Working with Results Overview
Once a scan finishes, you move on to understanding and acting on the risks that were found. Even for the same results, the perspective you need depends on your goal. When surveying the whole organization there is the dashboard, when handling individual items there is vulnerability management, and when checking standards compliance there is the compliance view, each prepared for the situation at hand.
Recommended order
The fastest flow for reducing risk is as follows.
- In the [Dashboard] , identify the most at-risk services and items right now.
- Enter vulnerability management (triage) and work through items by severity and KEV priority.
- Organize recurring exceptions as false positive or accepted risk to reduce noise.
- Check improvement trends with the security score , and share with stakeholders via reports and VEX .
- Stay continuously aware of new threats affecting your assets through security news .
Next steps
At a glanceDashboardOrganization-wide risk on one screenHandleVulnerability ManagementReview individual findings, false positive/accepted riskStandardsComplianceOWASP/CWE/KISA compliance statusMetricsSecurity ScoreSecurity posture and improvement trendsShareReports & VEXPDF reports and VEX exportThreatsSecurity NewsLatest threats affecting your assets