Categorizing findings and discovered items using classification rules

  • Release version: Australia
  • Updated March 12, 2026
  • 1 minute to read
  • Classification groups automate the classification of entities or records based on the classification rules defined in the group. The condition for each rule is evaluated in order, and the first matching rule is used.

    The Unified Security Exposure Management base system includes the following two classification groups, which classify discovered items and vulnerabilities respectively:
    • Technologies Classification
    • Discovered Containers Classification
    • Configuration Tests Classification
    • CWEs Classification
    • Test Groups Classification
    • Discovered Applications Classification
    • Discovered Items Classification
    • Vulnerability Entries Classification
    Whenever findings and discovered items are imported, the vulnerability classification rules in the respective groups are executed. Based on the conditions set in the rule, the records are classified into the relevant classification group. You can create, edit, delete, or reapply these rules to an existing vulnerability.
    Note:
    • For a selected table, there can only be one active classification group.
    • Once you create a group, you can’t delete it.