What the vulnerability analysis and the permission analysis evaluate, where their data comes from, and what the results are used for.
An analysis evaluates the entire inventory, not a single asset. It answers
questions that do not show up on one asset alone – which systems a
vulnerability affects, or who has access across multiple folders. Docusnap365
runs two such analyses: the vulnerability analysis against known CVEs, and
the permission analysis for the file system.
Known vulnerabilities (CVEs) against the software installed on captured
systems. Menu entry CVE Analysis.
Permission Analysis
Who can access which directories, and where the right comes from. Menu
entry File System.
Permission Analysis is the menu group heading, not a clickable entry;
File System is the only entry under it. Permission modules for shares,
databases and SharePoint will join the same group.
Scan modules capture systems,
software, directories and permissions; a background match compares captured
software against known vulnerabilities, and an analysis package evaluates
NTFS permissions.
Neither area has a create function. A CVE comes from the background match, a permission analysis result from an
analysis package – never from an entry made in the interface.
The vulnerability analysis shows up in two places with different scope. The
module surface under Analysis answers how many CVEs exist overall, which
to treat first, and who is responsible; the CVEs tab on a single asset
answers what concerns that one device.Two related figures rate a CVE: the CVSS score, a number
from 0 to 10, and the severity, with the four
levels Critical, High, Medium and Low. Where severity is set, it
takes precedence; where only the score exists, Docusnap365 derives the level
from it.
The vulnerability analysis exists to prioritize CVEs by severity, assign
them to a responsible person, and carry them into an ISMS control through
the Controls tab – the same control, not a copy. The permission analysis
answers who can access which directories and where the right comes from.
Both analyses only evaluate what a scan module has captured: software no scan
module captures never appears in a vulnerability analysis; directories no
scan module captures never appear in a permission analysis. CVE data is only
as current as the last background match, not the last scan.