Forum Discussion

Mo9823's avatar
Mo9823
Icon for Nimbostratus rankNimbostratus
Oct 07, 2019

One ASM Security Policy for Multiple web applications

Hello,

 

I got a call for a customer to verify the ASM Polices for the published applications, I found that he has 7 applications shares one policy.

this policy is in blocking mode and applications are working fine.

 

I have two options for this case:

 

1- make a new policy for each application.

2- ask him to do vulnerability assesmen/pen test and close the vulnerabilites on the same policy.

 

what is the best practice in this case, I need your advice.

 

Thanks

2 Replies

  • Option 2 first. If the vulnerabilities cannot be resolved using the existing policy then explore option 1. Even then, clone the existing policy and adjust as needed only for applications that require it. Each new policy adds the same overhead as the original in terms of ongoing management. Given the client and their needs its really a judgement call on your behalf but that is where I would start.