How can I consolidate multiple assigned remediation tasks with the same vulnerability?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎04-05-2022 12:46 PM
Hi,
We came across a scenario that is causing some frustration for some users. We are seeing multiple remediation tasks created for the same vulnerability each week, but the VI's have different CI's. We currently group remediation tasks by vulnerability. This seems to be happening because we perform agentless scanning for certain computers. For example, one week our scanners will detect 50 vulnerable assets and the next week it will detect another 20 for the same vulnerability. The result is 2 remediation tasks for the same vuln with different CI's. Anyone come across this and have a solution? Any feedback from the community would be great.
Some ideas I had:
*Reapply the remediation task rule manually to consolidate remediation tasks, but then I lose all work notes in existing remediation tasks inputting by users and more.
*Adjust the run frequency of the Tenable vulnerability integration import jobs. That delay's creating remediation tasks for other remediation task rules.
*Manually de-active the remediation task rule to defer remediation task creation and activate it when ready. Would this impact existing remediation tasks?
*Use scan agents instead of agentless scanning for computers.
Thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎06-15-2022 05:15 AM
Hi Dommer,
Did you get a suitable resolution for this?
Thanks
Sam
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎06-15-2022 09:27 AM
We limited the vulnerability import jobs to run once a week versus every day. That helped provide some relief where new remediation tasks were getting created daily. Otherwise we found no real solution here except to use agents for vulnerability scanning on a VPN (remote users).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎06-16-2022 05:50 AM
I haven't worked with Tenable. Have you tried generating remediation tasks that group by the preferred solution summary of the VIT? I think as long as the assignee doesn't progress the state of the remediation task past open or 'under investigation' new VITs with the same solution can be added to the existing remediation task.