Starting point
Docusnap Sports GmbH has finished scanning the Windows servers. Under Analysis › CVE Analysis, the list By CVEs shows at the top a CVE with CVSS 9.8 and severity Critical. Affected: the web frontend of the ERP system.1. Prioritize
The list By CVEs is sorted by CVSS descending. The most dangerous vulnerability is at the top. We open it via the column CVE ID. The Overview tab shows the CVSS value, the severity and the metrics of the rating. The Remediation Deadline in the section General follows from the CVSS value: at 9.8 it is 7 days.2. Check affected systems
The tab Affected Assets lists the systems, the tab Affected Software the installations with version and host. Here: the web frontend, one installation.Both tabs count installations. A system with two affected installations appears
twice.
3. Assign and rate
Tab Assessment, pencil icon.
Save.
Accepted and False Positive require a Justification. An accepted CVE stays
documented without a control.
4. Create the control
Tab Controls, button Control, in the dialog Create New:
The control is linked to the CVE and also appears under ISMS › Risk Management
› Controls.
The Controls tab on the CVE is a view of the ISMS controls, not a separate
management. The same control can treat a CVE and fulfil a regulation objective.
5. Track implementation
Under ISMS › Risk Management › Controls the administrator sets the status to In Progress and, after the update, to Implemented. The CVE’s Controls tab shows the progress: one of one control implemented.6. Close the CVE
Tab Assessment: Status Fixed. After the next scan of the web frontend the matching detects the new version; the CVE no longer appears under Open CVEs of the asset.Result
- The critical CVE has an owner, a due date and a status.
- A control in the ISMS documents the remediation.
- The path from vulnerability to implementation is traceable — on the CVE and on the control.