# Portfolios

## Overview

Portfolios help you to create dedicated programs to track and manage your security testing activities. Want to know how your internal systems compare to your external systems? Or wanting to track security posture for your applications? Portfolios makes this easy!

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FqyQv1FHHVg9gaK5KOLRa%2FScreenshot%202024-06-21%20at%201.24.43%E2%80%AFPM.png?alt=media&#x26;token=aaacce79-66e2-41e1-8f23-d6c7d9fcc23f" alt=""><figcaption></figcaption></figure>

Every `Portfolio` comes with `Streams`.&#x20;

Streams help you to consolidate all of your related testing activities for a portfolio, for example:

![](https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FOvOcICAQrRr4yG7wZCk4%2FPortfolio%2BDiagram%2B01.png?alt=media\&token=0d417e48-0475-4f62-8bf7-c018ad896467)

#### **Portfolio:&#x20;*****Externally Facing Applications***

**Stream 1:&#x20;*****US External Apps***

* Project 1: USA Commerce Portal
* Project 2: USA Mobile App
* Project 3: Main Integration Gateway

**Stream 2:&#x20;*****European External Apps***

* Project 1: Main Integration Gateway
* Project 2: EU Mobile App

![](https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2F2VHYasP89snjhOYksyCO%2FPortfolio%2BDiagram%2B02.png?alt=media\&token=bc941341-855a-4661-93ec-210248d8ea13)

Portfolios and Streams can help you track Business-as-Usual (BAU) pentesting and help you to better understand where to focus your time and resources more effectively.

Projects can be assigned to many streams and portfolios. This can help to ensure you are tracking the right vulnerabilities, across your enterprise.

Using the example above, vulnerabilities in project `Main Integration Gateway` might be relevant to both `USA External Apps` & `European External Apps` - therefore could be assigned to both streams.

Every Portfolio and Stream has a unique dashboard which includes details on vulnerabilities, projects & assets - helping you make more informed business decisions when it comes to tracking and remediation.

Portfolios are created and managed by administrators.

View access can be given to individual portfolios, or their respective streams, to non-admin users. Those users will only see data relevant to projects they have access to on the portfolio and/or stream.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2F2hWHmlwxrI8BVtnDZjMs%2FScreenshot%202024-06-21%20at%201.28.59%E2%80%AFPM.png?alt=media&#x26;token=de2a2eca-7e5e-4ad0-90f3-fb04e637fd4c" alt=""><figcaption></figcaption></figure>

## Creating a Portfolio

Start by clicking on Portfolios module in your main menu. You must be an Administrator. Click on `New`.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FQI27IUGhpMBczxfMDbpl%2FScreenshot%202024-06-21%20at%201.29.31%E2%80%AFPM.png?alt=media&#x26;token=d9f67bfc-47f7-429e-a6bc-c0125cd1807d" alt=""><figcaption></figcaption></figure>

Complete the details for your portfolio. You can add a stream by clicking on `Streams`.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FHggsCw6RNnG7WNWzLhYI%2FScreenshot%202024-06-21%20at%201.30.53%E2%80%AFPM.png?alt=media&#x26;token=4caf5bff-87ca-4341-8663-0d8258ca9afa" alt=""><figcaption></figcaption></figure>

Enter a name for your stream, and optionally link any existing projects to the stream.&#x20;

> You can create as many streams as you need.

View access can be given to to non-admin users for individual portfolios or their respective streams. Those users will only see data relevent to projects they have access to on the portfolio and/or stream.

## Linking Projects to Streams

You can add new projects to Portfolios & Streams directly..

To edit a Portfolio, click on the `cog` from the portfolio page.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FNz1OFgmcuPid2ck0mw1E%2FScreenshot%202024-06-21%20at%201.32.29%E2%80%AFPM.png?alt=media&#x26;token=edcf1868-b712-44be-afc3-06398eba451b" alt=""><figcaption></figcaption></figure>

Select Access and Streams. You can create new streams and link associated projects, or you can update existing projects on existing streams.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2Fvt973oQVpZHosJDEtxWB%2FScreenshot%202024-06-21%20at%201.33.45%E2%80%AFPM.png?alt=media&#x26;token=8c9b897d-aaa5-4389-96a4-621f587c3d5b" alt=""><figcaption></figcaption></figure>

You can also associate a project with one or more Portfolios & Streams at time of project creation or approval; or when editing a project.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FjKnhSAWOFOTPYBpmYtsf%2FScreenshot%202024-06-21%20at%201.34.29%E2%80%AFPM.png?alt=media&#x26;token=20679150-a0c6-4863-a4e2-bda3ce84bcf7" alt=""><figcaption></figcaption></figure>

## Managing Access to Streams

View access can be given to to non-admin users for individual portfolios or their respective streams. Those users will only see data relevent to projects they have access to on the portfolio and/or stream.

Access can be granted to portfolios and/or streams based on `Groups` or `Users`.

Access can be granted to the entire Portfolio and its related Streams using the option at the top of the `Access and Streams` settings page for the Portfolio.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FWKFLfBkdi2pVoDSHxfkV%2FScreenshot%202024-06-21%20at%201.35.47%E2%80%AFPM.png?alt=media&#x26;token=247d3e29-9b23-4d03-9002-bf691a70f9d0" alt=""><figcaption></figcaption></figure>

Alternatively, access to individual streams can be granted by clicking on any of the streams and configuring the access on that stream.

<figure><img src="https://372186556-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-M8s1QY2Q6YTHB4a6DMu%2Fuploads%2FEwFQ78wS6gCHYXv8uEeb%2FScreenshot%202024-06-21%20at%201.35.57%E2%80%AFPM.png?alt=media&#x26;token=4231315e-55c9-4bdb-97a4-a69642be80fd" alt=""><figcaption></figcaption></figure>
