🎉 VSEC Test v4.0.1 is now live! Release Notes ↗
Rules

Rules

Rules define what Beacon watches for across your assets and risks. Disable a rule to silence its findings, or tune its thresholds — edits take effect immediately: every rule change invalidates the scan cache, a BOM country of origin configuration change triggers an immediate sweep, and an External signals keyword edit re-matches open signals against the new list.

Each rule is shown as a card with its name, a Built-in tag (it ships with VSEC, as opposed to a future custom rule), a description, an enable/disable switch, and any configuration fields it takes. Every rule — including built-in ones — can be switched off from here if you don’t want its findings. Number fields and comma-separated lists save when you click away or press Enter; the enable switch saves immediately. A rule’s configuration fields are disabled while the rule is switched off.

Rules With No Configuration

RuleWhat it watches for
Incomplete riskA risk missing a required evidence input (likelihood or impact)
Stale scoreNew evidence arrived after the risk’s last scoring run
Uncovered assetAn asset with no risks, adjacent to assets that do carry risks

Configurable Rules

RuleConfigurationDefault
Stalled eventDays a Clause-8 evidence item can sit in Event before flagging30 days
Untreated high riskResidual score threshold that counts as “high”4
BOM country of originComma-separated list of ISO 3166-1 alpha-2 country codes (e.g. CN, RU)none configured
External signalsComma-separated watch keywords (e.g. ransomware, zero-day, supply chain)disabled, no keywords

BOM Country of Origin

Flags a package in an asset’s SBOM or HBOM — uploaded directly, or synced from linked xZETA firmware — that originates from one of the listed countries. This is the one rule that also creates a risk automatically: see Beacon → BOM Country of Origin.

External Signals

Enabling this rule is what turns on automatic feed ingestion for the External Signals inbox — while it’s off, only manually added signals flow through matching. Asset matching always runs on asset names plus each asset’s Keywords and Business Unit property terms; the watch-keyword list doesn’t narrow that. Instead, watch keywords additionally flag signals beyond what your assets already declare — a keyword hit marks the signal as notable without mapping it to a specific asset.

The rules above are what Beacon can watch today. Broader “aim the lookout” targets — a specific supplier, part, or CVE feed — aren’t yet separate rule types; use the External signals keyword list or a manually added signal to cover those cases in the meantime.

Permissions

Access to Rules is governed by the Monitor permission block — see Permissions.

Last updated on