Tenable Enhances Nessus Risk Prioritization to Help Customers Expose and Close Exposures
Tenable, the exposure management company, announced new risk prioritization and
compliance features for Tenable Nessus, the #1 vulnerability assessment solution in accuracy,
coverage and adoption. Nessus supports new and updated vulnerability scoring
systems – Exploit Prediction Scoring System (EPSS) and Common Vulnerability
Scoring System (CVSS) v4 – to help customers implement more effective prioritization
for risk reduction and maintain compliance.
Due to evolving
threats and expanding attack surfaces, organizations rely on multiple risk
scoring systems, which are not effective risk qualifiers on their own to
determine criticality. With Tenable Nessus, customers can take advantage of the
latest industry-adopted vulnerability scoring systems – EPSS and CVSS v4 – and
Tenable Vulnerability Priority Rating (VPR) to identify and take action on the
vulnerabilities that pose the greatest risk specific to their environment.
Leveraging an advanced data science algorithm developed by Tenable Research,
Tenable VPR combines and analyzes Tenable proprietary vulnerability data,
third-party vulnerability data and threat data to effectively and efficiently
measure risk.
“EPSS and CVSS are
single variables in the risk equation – context around exposures delivers a
deeper level of understanding around true risk,” said Shai Morag, chief product
officer, Tenable. “Recent Tenable Research found that only 3% of
vulnerabilities most frequently result in impactful exposure.
We’ve optimized Nessus to meet the evolving needs of our customers, empowering
informed vulnerability prioritization strategies to address these critical
few.”
Key features in
this release include:
- EPSS and CVSS v4 Support enables users to see
and filter plugins by EPSS and CVSS v4 score, further informing
prioritization strategy. This feature enables security teams to remain
compliant with organizational policies that require the use of EPSS or
CVSS as the primary scoring system.
- Nessus Offline Mode addresses challenges with
conducting vulnerability scans offline in air-gapped environments.
Building upon existing offline scanning capabilities, Nessus runs critical
services only, removing unwanted traffic generated by functions that rely
on an active internet connection, thereby ensuring the security of
sensitive data within a secure environment.
- Declarative Agent Versioning
On-Prem enables
users to create and manage agent profiles in Nessus Manager for Tenable
Security Center. Users can specify a product version for an agent deployed
in an environment, thereby reducing disruptions in day-to-day operations
and enabling users to adhere to enterprise change control policies.
Leave A Comment