VRM Applications and Dashboards
Use this reference to identify where VRM stores operational records, supporting workflow data, and reporting views.
Choose Your Path
Goal | Go To |
|---|---|
Manage findings, assets, cases, remediation, or exceptions | |
Monitor ingestion, filtering, exports, or reporting data | |
Select an operational or reporting dashboard | Dashboardsο»Ώ |
Review workspaces, assets, sensors, and the packaged connector |
Operational Applications
Operational applications store the records analysts use to prioritize, investigate, group, remediate, and close vulnerability work.
Vulnerability Finding
Acronym: VFIN
The Vulnerability Finding application is the primary system of record for vulnerabilities. Each record represents a vulnerability associated with one asset.
Information Group | Examples |
|---|---|
Identification | Vulnerability ID, source, scan ID, unique ID, and raw finding data. |
Asset context | Asset reference, primary identifier, hostnames, IP addresses, MAC addresses, zone, criticality, and additional metadata. |
Risk and intelligence | Turbine Risk Score, CVSS, EPSS, exploit data, known exploitation, weaknesses, attack patterns, and MITRE ATT&CK techniques. |
Case and exception state | Grouping ID, grouping status, case tracking ID, and exception reference. |
Remediation | Status, remediation owner, remediation advice, SLA status, outcome, and dates. |
Automation health | Requires Attention and supporting documentation. |
Use this application to:
- Prioritize findings by Turbine Risk Score.
- Review vulnerability and asset context.
- Reassign an asset when the existing association is incorrect.
- Reprocess a finding through enrichment and scoring.
- Add findings to a case or create a manual case.
- Review exception and remediation status.
See Vulnerability FindingsVulnerability Findings for the published finding details.
Vulnerability Asset
Acronym: VAST
The Vulnerability Asset application stores systems associated with vulnerability findings.
Information Group | Examples |
|---|---|
Identity | Primary asset identifier, asset type, hostnames, IP addresses, MAC addresses, and repositories. |
Business context | Asset zone, zone criticality, asset criticality, and additional metadata. |
Risk | Asset Risk Score, score label, highest-risk finding, open finding count, and last update time. |
Remediation routing | Remediation owner, remediation channel, and risk-based SLA targets. |
Automation health | Requires Attention and supporting documentation. |
Changes to asset criticality, zone, owner, or remediation channel can propagate to associated open findings.
See Vulnerability Asset ManagementVulnerability Asset Management for the published asset details.
Vulnerability Case Management
Acronym: VRSP
The Vulnerability Case Management application groups related findings into an analyst-owned unit of work.
Use a case to:
- Review all grouped findings.
- Track the current owner and case owner.
- Prioritize work by the highest associated Turbine Risk Score.
- Create remediation items.
- Monitor remediation creation status and automation errors.
- Close the case after associated findings are resolved.
Cases can be created manually, through automated grouping, or through automated grouping and remediation.
See Vulnerability Case ManagementVulnerability Case Management for the published case details.
Vulnerability Remediation Item
Acronym: VRI
The Vulnerability Remediation Item application tracks remediation work for one case and its associated findings.
Key information includes:
- Case tracking ID
- Finding tracking IDs and summaries
- Remediation owner and channel
- External ticket ID and URL
- Ticket status, message, and last update time
- Requires Attention and supporting documentation
Depending on solution configuration, VRM can submit a remediation item automatically or wait for a user to initiate Create ITSM Ticket.
See Creating and Managing Remediation ItemsCreating and Managing Remediation Items for the published remediation workflow.
Vulnerability Exception
Acronym: VEXC
The Vulnerability Exception application defines findings that do not require standard remediation.
An exception can use criteria such as:
- Vulnerability identifiers
- Asset identifiers or zones
- Finding sources
- Minimum and maximum Turbine Risk Score
- Effective and expiration dates
- Enabled or disabled status
The exception workflow evaluates matching criteria during finding enrichment. Applicable findings receive the exception state and can be excluded from normal remediation and SLA calculations.
See Exception ManagementException Management for the published exception details.
Supporting Applications
Application | Acronym | Purpose |
|---|---|---|
VRM - CSV Import | VCI | Stores finding or asset CSV attachments, source selection, page size, import state, and row counts. |
VRM - Ingestion Page | VMIP | Stores one batch of finding data, its attachment, source, count, processing status, sample data, and error details. |
VRM - Export Results | VER | Stores known-finding exports used by deduplication, including current or stale state, row count, file, and processing time. |
VRM - Filtering Activity | VFA | Stores filtering and deduplication metrics, including excluded, known, and unseen findings, memory use, and runtime. |
VRM - Reporting | VRPT | Stores metric snapshots for findings, assets, exceptions, and remediation items used by the reporting dashboard. |
Supporting applications are primarily maintained by automation. Use them to monitor processing, investigate failures, and validate reporting inputs.
