Viewing your Tenable.io Vulnerabilities
Overview
This page is where you can view your Tenable vulnerability data that has been exported into CS. The entire page runs off a "main" export, whilst comparing the results with the prior 3 exports to provide a view of your vulnerabilities over a period of time.
Choosing an export
- By default, this page will open using the most recent, non-archived export that has been run from Tenable.io to CS.
- You can use this drop down to choose another export to use as the main export.
Compare settings
- This is where you can update which exports are being compared with the "main" export on the page.
- By default, these will be automatically set to the last 3 exports prior to the "main" export.
- For example, if you have been running exports on a quarterly basis for the past year, you will have 4 exports in the system - Q1, Q2, Q3, Q4. The "main" export on the page will be Q4 (the most recent), and it will be compared with Q3, Q2 and Q1 data within the graphs.
Benchmarking org
- The final field in these settings, allows you to choose a benchmarking organisation if you have access to more than one.
- For more information on setting up benchmarking, please see Setting up Benchmarking for Tenable.io
Graphs
Assest review | Onboards / Offboards
- This graph provides a comparison of the "main" export and the two prior.
- Due to the potential of the number of assets being scanned changing between the exports, this graph shoes a per asset count of the vulnerabilities broken down by severity to ensure a like-for-like comparison.
Vulnerability Scan Results
- These two graphs are looking only at the "main" export on the page.
- The first is a view of you resolved vs outstanding vulnerabilities
- The second is a view of the age of those vulnerabilities to help you spot which are not being resolved over time
Vulnerability management timeline
- These two graphs are comparing the "main" export with the previous 3 that have been setup in the compare settings, broken down into the number of vulnerabilities vs the number of fixes across the same period.
Notes
- The notes section is visible to all users from your organisation.
- This is where you can add/edit notes related to the "main" export for reference at a later date.
- You can also see these notes on the Exports page here:
Critical Vulnerabilities Table
- This table provides a granular view of the vulnerabilities found within Tenable.io and can be seen as a different view of the Findings page within Tenable.
- CS lists the findings into the actual vulnerabilities and groups the assets with those vulnerabilities to provide a more condensed and easy to read layout
- By default, the findings are filtered by Critical severity only, however you can change this by using the FILTER button on the top right of the table.