Reference B: Supply Chain Security Category values
This appendix lists the Supply Chain Security Category (Rule Category) values that classify supply chain findings. Cortex Cloud derives the category from the Finding Type. A finding is either an SBOM finding (a third-party package risk) or an Environment finding (a CI/CD supply chain check).
Finding Type
Category values
SBOM
Vulnerability, Operational Risk, License, Malicious Packages
Environment
SCM Systems Misconfiguration, CI/CD Systems Misconfiguration, Attack Path
NOTE: The complete Environment category set is defined in the Cortex Cloud CI/CD detection rule catalog. Each detection rule maps to one category, and the category propagates to the Rule Category field on the findings and issues that the rule produces.
Last updated
Was this helpful?