Application Relationships
Source | Related Application | Relationship |
|---|---|---|
Vulnerability Finding | Vulnerability Asset | A finding references the affected asset and copies selected asset context for scoring and routing. |
Vulnerability Finding | Vulnerability Exception | A finding references an applicable active exception. |
Vulnerability Finding | Vulnerability Case Management | Grouped findings store the case tracking ID and contribute to case risk. |
Vulnerability Case Management | Vulnerability Remediation Item | A case creates one or more remediation items based on grouped findings and routing information. |
Vulnerability Remediation Item | Finding and case records | Ticket state propagates to associated findings and the parent case. |
CSV Import | Ingestion Page | A finding CSV is divided into page records before filtering and enrichment. |
Export Results | Filtering Activity | The current known-finding export supports comparison; filtering records capture the outcome. |
Operational applications | VRM - Reporting | Scheduled reporting flows aggregate operational data into metric records. |
Application Automation Map
Use this map to identify the automation that creates or updates each primary record and where to verify the result.
Application | Created or Updated By | Related Records | Verify |
|---|---|---|---|
Vulnerability Finding | Enrichment Pipeline, Re-Enrich Finding, asset updates, exception processing, grouping, and ticket-status synchronization | Vulnerability Asset, Vulnerability Exception, Vulnerability Case Management, and Vulnerability Remediation Item | Risk score, asset association, exception state, grouping status, case tracking ID, remediation status, and Requires Attention |
Vulnerability Asset | Write Assets, Calculate Asset Risk Scores, and asset metadata refresh | Open Vulnerability Finding records associated by asset identifiers | Asset identifiers, criticality, owner, remediation channel, aggregate risk, open finding count, and Requires Attention |
Vulnerability Case Management | Case Creation, Create New Case, case risk-score updates, and remediation-status synchronization | Grouped Vulnerability Finding records and created Vulnerability Remediation Item records | Finding relationships, owner, highest risk score, remediation state, and Requires Attention |
Vulnerability Remediation Item | Create Remediation Items, ticket submission, ticket-status checks, and ticket closure | Parent Vulnerability Case Management record, grouped findings, and external ITSM ticket | Owner, channel, ticket ID and URL, ticket status, last update time, and Requires Attention |
Vulnerability Exception | Administrator-managed exception records evaluated during finding enrichment and re-enrichment | Matching Vulnerability Finding records | Enabled state, matching criteria, effective dates, expiration date, and affected findings |
Dashboards
Dashboard | Use |
|---|---|
Vulnerability Management Overview | Review active findings, assets, critical assets, case counts, exceptions, SLA status, risk distribution, and remediation performance. |
Assets Overview | Review asset inventory, risk, criticality, highest-risk findings, and remediation ownership. |
Vulnerability Analyst View | Prioritize analyst work across findings and cases by risk, status, owner, and other operational filters. |
Requires Attention View | Locate assets, findings, cases, and remediation items that require configuration or manual intervention. |
VRM - Reporting | Review historical and aggregate reporting records generated for findings, assets, exceptions, and remediation items. |
VRM Utilities Dashboard | Monitor ingestion volume, page queues, filtering, enrichment progress, and source distribution. |
Dashboard reports and counts can vary after administrators customize the solution.
Supporting Solution Content
Supporting content connects application workflows, stores required configuration, and organizes operational views.
Workspaces
Workspace | Purpose |
|---|---|
VRM - Vulnerability Response Management | Organizes the main operational applications and dashboards. |
VRM - Utilities | Organizes CSV ingestion, ingestion pages, exports, filtering activity, and utility monitoring. |
Custom Assets
Asset | Parameters | Use |
|---|---|---|
Turbine Tenant Credentials | Host, Account ID, Tenant ID, Personal Access Token | Allows packaged automation, including the reporting playbook, to access tenant data. |
Treat personal access tokens as secrets. Do not place token values in documentation, exported examples, or unprotected records.
Sensors
Sensor | Type | Use |
|---|---|---|
Write Assets Page | Flow event | Submits an array of normalized asset objects for writing. |
Write Ingestion Page | Flow event | Creates one file-backed ingestion page. |
Submit Ingestion Page to Enrichment Pipeline | Flow event | Passes a queued ingestion page to normalization and enrichment. |
Vulnerability Finding | Flow event | Submits a finding to the standard enrichment pipeline. |
Close Vulnerability Finding | Flow event | Submits a finding for closure processing. |
Packaged Connector
To ingest Qualys vulnerability data, install and configure the supported Qualys Vulnerability Scanner connector and its required asset. Use the connector documentation for available actions and configuration requirements.
Next Steps
- Review Vulnerability Response Management WorkflowsVulnerability Response Management Workflows to follow data between applications.
- Review VRM Playbooks and ComponentsVRM Playbooks and Components to identify the automation that maintains each record type.