Rules
Rules define what Beacon watches for across your assets and risks. Disable a rule to silence its findings, or tune its thresholds — edits take effect immediately: every rule change invalidates the scan cache, a BOM country of origin configuration change triggers an immediate sweep, and an External signals keyword edit re-matches open signals against the new list.
Each rule is shown as a card with its name, a Built-in tag (it ships with VSEC, as opposed to a future custom rule), a description, an enable/disable switch, and any configuration fields it takes. Every rule — including built-in ones — can be switched off from here if you don’t want its findings. Number fields and comma-separated lists save when you click away or press Enter; the enable switch saves immediately. A rule’s configuration fields are disabled while the rule is switched off.
Rules With No Configuration
| Rule | What it watches for |
|---|---|
| Incomplete risk | A risk missing a required evidence input (likelihood or impact) |
| Stale score | New evidence arrived after the risk’s last scoring run |
| Uncovered asset | An asset with no risks, adjacent to assets that do carry risks |
Configurable Rules
| Rule | Configuration | Default |
|---|---|---|
| Stalled event | Days a Clause-8 evidence item can sit in Event before flagging | 30 days |
| Untreated high risk | Residual score threshold that counts as “high” | 4 |
| BOM country of origin | Comma-separated list of ISO 3166-1 alpha-2 country codes (e.g. CN, RU) | none configured |
| External signals | Comma-separated watch keywords (e.g. ransomware, zero-day, supply chain) | disabled, no keywords |
BOM Country of Origin
Flags a package in an asset’s SBOM or HBOM — uploaded directly, or synced from linked xZETA firmware — that originates from one of the listed countries. This is the one rule that also creates a risk automatically: see Beacon → BOM Country of Origin.
External Signals
Enabling this rule is what turns on automatic feed ingestion for the External Signals inbox — while it’s off, only manually added signals flow through matching. Asset matching always runs on asset names plus each asset’s Keywords and Business Unit property terms; the watch-keyword list doesn’t narrow that. Instead, watch keywords additionally flag signals beyond what your assets already declare — a keyword hit marks the signal as notable without mapping it to a specific asset.
Permissions
Access to Rules is governed by the Monitor permission block — see Permissions.