Tenable AI Exposure Metrics
The following metrics are used to assess data within Tenable AI Exposure:
Issue and Finding Severity
Issues and Findings are categorized into severity categories based on the expected potential security risk to your business.
| Severity Category | Business Risk |
|---|---|
| Critical |
The highest level of issue, representing a clear and active threat with severe consequences.
|
| High |
A serious issue that strongly indicates malicious activity or exposure of sensitive data.
|
| Medium |
An issue with a moderate risk of leading to harmful behavior or data exposure if left unchecked.
|
| Low |
A minor issue with little to no immediate security impact.
|
User Risk
Users are be categorized based on the expected potential risk they present to your organization.
| Severity Category | User Risk |
|---|---|
| Critical |
User activity represents a direct and active threat to AI security, compliance, and business integrity.
|
| High |
User behavior indicates serious attempts to bypass AI security controls or expose sensitive data.
|
| Medium |
User behavior shows moderate potential for security or compliance issues. Could escalate if repeated or combined with other actions.
|
| Low |
User activity poses minimal security risk, with little chance of leading to sensitive data exposure or harmful outcomes.
|
Policy and Rule Severity
Policy and Rule severities are user defined, and can be configured in the following locations:
-
Policy Severity — Via the Edit Policy page. For more information, see Edit a Policy.
-
Rule Severity — Via the Edit Rule page. For more information, see Edit a Policy Rule.
| Severity Category | Description |
|---|---|
| Critical |
The highest risk level, representing a clear and present security threat with significant potential impact (legal, financial, or reputational).
|
| High |
A serious risk event where the detection strongly indicates a security violation or policy breach that could cause harmful output, sensitive data exposure, or exploitation.
|
| Medium |
A moderate risk event where the issue could potentially expose sensitive data or enable harmful behavior if not addressed.
|
| Low |
A minor risk event where the detected issue poses limited or no immediate security impact.
|
Policy and Rule Sensitivity
Policy and Rule sensitivities are user defined, and can be configured in the following locations:
-
Policy Sensitivity — Via the Edit Policy page. For more information, see Edit a Policy.
-
Rule Sensitivity — Via the Edit Rule page. For more information, see Edit a Policy Rule.
| Sensitivity Level | Description |
|---|---|
| High |
A stricter rule setting where AI systems are tuned to detect and block even subtle or low-confidence signs of malicious or harmful content. This sensitivity level:
|
| Balanced |
A moderation or detection setting where AI security rules aim to strike a balance between accuracy and usability — reducing both false positives (overblocking safe content) and false negatives (missing harmful content). This sensitivity level:
|