Add a compensating control to the library
As a Vulnerability Manager or Analyst, add a list of compensatory controls to the Compensating Controls library in the Vulnerability Manager Workspace, which can be applied for the risk change of vulnerable items, application vulnerable items, remediation tasks, and application remediation tasks.
Before you begin
Role required: sn_vul.vulnerability_analyst, or sn_vul.vulnerability_admin
About this task
Some commonly used compensating controls are shipped with the base system. You can view these compensating controls by navigating to . You can activate or deactivate these compensating controls as per your requirement.
Procedure
What to do next
Starting from v21.0 of Vulnerability Response, you can associate compensating controls with CVEs or TPEs after adding a compensating controls to the library. For more information on how to associate compensating controls, see Associate compensating controls with CVEs or TPEs for risk change requests.
Associate compensating controls with CVEs or TPEs for risk change requests
As a Vulnerability Manager or Analyst, you can associate relevant compensating controls with a CVE or TPE, which can be applied for risk change requests.
Disable or enable risk change for a CVE or TPE
As a Vulnerability Manager and Analyst, you can disable or enable the risk change requests for the host vulnerabilities from a Common Vulnerability Entry (CVE) or Third-party Entry (TPE).