Manage Exposure Cards

In Tenable Exposure Management, you can manage exposure cards in the following ways:

Create a Custom Exposure Card

Required User Role: Administrator or Custom Role

In Tenable Exposure Management, you can create a custom exposure card to specify the categories for which you want to see data. Once you create a custom exposure card, you can then select the card in the exposure card library to view its data on the Exposure View page.

Before you begin:

To create a custom exposure card:

  1. At the top of the exposure card library, click the New Custom Card button.

    The New Custom Card page appears.

  2. In the Card Details section:

    1. In the Card Name box, type a name for the exposure card.

    2. In the Card Description box, type a brief description of the exposure card.

  3. In the Adding Tags section, select the tags you want to use to provide data for the exposure card:

    1. (Optional) Use the Search box to search for specific tags.

    2. Select the check box next to each tag you want to use to provide data for the exposure card.

  4. Click Save .

    Tenable Exposure Management saves the exposure card and adds it to the Custom tab within the exposure card library.

Tip: You can later edit the card to configure more settings such as the card layout and targets, as well as change the defaults for card's Trend and Remediation SLA.

Edit an Exposure Card

Required User Role: Administrator or Custom Role

To edit an exposure card:

  1. In the exposure card library, cick the card you want to edit.

    The card information appears.

  2. In the upper right corner of the page, click the button.

    A menu appears.

  3. Click Edit.

    The edit card page appears.

  4. On the Card Settings tab, make any desired changes:

    • Card Settings

      Option Description
      Card Name Edit the name of the card.
      Card Description Edit the card description.
    • Benchmark Industry

      Option Description
      Benchmark Industry

      In the drop-down menu, select the industry to use as a benchmark when comparing your metrics. For more information, see Tenable Exposure Management Metrics.

    • Card Layout

      Option Description
      Show Metric

      Do any of the following:

      • Select the check box next to any metric that you want to include in the exposure card.

      • Deselect the check box next to any metric that you do not want to include in the exposure card.

      Open by Default

      Do any of the following:

      • Enable the toggle for any metric that you want to open by default when viewing the exposure card.

      • Disable the toggle for any metric that you do not want to open by default when viewing the exposure card.

      Drag to Reorder Drag and drop the rows of metrics to edit the order in which they appear on the exposure card.
    • Exposure Card Targets

      Option Description
      Default/Custom toggle

      Do any of the following:

      • Enable the toggle to use the default options for this section.

      • Disable the toggle to set custom options for this section.

      Card Targets

      The Card Targets section allows you set the overall target for the card.

      Select the radio button next to one of the following options:

      • Custom — Manually select a target benchmark for the exposure card by doing one of the following:

        • In the text box, manually type a target benchmark number for the card.

        • Click and drag the slider to select a target benchmark number for the card.

      • Set to Global Target — Automatically set the target to match your Global CES for the data.

      • Set to Industry Benchmark — Automatically set the target to match the industry benchmark for the data.

      • Set to Population Benchmark — Automatically set the target to match the population benchmark for the data.

    • Exposure Targets (Custom Cards Only)

      Option Description
      Exposure Targets
      • Vulnerability Management

      • Web Applications

      • Identity Exposure

      • Operational Technologies

      • Cloud Security

      The Exposure Targets section allows you set the target benchmark for each individual category whose data populates the card.

      For each category, select the radio button next to one of the following options:

      • Custom — Manually select a target benchmark for the category by doing one of the following:

        • In the text box, manually type a target for the category.

        • Click and drag the slider to select a target for the category.

      • Set to Global Target — Automatically set the target to match your Global CES for the data.

      • Set to Industry Benchmark — Automatically set the target to match the industry benchmark for the data.

      • Set to Population Benchmark — Automatically set the target to match the population benchmark for the data.

    • Trend

      Option Description
      Default/Custom toggle

      Do any of the following:

      • Enable the toggle to use the default options for this section.

      • Disable the toggle to set custom options for this section.

      Default Timespan Shown

      In the drop-down menu, select the timespan to use for the Trend section within Tenable Exposure Management.

    • Remediation SLA

      Option Description
      Default/Custom toggle

      Do any of the following:

      • Enable the toggle to use the default options for this section.

      • Disable the toggle to set custom options for this section.

      Low, Medium, High, and Critical ranges For each category, type the number of days within which each risk level of SLA must be addressed. For example, if you have an internal SLA to address critical Computing Resources risks within 4 days, in the Critical text box for that category, type 4.
      View Severity on Card

      Do any of the following:

      • Select the check box below any risk range that you want to include in the exposure card.

      • Deselect the check box below any risk range that you do not want to include in the exposure card.

      Graph Range

      For each risk range, type the date range to use for the graph in the SLA section within Tenable Exposure Management.

  5. Click Save .

    Tenable Exposure Management saves your changes to the exposure card.

Share a Custom Exposure Card

Required User Role: Scan Operator, Standard, Scan Manager, Administrator, or Custom Role

Note: You can only share custom exposure cards.

To share a custom exposure card:

  1. In the exposure card library. click the Custom tab.

    A list of user-created custom cards appears.

  2. Click the custom card you want to share.

    The card information appears.

  3. At the top of the page, click Share .

    The Share Exposure Card window appears.

  4. In the search box, type the email address of the user or users with which you want to share the exposure card data.

    Tip: Below the search box, you can view which users have access to the data.

  5. In the drop-down menu, select the access you want to grant to the user with which you are sharing the exposure card data. For example, if you want to allow the user to comment on the data, select can comment.

  6. Click Share.

    Tenable Exposure Management shares the exposure card data with the selected users. Selected users receive notification emails.

Delete a Custom Exposure Card

Required User Role: Administrator or Custom Role

Note: You can only delete custom exposure cards.

To delete a custom exposure card:

  1. In the exposure card library. click the Custom tab.

    A list of user-created custom cards appears.

  2. Click the custom card you want to delete.

    The card information appears.

  3. At the top of the page, click the button.

    A menu appears.

  4. Click Edit.

    The edit card page appears.

  5. At the bottom of the page, click Delete.

    A confirmation message appears.

  6. Click Delete card.

    Tenable Exposure Management deletes the custom exposure card.