Cortex connects to many third-party vendors whose system interfaces frequently change. As a result, integration behavior or configuration steps may shift without notice. If you encounter unexpected issues, check with your system administrator or refer to the vendor’s documentation for the most current information. Additionally, integration sync times vary and are subject to scheduling overrides and timing variance.
Why use the integration for Apiiro
Apiiro is an application security posture management (ASPM) platform that surfaces risks across your applications and repositories. On its own, Apiiro tells you what is at risk. Connecting it to Cortex tells you who owns it and whether it meets your standards.- Connect risks to owners. Cortex maps Apiiro repositories and applications to your entities, so every risk is tied to a service and the team that owns it.
- Put security context where engineers work. Risks appear on entity pages, grouped by severity, next to the rest of a service’s operational data. Developers don’t need to switch tools to see what needs attention.
- Turn security goals into measurable standards. Use Scorecards to define rules, such as no open critical risks or every service registered in Apiiro, and track compliance across your catalog.
- Prioritize by severity. Grouping risks as critical, high, medium, and low helps teams focus on the issues that matter most first.
Configuring Apiiro
Prerequisites
- Users with the
Configure Integrationspermission can configure Apiiro. - In Apiiro, create an API key. Include the following permissions:
Risks > ReadInventory management > Applications > ReadInventory management > Repositories > Read
Configuring the integration in Cortex
- From the main sidebar, expand Integrations, then select Configurations.
- Locate Apiiro, then click Install. The Apiiro side panel opens.
- In the Apiiro side panel, do the following:
- From the Category dropdown, select the types of data to import from Apiiro (required). The category field is set to Security by default.
- Under Alias, enter the alias you’ll use in the
aliasfield of an entity’sx-cortex-apiiroblock (required). - Under API key, enter the API key you generated in Apiiro (required).
- Optionally, under Host, enter the base URL of your Apiiro instance. If left blank, the default host is used.
- Click Test connection. A successful connection means your integration is configured correctly.
- Click Save.
To modify the integration configuration, see Modifying an existing integration configuration.