Audit Trail records now capture every SAST triage change with before-and-after values, actor, timestamp, bulk-action indicator, and triage method—giving release owners defensible evidence for risk acceptance and remediation decisions.
Audit evidence moves closer to the engineering workflow
CxONE 3.62 closes an important governance gap in manual and bulk SAST triage. Severity, state, and note changes are available through the Audit Trail API, including whether similarity-based or attack-vector-based triage was used.
For regulated teams, this supports a clearer chain of custody for findings that are downgraded, marked not exploitable, or otherwise dispositioned. It also makes post-incident review less dependent on screenshots, exported spreadsheets, or individual recollection.
Audit coverage now also includes Analytics and Reporting activity. Actions initiated by users, APIs, integrations, and automation are logged through the centralized audit framework with a standardized schema.
Operationally, security leaders should consider:
- Mapping audit events to internal control statements.
- Defining review requirements for bulk triage actions.
- Retaining API-derived evidence alongside release approvals.
- Testing whether SIEM and GRC integrations capture the new events.
One risk view across security engines
Risk Orchestration consolidates scan results from Checkmarx security engines into a single, severity-organized table. Teams can investigate findings, review affected files and lines, and act without repeatedly switching scanner views.
The value differs by role:
