Scheduling Web Application Vulnerability Scans

Note: This information applies when WAS 1.0 is enabled for your subscription.

Schedule a web application vulnerability scan to find out whether your web application has vulnerabilities and to view scan results showing detected vulnerabilities, sensitive content data, and information gathered data. After the scan is finished, you have the option to generate reports based on the most recent scan data in your account to assist you with the remediation process.

The instructions below describe how to schedule a web application vulnerability scan and how to edit a scheduled task.

Schedule web application vulnerability scans to run automatically in the future according to a schedule you specify. After adding a schedule, you can edit the schedule settings and deactivate it if you don't want it to run.

Before you begin, be sure that configurations are available in your account. The target web application must be available on the web applications list (go to Web Applications under Tools. See Creating Web Applications for information. A web application profile to be used must be available on the option profiles list (go to Option Profiles under Tools). See Managing Web Application Profiles for information.

User Permissions: The web application scanning (WAS) 1.0 module must be enabled for the subscription. Users other than Managers and web application owners must be granted permissions to schedule web application scans. See Users and WAS Features.

 

To schedule a web application vulnerability scan:

1.    Select nav_schedule.jpg Schedule from the left menu.

2.    Go to New > Schedule Scan > Web Application > Vulnerability. This scan option is available when the web application module is enabled for the subscription and your account has permissions to launch and schedule web application scans.

3.    Specify settings in these sections:

      Task Title. Provide a title, change the task owner, and select a scanner to apply to the scheduled task.

      Target & Settings. Identify the target web application and settings for the scheduled task. The settings include a web application title, a web application profile, and a web application record, if you want to test the validity of authentication records.

      Scheduling. Specify the start date and time, the maximum run time and how often the task should occur.

      Notifications. Enable the notifications option to receive an email each time this scheduled task is scheduled to start.

4.    Click Save.

If you have an account with a Pay Per Scan service option, a confirmation appears with the number of web application scans remaining in your account and the number of web application scans that may be used up by the task. See Pay Per Scan Accounts for more information.

 

To edit a web application vulnerability scan schedule:

1.    Select nav_schedule.jpg Schedule from the left menu.

2.    Identify the scheduled task you want to change, and click ico_edit.jpg.

3.    Make changes to settings in these sections: Task Title, Target & Settings, and Scheduling.

4.    Select Deactivate this task if you do not want the task to run according to its schedule.

5.    Click Save.