Core Concepts

What Is a Tag?

A tag is a piece of metadata you attach to one or more assets to add business context. Tags are structured as Category:Value pairs. The category groups related values under a common theme, and the value identifies the specific attribute within that category.

For example, if you want to group assets by geographic location, you create a Location category with a value of Headquarters. The resulting tag is Location:Headquarters.

A single asset can hold many tags simultaneously, and a single tag can be applied to many assets. This many-to-many relationship makes tags flexible enough to express complex organizational structures without duplicating assets or creating separate scan policies.

Note: If you want to create tags without meaningful category groupings, Tenable recommends using the generic category name Category, which you can apply to all your tags.

Tag Types

Tenable supports two modes of applying tags:

Type How Applied Stays Current? Use Case
Manual (Static) An administrator explicitly adds the tag to selected assets No — must be maintained manually Priority flags, exceptions, compliance attestations
Automatic (Dynamic) Tag Rules define criteria; Tenable One Vulnerability Management evaluates assets continuously Yes — re-evaluated every 12 hours and on every data import OS grouping, cloud region, installed software, owner segmentation

Automatic tag rules are available for tags in Tenable One Vulnerability Management, for Tenable One Tags in Tenable Exposure Management, and for Dynamic and Combination Asset Tags in Tenable Security Center. Tenable One Attack Surface Management tags support manual assignment only and currently offer no rule-based automatic tagging.

Manual tags appear with a static tag icon () in the user interface. Automatic tags appear with a dynamic tag icon (). When you manually apply an automatic tag to an asset, it displays the manual icon rather than the dynamic one.

Caution: When you manually apply an automatic tag to an asset, Tenable One Vulnerability Management excludes that asset from future rule evaluation for that tag. The asset keeps the tag until you explicitly remove it, even if it no longer satisfies the rule criteria.

When Tag Membership Is Re-evaluated

For automatic tags, Tenable One Vulnerability Management re-evaluates asset membership against tag rules in the following situations:

  • When you create or update a tag
  • Tenable One Vulnerability Management imports new scan or connector data
  • Every 12 hours (background sweep)

Tenable One Tags in Tenable Exposure Management follow the same re-evaluation cadence: on data import and on a 12-hour background sweep. Tenable Security Center Dynamic Asset Tags refresh using results from Tenable Security Center scans rather than on a fixed interval, and Combination Asset Tags update immediately when a source Asset Tag changes. Tenable One Attack Surface Management tags are always manual, so Tenable One Attack Surface Management has no re-evaluation cycle to consider.

Product Terminology at a Glance

The naming and capabilities of the tagging feature differ across Tenable products, as the following table shows.

Product Feature Name Applies To Supports Rules? Flows to Tenable One?
Tenable One Vulnerability Management (cloud) Tags (Category:Value) Assets Yes — dynamic/automatic tags Yes — as Business Context
Tenable Exposure Management Tags (Tenable One, Tenable One Vulnerability Management, and External) Assets, Exposure View Cards, Dashboards (varies by tag type) Inherited from Tenable One Vulnerability Management tags Not applicable — native
Tenable Security Center (on-premises) Asset Tags Assets Yes — Dynamic and Combination Asset Tags Partially — via optional Tenable One Synchronization (IPv4 Static/Dynamic Asset Tags only, requires a Tenable Lumin or Tenable One license)
Tenable One Attack Surface Management Tags (name + value type) External attack surface assets (domains, IP addresses, web applications, cloud services) No — manual assignment only No — isolated to the Tenable One Attack Surface Management inventory