TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

Wiz

Estimated reading: 3 minutes 1208 views

Set up Wiz for automated tests with TrustCloud!

Purpose

Once you set up your compliance program, TrustCloud TrustOps works to ensure that your systems remain compliant with your adopted controls. To do so, TrustCloud runs automated tests against systems in your product and business stack and verifies that they are properly configured.

This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your Wiz account so that TrustOps can validate and generate evidence for your compliance program.

Instructions to grant TrustCloud limited access to Wiz

  1. Login to your Wiz account as a user who has Project Admin role.
  2. Create a Service Account
    1. Click the Settings icon that is available at the top-right of the landing page.
    2. Within the Settings page, click Service Accounts which is available in the left menu.
    3. Click the Add Service Account button within the Service Accounts page.
    4. Provide a Service Account Name & select Custom Integration (GraphQL API) as the Type
    5. Provide read-only access by selecting the permissions –
      1. read:projects
      2. read:issues
      3. read:vulnerabilities
      4. read:resources
      5. read:users
      6. read:cloud_configuration
    6. Create a service account by clicking Add Service Account button & copy the Client ID & Client Secret for future reference.
    7. Provide the created Client ID & Client Secret into TrustCloud.
  3. Determine the region for your tenant
    To get your tenant’s region, Click the User Profile icon available at the top right of the screen and click the User Settings option. Then click the Tenant option from the left options menu. The API Endpoint URL will be displayed in the form of https://api.{region}.app.wiz.io/graphql. Provide the region that you see as a part of the API endpoint URL.

You can also refer to the Wiz Guide to create a service account.

Data feeds

Types of control testing that TrustCloud enables with Wiz:

  1. Vulnerability Scanning

To automate the continuous monitoring of these controls, TrustCloud pulls the following types of data feeds from Wiz

  1. Projects
  2. Issues
  3. Vulnerabilities
  4. Resources

The following section describes the sample endpoints that TrustCloud uses, and the corresponding data that is pulled into the Hybrid Data Fabric.

The API will provide read-only access to the following:

Read:projects
   - name
   - archived
   - businessUnit
   - description

Read:issues
   - sourceRule name
   - sourceRule controlDescription
   - createdAt
   - Type
   - resolvedAt
   - Projects name
   - Status
   - Severity
   - serviceTickets name

Read:vulnerabilities
   - Name
   - CVEDescription
   - CVSSSeverity
   - Score
   - Status
   - firstDetectedAt
   - detailedName
   - Link
   - Projects name
   - vulnerableAsset type
   - vulnerableAsset name

Read:cloud_configuration
   - Rule name
   - Resource name
   - Resource type
   - Resource subscription name
   - Severity
   - Status
   - firstSeenAt
   - Projects name

Read:Network Exposures
   - exposedEntity name
   - exposedEntity type
   - exposedEntity properties kind
   - Type
   - accessibleFrom type
   - Applications Endpoints name
   - firstseenAt
   - sourceIPRange
   - destinationIPRange
   - portRange

Join the conversation

You might also be interested in

Excluding a Test or Assessment (Updated UI)

Excluding a test or assessment allows you to remove certain tests or assessments from...

Hybrid Data Fabric

Rather than chasing fragmented spreadsheets or outdated lists, hybrid data fabric gives you a...

Duo

This document outlines the steps you can take to grant TrustCloud access to only...

Control Attributes

Every control has many attributes that help us understand it better for mapping and...

Editing Controls

Control customization is a pillar of TrustCloud’s platform, effortless crafting of custom controls. With...

Adding Controls

TrustOps gives you the ability to add a custom control to your program, add...

Testing Controls

Once you have set up your integrations, you can leverage automated tests. Automated tests...

Self Attestations

The Self Assessments page in TrustOps provides users with a streamlined, centralized workspace to...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue