How to send Wiz vulnerability data into Risk Cloud with a one-way integration that the LogicGate integration services team builds and deploys for you.
Integration Overview
With the Wiz integration, vulnerability data from Wiz is sent to a Wiz-specific app in your Risk Cloud environment, so your team can track and manage vulnerabilities alongside the rest of your GRC program.
This is a one-way integration. Data flows from Wiz to Risk Cloud, and nothing in Risk Cloud is written back to Wiz.
You create your credentials in Wiz and share them with the LogicGate integration services team using a secure method. The team handles the rest of the build. Once the integration is running, it checks Wiz for new and updated findings once a day.
Requirements
- You must have admin access in Wiz to open Connections and create credentials.
- You must have purchased the Risk Cloud Vulnerability Management app. If you haven't, your Customer Success Manager (CSM) will work with you to purchase the Wiz app during setup.
- You must contact the LogicGate integration services team to enable the integration (see step 2).
Set Up the Integration
1. Create your credentials in Wiz.
- In Wiz, go to Connections and set up the credentials for this integration.
- Keep the credentials available and treat them as sensitive. You will provide them to the LogicGate integration services team after your setup conversation (see step 3).
2. Ask LogicGate to enable the Wiz integration.
Email integrations@logicgate.com and let the team know you would like to enable the Wiz integration.
3. Talk through the setup with the integration team and share your credentials.
Someone from the integration services team will respond within 48 hours to discuss the setup. After that conversation, provide the credentials you created in Wiz to the integration services team. Credentials must be shared using a secure method.
4. LogicGate confirms your Vulnerability Management app.
After your credentials are shared, the integration services team checks that you have purchased the Vulnerability Management app. What happens next depends on the result:
-
You have purchased the app
- The team deploys an additional app, built specifically for Wiz data, in your Risk Cloud environment.
-
You have not purchased the app
- The team brings in your CSM, who works with you to purchase the Wiz app.
5. LogicGate builds the integration.
The integration team builds the integration on the back end. You don't need to do anything during this step.
6. Complete a walkthrough session.
Once the integration is deployed and running, the integration team will reach out to schedule a short walkthrough session with you. During the session, you will confirm together that your data is flowing as expected.
Note: Your setup is complete after the walkthrough session. Wiz data continues to flow into Risk Cloud from that point on.
How the Integration Works
The integration that LogicGate builds for you has three parts that work together:
- Trigger: Polls the Wiz API once a day to collect all new and updated vulnerability findings.
- Function: Maps the Wiz data to Risk Cloud and, in some places, transforms values so they appear the way you want them in Risk Cloud.
- Action: Upserts the data into Risk Cloud. A new finding creates a new record, and a changed finding updates the existing record. Based on the finding's status in Wiz, the action also moves the record between steps in the Vulnerability Management workflow.
Each finding from Wiz passes through all three parts and arrives in Risk Cloud as a record with the same CVE and all of the transformed data.
Where Wiz Data Appears in Risk Cloud
Wiz findings arrive in the Vulnerability Management app built for this integration.
- Workflow: In the Vulnerabilities workflow, the origin step is where users normally create vulnerability records by hand. With this integration, records are created for you, so they start at the Analyze Vulnerability step instead.
- Dashboard: The home screen shows metrics for the vulnerabilities ingested from Wiz, plus any remediations created for them. A table report lists the open vulnerabilities with many of the fields pulled directly from Wiz. You can search, sort, and filter the table, or click a record to open it.
Review and Prioritize an Imported Vulnerability
Open a vulnerability from the table report. The top of the record is a read-only view of the data imported from Wiz. Below it, you add your own prioritization details.
1. Review the imported data.
The Wiz.io Import section includes a link to your Wiz login page. Asset Overview shows the assets linked to the vulnerability. The Overview section lists the Unique ID, Name, Status, Description, and CVE Description.
2. Review scoring and exploitability.
The Scoring section includes the Overall Score, Severity, Vendor Severity, NVD Severity, and CNA Score. The Exploitability section includes the Exploitability Score, EPSS Severity, and EPSS Percentile.
3. Review the CVSS details.
The CVSSv2 and CVSSv3 sections show fields such as Attack Vector, Attack Complexity, Confidentiality Impact, Integrity Impact, and User Interaction Required. Fields without a value show a dash.
4. Check the detection details and source.
The Detection Details section shows when the vulnerability was first detected, last detected, and last updated. Click View Source Page to open the source of the vulnerability if you want to dig deeper.
5. Describe the impact and current safeguards.
In the Prioritize Vulnerability section, describe the potential impact of the vulnerability on your organization in Vulnerability Impact. Then describe the controls you already have in place in Current Safeguards. Both fields are required.
6. Set the prioritization and initial treatment details.
- In External Facing Assets, link any external facing assets the vulnerability affects.
- Select a Recasted Severity and set the Initial Prioritization Date.
- In Treatment Options, select whether to initiate treatment and enter a Treatment Recommendation.
This information carries over to the next step in the workflow.
If you have any questions about this integration, please reach out to integrations@logicgate.com.