Skip to Main Content
Cyber GRC Ideas Portal
ADD A NEW IDEA

Threat & Vulnerability Management

Showing 29 of 130

Data feed from external scanning vendors should be up-loadable and tracked in MSI platform using ISM

SABB employs the services of 2 external vendors to scan the internet facing IP addresses to check for any vulnerabilities. These results (2 different excel formats) should be up-loadable into the system. The external IP can in fact refer to the sa...
Guest over 6 years ago in Threat & Vulnerability Management 0 Pending Roadmap Inclusion

Auto closure of issues if related vulnerability is not active

Issues created by vulnerability scan should be auto-closed if in the subsequent scans, that vulnerability is not active A new source type – External Vulnerability Update to be supported in Issue management app. This feature should be an optional f...
Guest over 6 years ago in Threat & Vulnerability Management 0 Pending Roadmap Inclusion

New comparison report to track SLA adherence

The SLA applied by TVM team on IT resource users is 90 days. All the issues open on the 1st day of the quarter has to be stored (Issue, Action, start date, Due Date, Title, Pending with, Owner by Org, Owner etc.,). The same vulnerabilities/issues ...
Guest over 6 years ago in Threat & Vulnerability Management 0 Pending Roadmap Inclusion

Pre-Vulnerability scan workflow and Approval workflow

Users can raise request/ticket for server movement, new server commissioning, production movement etc., This will trigger Nexpose scan on the target IP by TVM coordinator Once the vulnerability scan results are out and no issues are triggered, the...
Guest over 6 years ago in Threat & Vulnerability Management 0 Pending Roadmap Inclusion

When Scanning the key should be configurable from IP address to Hostname

When assets are pulled in from CMDB Service Now IP address information is not held. Therefore the scanner will pick up many IP addresses where the Asset is available but no IP information is entered. The ask is to include in M7 the ability to conf...
Guest over 7 years ago in Threat & Vulnerability Management 2 Pending Roadmap Inclusion

Import Assets from QualysGuard into GRC Asset Library.

QualysGuard has an inventory of Assets being scanned and it therefore adds value to import the same set of Assets into the GRC Asset Library.
Deleted User over 8 years ago in Threat & Vulnerability Management 0 Cannot be considered in the Roadmap

Add Process linkage as an attribute in Remediation Rule setup.

From an integrated GRC approach it adds value to have an Asset's Process linkage available under Asset vocabulary when defining Remediation Rules.
Deleted User over 8 years ago in Threat & Vulnerability Management 0 Pending Roadmap Inclusion

FIPS 199 classification of Assets.

Increasingly FIPS 199 is being leveraged as a method to classify Assets in order to determine their business significance. It adds value to enhance the Asset Library to support the FIPS 199 methodology.
Deleted User over 8 years ago in Threat & Vulnerability Management 0 Cannot be considered in the Roadmap

Add Risk Rating/Score as an attribute in Remediation Rule setup.

From an integrated GRC approach it adds value to have an Asset's Risk Rating/Score available under Asset vocabulary when defining Remediation Rules.
Deleted User over 8 years ago in Threat & Vulnerability Management 0 Pending Roadmap Inclusion