Indicator sources and indicators for the Operational Technology Vulnerability Response (PA) dashboard
Summarize
Summary of Indicator Sources and Indicators for the Operational Technology Vulnerability Response (PA) Dashboard
The Operational Technology Vulnerability Response application is designed to facilitate the tracking and remediation of vulnerabilities within your operational technology environment. It utilizes various indicator sources and indicators to efficiently gather data and monitor the progress of vulnerability remediation efforts.
Show less
Indicator Sources
Data for the application is collected from several key indicator sources:
- OTVI.New: Collects new OT vulnerable items from the snvulvulnerableitem table.
- OTVI.Active: Includes all active vulnerable items from the same table.
- OTVI.Closed: Covers all closed vulnerable items from the snvulvulnerableitem table.
- OTRT.Active: Encompasses all active remediation tasks from the snvulvulnerability table.
For extensive data collection (over 1 million records), adjustments must be made in the Records collection section of the indicator source settings.
Key Features
The application features several indicators that allow you to measure and track remediation progress:
- OT Vulnerable Items: Tracks the total number of OT vulnerable items to minimize vulnerabilities.
- OT Critical Vulnerable Items: Monitors critical vulnerabilities with a focus on reduction.
- OT Unassigned Vulnerable Items: Identifies active items without an assigned group or individual, aiming for minimization.
- OT Closed Vulnerable Items: Measures closed items daily, with a goal to maximize closures.
- OT Deferred Vulnerable Items: Keeps track of deferred items to minimize their count.
- OT Remediation Tasks: Counts active remediation tasks to reduce the total.
- % Vulnerable Items Met Remediation Target: Calculates the percentage of closed items that meet remediation goals.
- OT Vulnerable Item Mean Time to Remediate: Assesses the average time taken to remediate closed vulnerable items.
Key Outcomes
By effectively utilizing these indicators, you can expect to:
- Reduce the number of active and critical vulnerabilities in your operational technology system.
- Minimize unassigned and deferred items for improved accountability.
- Maximize the percentage of vulnerabilities meeting remediation targets, enhancing overall security posture.
- Streamline remediation processes by tracking task statuses and durations.
Implementing these features will help ensure a robust response to vulnerabilities, contributing to a safer operational environment.
The Operational Technology Vulnerability Response application uses indicator sources and indicators to gather data and track the progress of your vulnerability remediation.
Indicator sources
- OTVI.New
- Uses the sn_vul_vulnerable_item table and collects the new OT vulnerable items.
- OTVI.Active
- Uses the sn_vul_vulnerable_item table and includes all the active vulnerable items in your OT system.
- OTVI.Closed
- Uses the sn_vul_vulnerable_item table and includes all the closed vulnerable items in your OT system.
- OTRT.Active
- Uses the sn_vul_vulnerablity table and includes all the active remediation tasks in your OT system.
Indicators
Several indicators are used to measure and track the progress of your vulnerability remediation in the Operational Technology Vulnerability Response application.
The collect records option for the indicators is inactive by default for the Operational Technology Vulnerability Response application. This option is turned off to avoid the performance issues that may occur when you collect a large amount of data for each indicator.
- OT Vulnerable Items
- Number of the OT vulnerable items on the data source OTVI.Active, which uses the sn_vul_vulnerable_item table. The goal is to minimize the number of vulnerable items in your system.
- OT Critical Vulnerable Items
- Number of the OT critical vulnerable items on the data source OTVI.Active, which uses the sn_vul_vulnerable_item table. The goal is to minimize the number of critical vulnerable items in your system.
- OT Unassigned Vulnerable Items
- All active OT Vulnerable Items where both the Assignment Group and Assigned To fields are empty. The goal is to minimize the number of unassigned vulnerable items.
- OT Closed Vulnerable Items
- The OT Closed Vulnerable Items indicator is measured daily as a unit number. The goal is to maximize the number of closed vulnerable items in your system.
- OT Deferred Vulnerable Items
- Number of OT deferred vulnerable items on the data source OTVI.Active, which uses the sn_vul_vulnerable_item table. The goal is to minimize the number of deferred vulnerable items in your system.
- OT Critical Deferred Vulnerable Items
- Number of OT critical deferred vulnerable items on data source OTVI.Active, which uses the sn_vul_vulnerable_item table. The goal is to minimize the number of critical deferred vulnerable items.
- OT Non-Deferred Overdue Critical Vulnerable Items
- Number of OT non-deferred overdue critical vulnerable items on the data source OTVI.Active, which uses the sn_vul_vulnerable_item table. The goal is to minimize the number of non-deferred overdue critical vulnerable items in your system.
- OT Remediation Tasks
- Number of OT remediation tasks on the data source OTRT.Active, which uses the sn_vul_vulnerability table. The goal is to minimize the number of remediation tasks in your system.
- OT Non-Deferred Overdue Critical Remediation Tasks
- Number of OT non-deferred overdue critical remediation tasks on the data source OTRT.Active, which uses the sn_vul_vulnerability table. The goal is to minimize the number of non-deferred overdue critical remediation tasks in your system.
- OT Non-Deferred Remediation Tasks
- Number of OT non-deferred remediation tasks on the data source OTRT.Active, which uses the sn_vul_vulnerability table. The goal is to minimize the number of non-deferred remediation tasks in your system.
- OT Non-Deferred Critical Remediation Tasks
- Number of OT non-deferred critical remediation tasks on the data source OTRT.Active, which uses the sn_vul_vulnerability table. The goal is to minimize the number of non-deferred critical remediation tasks in your system.
- OT Unassigned Remediation Tasks
- All active remediation tasks where both the Assignment Group and Assigned To fields are empty. The goal is to minimize the number of unassigned remediation tasks in your system.
- % Vulnerable Items Met Remediation Target
- ([[Closed Vulnerable Items > Remediation Target = Target Met]] / [[Closed Vulnerable Items]]) * 100
The goal is to maximize the percentage of vulnerable items that meet the remediation target in your system.
- OT Vulnerable Item Mean Time to Remediate
- [[Summed Duration of Closed Vulnerable Items]] / [[Closed Vulnerable Items]]
- OT Summed Duration of Closed Vulnerable Items
- Number of OT summed duration of closed vulnerable items on the data source OTVI.Closed, which uses the sn_vul_vulnerable_item table. The goal is to minimize the summed duration of the closed vulnerable items in your system.