Computing Resources (Tenable One Vulnerability Management and Tenable Lumin)
The following scores can be found within Computing Resources data sources.
Vulnerability Priority Rating
The prioritization of vulnerabilities in Tenable One Vulnerability Management is derived from the Vulnerability Priority Rating (VPR) which takes a risk based approach to prioritization based on the characteristics of the vulnerability and threat intelligence.
Asset Criticality Rating
Required Additional License: Tenable One / Tenable Lumin
The Asset Criticality Rating (ACR) found in Tenable Lumin rates the criticality of an asset to the organization. An asset’s ACR is expressed as an integer from 1 to 10, with higher values corresponding to the asset being more critical to the business.
An asset's ACR can be generated by the Tenable model or defined by you. If you define a value, it is used in place of the model-generated value. ACR values are calculated every 24 hours, so it can take up to 24 hours for an ACR to appear after you scan an asset. Running unauthenticated scans may result in limited or incomplete ACR key drivers. For more information about how Tenable calculates ACR, including the key drivers and how multiple values are prioritized, see Tenable Lumin Metrics in the Tenable One Vulnerability Management User Guide.
Asset Exposure Score Computation
Required Additional License: Tenable One / Tenable Lumin
In Tenable Lumin, each asset is given an AES from 0 to 1000. Tenable Lumin computes the AES in two steps:
- Calculate the Vulnerability Density for the asset. Vulnerability Density is based on the number of vulnerabilities on the asset, their severity as reflected in their VPR scores, and whether they are remotely discoverable.
- Combine the Vulnerability Density with the asset's ACR, then scale the result to produce the AES.
The Cyber Exposure Score (CES) is the average AES across a group of assets. For more information, see Legacy Scoring.
Understanding an Asset's Score
If an asset's AES is not what you expect, check the following:
- ACR: Confirm the asset's current ACR, and whether it was modified manually. A manually overridden ACR takes priority over the Tenable-provided value. If you recently scanned the asset, allow up to 24 hours for the ACR to update.
- Open vulnerabilities: Review the vulnerabilities currently open on the asset and their VPR values.