Skip to main content

Set global default protection levels

Your organization's default protection level determines how Contrast CVE Shield behaves for every CVE that has shield capability, in each environment, unless you've set a custom override for a specific CVE.

The default applies to applications across your entire organization for the environment including any applications you may add in the future that have been instrumented with Contrast.

Global default protection levels include:

  • Off: Disables CVE Shield entirely for the selected environment. No monitoring or blocking occurs.

  • Monitor: CVE Shield watches for exploitation attempts and reports them, without blocking. Monitor mode also includes reachability information for CVE Shield Free tier and Assess-licensed customers.

  • Block: CVE Shield identifies, reports, and blocks exploitation attempts. Not available on CVE Shield Free tier.

Note

Default protection levels apply only to CVEs that have CVE Shield capability. Not every CVE published against a library you use is eligible for shielding.

Before you begin

  • An agent must be installed and configured on a service.

  • Any authenticated member of your organization who can reach Policies > CVE shield can change default protection levels.

Set the default protection level

Changing a default applies across your entire organization for that environment, and can take up to 5 minutes to take effect.

  1. In Northstar, in the left navigation, go to Policies > CVE shield.

  2. Under General Settings, select Edit.

    • For each environment including Development, QA, and Production, select the dropdown and choose a protection mode.

    • If your organization is on the CVE Shield Free tier, Block won't appear as an option. Choose Off or Monitor.

See also

Contrast CVE Shield

Customize protection by CVE

View your CVE Shields in Explorer

Review Contrast CVE Shield states

CVE Shield observations

Investigate with Explorer