Use security issues

Security issues are used to record all elements resulting from Cyberwatch security analyses that do not fall under vulnerabilities. These elements are frequently obtained from scans of “Network targets and websites.” However, they can also be obtained from the analysis of an asset, such as security issues indicating the obsolescence of an OS or application, or the presence of a malicious open source package.

Cyberwatch allows you to create “custom” security issues and associate them with your assets. This feature can be used, for example, to:

  • import data from a security audit / penetration test
  • import results from third-party security software using our API

Create a security issue

From an asset page:

  1. Click on Inventory
  2. Click on the name of the affected asset
  3. In the asset details, click on the “Security issues” tab
  4. Click on Add a new security issue

From a CVE page:

  1. Click on Vulnerability Encyclopedia
  2. Click on the relevant CVE
  3. In the CVE details, click on “Actions”
  4. Click on “Add a security issue”
  5. Fill in the form fields:

    • Reference: reference of the security issue (example: reference from a penetration test report, or from third-party security software)
    • Title: title of the security issue
    • Description: description of the security issue
    • Severity: severity of the security issue
    • Assets: list of assets affected by the security issue
    • CVEs: list of CVEs affected by the security issue
  6. Save

If the fields have been filled in correctly, the security issue will appear in the asset’s “Security issues” tab.

Additionally, if CVEs have been specified in the CVEs field of the form, these CVEs will be assigned to the asset and will also appear in the “Vulnerabilities” tab.

Edit a security issue

  1. Click on Inventory
  2. Click on the name of the affected asset
  3. In the asset details, click on the “Security issues” tab
  4. Click on the edit button (pencil icon) on the line of the chosen security issue
  5. Modify the desired fields in the form. Fields not modified will retain their existing values
  6. Save

Delete a security issue

  1. Click on Inventory
  2. Click on the name of the affected asset
  3. In the asset details, click on the “Security issues” tab
  4. Click on the delete button (trash icon) on the line of the chosen security issue
  5. Confirm

Delete multiple security issues

  1. Click on Inventory
  2. Click on the name of the affected asset
  3. In the asset details, click on the “Security issues” tab
  4. Select the security issues to delete
  5. Click on the “Bulk actions” button to display the different options
  6. Click on the “Delete selected security issues” button
  7. Confirm

Severity rate

Security issues present in Cyberwatch are assigned a severity rate ranging from informational to critical. The assignment of this severity rate is determined by Cyberwatch. It depends on the type of issue, the risk it represents, and the impact it may have.

In other words, the severity rate of a security issue is relative to its level of danger. For example, a security issue of type “OS obsolescence” has a higher score than a security issue of type “application obsolescence.” This is because the obsolescence of a system could have more impact than that of an application.

See the list of all security issues


Table of contents


Back to top

English Français Español