description>&lt;p&gt;&lt;strong&gt;PSIRT → Feed Findings&lt;/strong&gt; is the queue of advisories your enabled feeds have
brought in, and the place each one gets its answer.&lt;/p&gt;</description></item><item><title>Cases and SLA</title><link>https://docs.defectdojo.com/psirt/cases/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/psirt/cases/</guid><description>&lt;p&gt;A match is an observation. A &lt;strong&gt;case&lt;/strong&gt; is the work: several matches about the same
problem, grouped, prioritised and carried to a conclusion. Matching a busy feed set
produces thousands of matches; cases are what turn that into a queue somebody can
finish.&lt;/p&gt;</description></item><item><title>Advisories</title><link>https://docs.defectdojo.com/psirt/advisories/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/psirt/advisories/</guid><description>&lt;p&gt;Everything else in PSIRT is about what other people published. This page is about what
&lt;strong&gt;you&lt;/strong&gt; publish: a security advisory about your own product, written by your team,
reviewed, and sent to the customers it affects.&lt;/p&gt;</description></item><item><title>PSIRT dashboard</title><link>https://docs.defectdojo.com/psirt/dashboard/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/psirt/dashboard/</guid><description>&lt;p&gt;PSIRT ships a dashboard template. Add it from &lt;strong&gt;Dashboard → Shared Templates → PSIRT&lt;/strong&gt;,
which clones it into your own dashboard so you can rearrange or remove anything.&lt;/p&gt;</description></item><item><title>SLA Policies</title><link>https://docs.defectdojo.com/psirt/sla-policies/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.defectdojo.com/psirt/sla-policies/</guid><description>&lt;p&gt;SLA Policies is where you set how much time each severity tier gets. It is the
tuning surface for the clocks described in &lt;a href="../cases/"&gt;Cases and SLA&lt;/a&gt; — that page
explains what a clock is and how pausing works; this one is about changing the
numbers.&lt;/p&gt;</description></item></channel></rss>