Create a Risk Profile Policy

Coverity on Polaris

Version
latest

  1. Navigate to My Organization > Policy management
  2. Enter a title and description in the text areas
  3. Click Next
  4. Set the boundaries between "low," "medium," and "high" on the risk scale.

    A screenshot of the risk scale.

    These settings don't contribute to the risk profile calculation. They determine whether the final score will be considered low, medium, or high when it is presented in the application summary.

  5. Set levels for the optional parameters, if desired.
    If you do not set the optional fields, these parameters will have no impact on the final Risk Profile Score.
    The following are the available values.
    Table 1. Optional Risk Profile Parameters
    Name Available values Description
    tier
    • tier 1 = high penalty for risk profile calculation = 10 percent of base score
    • tier 2 = medium penalty for risk profile calculation = 5 percent of base score
    • tier 3 = low penalty for risk profile calculation = 2 percent of base score
    • none = no penalty assessed
    This setting is available in order to factor a custom parameter into the score calculation.
    phase
    • released = high penalty for risk profile calculation = 10 percent of base score
    • in production = medium penalty for risk profile calculation = 5 percent of base score
    • planning = low penalty for risk profile calculation = 2 percent of base score
    • none = no penalty assessed
    Corresponds to phases of the software development lifecycle.
    distribution
    • external = high penalty for risk profile calculation = 10 percent of base score
    • open source = medium penalty for risk profile calculation = 5 percent of base score
    • internal = low penalty for risk profile calculation = 2 percent of base score
    • none = no penalty assessed
    Identifies the way the application is distributed. The "open source" category applies only if the entire application is distributed as open source; if the application merely contains open source code, it should be categorized as internal or external.

    A screenshot of the optional parameters.
  6. Set the weights of severities.

    The default settings are provided when the page opens, but you can fine-tune these weights according to the needs of your organization.

    Table 2. Default weights for severities
    Severity Default weight Percent of final score
    High 3 50.00%
    Medium 2 33.33%
    Low 1 16.67%

    The weights shown are proportional. If you use the default settings shown in the table above, high severity issues have approximately three times as much impact on the final score as low severity issues. Medium severity issues matter nearly twice as much as low severity issues, because they are weighted at 2 and 1, respectively. If you set the weight of any severity level to zero, issues with that severity level don't affect the Risk Profile Score.

  7. Skip the setting for Weight of Domain. As long as Coverity is the only tool used, the default setting should be applied.
  8. Click Next
  9. Click Add Applications
  10. Select applications by clicking the checkboxes next to their names. (Use the search box at the upper right to find applications quickly.)

    A screenshot of the modal window for adding applications to a risk profile policy.
  11. Click Add Applications, at the bottom right.
  12. Click Finish.