Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 10 Next »

Criticality & Vulnerability

The Criticality & Vulnerability visualization is displayed under the Workspace.

 

 

Description:

Use the Criticality & Vulnerability visualization to view a roll-up of your vulnerability scan results.

FieldDescription
TitleName of the vulnerability as defined by iSight (at this time).
CVE/CVE CountVulnerability as assigned by iSight using the National Vulnerability Database (NVD) convention. This CVE count is expected to match customer scan information against the vendor/product pair (via Sprint 15), using synthetic Nessus scan information.

 Vendor

Vendor of the identified vulnerable software/system as defined by customer scan information (Nessus or Qualys)

ProductThe product associated with the Vendor.
Labor Effort

A customer input that assigns a low, medium or high selection.

Patch DifficultyA customer input that assigns a low, medium or high selection.
Vulnerable HostsThe count of the number of vulnerable hosts as identified by vulnerability scanning from Customer scan information (Nessus or Qualys). (Sprint 15)
Initial Estimate

A customer input that assigns a cost/value to patching a vulnerability based on the vulnerability/CVE using an FTE count and annual cost.

ExploitabilityThe National Vulnerability Database Exploitability category assignment to the given CVE.
Anticipated Risk LevelA Customer input that assigns a low, medium or high selection.
  

 


 

Related Documentation:

 

 

  • No labels