Manage Vulnerabilities

You can manage your organization's vulnerabilities from the Actions Bar or the Vulnerability Details Side Panel, depending on the level of change needed.

Actions Bar

To activate the action bar, click Select or select the engagement row checkbox on the table. Use the actions bar to select multiple engagements and perform the same bulk action on each one.

From the actions bar, you can change severity, update the engagement state, or assign a remediation user. Select the action you want, then follow the prompts in the dialog box.

Vulnerabilities actions bar example
Vulnerabilities actions bar example

Vulnerability details side panel

Using the vulnerability details side panel is ideal for a single engagement.

From the Vulnerability Details side panel, you can confirm the current severity, apply a client-assigned severity to reflect business context and personal prioritization, and update the state as remediation progresses. This helps keep NetSPI aligned on what to prioritize during remediation testing and validation.

Vulnerabilities details side panel
Vulnerabilities details side panel

Severity

The one area that can be managed is client assigned severity. Click the entry to open the list of available choices and select one that meets the severity needs for the vulnerability.

Severity Level
Severity Level

State

Click the entry to open the list of available states and select the next state to move the vulnerability to.

For more information and to review a list of vulnerability states, reference: Vulnerability States and Definitions

Remediation State
Remediation State

Team

The Team section is used to managed assignments for Assignee, Security Owner, and Reviewer.

Team Assignments
Team Assignments

Assignee and Security Owner

To add either:

  1. Click the Add icon.
  2. Search for and then choose the Assignee or Security Owner from the list.
  3. Click Submit.