by Carole Fennelly
            November 7, 2022 
 
              
            
            
            Organizations are typically overwhelmed with data that must be analyzed to determine the organization’s risk exposure. This dashboard helps prioritize remediation efforts by presenting lists of assets to prioritize in various categories. The widgets on this dashboard leverage vulnerability information from Tenable Web Application Security (WAS), Tenable.cs, and Tenable.io Vulnerability Management (Nessus, NNM).
The data presented closes the gap in awareness for security teams and enables system administrators to prioritize patch cycles and coverage in mitigation strategies. Security teams can add target groups to the dashboard template, allowing different asset managers to prioritize remediation efforts on the risk to their specific areas of concern. System administrators can take the same dashboards as actionable items to help set the priority of corrective actions and mitigation strategies.
The top row of the dashboard leverages Tenable WAS to provide a quick overview of actionable metrics to prioritize remediation of web application vulnerabilities. The middle row leverages Tenable.cs to provide an overview of vulnerabilities by risk factor related to cloud resources. The bottom row leverages Nessus and Nessus Network Monitor (NNM) to provide risk managers and system administrators information to prioritize remediation of asset vulnerabilities based on plugin family and CVSS Score. Overall, this dashboard is beneficial to several groups within the organization to reduce cyber risk.
Security leaders need to SEE everything, PREDICT what matters most and ACT to address cyber risk and effectively align cybersecurity initiatives with business objectives. Tenable.io discovers and analyzes assets continuously to provide an accurate and unified view of an organization’s security posture. The requirements for this dashboard are: Tenable Web Application Security (WAS), Tenable.cs, and Tenable.io Vulnerability Management (Nessus, NNM).
Widgets
Asset Scanning Stats by CVSS Score – This widget provides a quick overview of actionable metrics to prioritize remediation of asset vulnerabilities. The CVSSv3 information provides an overview of the highest severity vulnerabilities specific to CVSS Score. The first observed and most critical highlight if the asset was found in the last 30 days, and when the asset was last seen. Finally, the scans stats highlight recent scans. Assets that have not been scanned recently may warrant further investigation. The requirements for this widget are: Tenable.io Vulnerability Management (Nessus, NNM).
Asset Highest Vulnerabilities by Plugin Family – This widget displays vulnerabilities by plugin family. The results are filtered to only display critical and high vulnerabilities. The requirements for this widget are: Tenable.io Vulnerability Management (Nessus, NNM).
WAS Highest Vulnerabilities by Plugin Family – This widget displays vulnerabilities by plugin family related to web applications. The results are filtered to only display critical and high vulnerabilities related to web applications. The requirements for this widget are: Tenable Web Application Security (WAS).
Web Application Scanning Stats by CVSS Score – This widget provides a quick overview of actionable metrics to prioritize remediation of web application vulnerabilities. The web application stats provide an overview of the highest severity vulnerabilities specific to web applications. The assets stats highlight vulnerabilities with the highest CVSSv3 score. The scans stats highlight recent scans. Assets that have not been scanned recently may warrant further investigation. The requirements for this widget are: Tenable Web Application Security (WAS).
Cloud Resources Scanning Stats – This widget provides a quick overview of actionable metrics to prioritize remediation of cloud resource vulnerabilities. The cloud resource risk factor provides an overview of the highest severity vulnerabilities specific to cloud resources. The first observed and last seen section highlights if the resource was found in the last 30 days, and when the resource was last seen. Finally, the scans stats highlight recent scans. Assets that have not been scanned recently warrant further investigation. The requirements for this widget are: Tenable.cs.
Cloud Resource by Risk Factor – This widget displays vulnerabilities by risk factor related to cloud resources. The results are filtered to only display critical and high-risk factor vulnerabilities. The requirements for this widget are: Tenable.cs.