Core Concepts
What Is a Tag?
A tag is a piece of metadata you attach to one or more assets to add business context. Tags are structured as Category:Value pairs. The category groups related values under a common theme, and the value identifies the specific attribute within that category.
For example, if you want to group assets by geographic location, you create a Location category with a value of Headquarters. The resulting tag is Location:Headquarters.
A single asset can hold many tags simultaneously, and a single tag can be applied to many assets. This many-to-many relationship makes tags flexible enough to express complex organizational structures without duplicating assets or creating separate scan policies.
Tag Types
Tenable supports two modes of applying tags:
| Type | How Applied | Stays Current? | Use Case |
|---|---|---|---|
| Manual (Static) | An administrator explicitly adds the tag to selected assets | No — must be maintained manually | Priority flags, exceptions, compliance attestations |
| Automatic (Dynamic) | Tag Rules define criteria; Tenable One Vulnerability Management evaluates assets continuously | Yes — re-evaluated every 12 hours and on every data import | OS grouping, cloud region, installed software, owner segmentation |
Automatic tag rules are available for tags in Tenable One Vulnerability Management, for Tenable One Tags in Tenable Exposure Management, and for Dynamic and Combination Asset Tags in Tenable Security Center. Tenable One Attack Surface Management tags support manual assignment only and currently offer no rule-based automatic tagging.
Manual tags appear with a static tag icon () in the user interface. Automatic tags appear with a dynamic tag icon (
). When you manually apply an automatic tag to an asset, it displays the manual icon rather than the dynamic one.
When Tag Membership Is Re-evaluated
For automatic tags, Tenable One Vulnerability Management re-evaluates asset membership against tag rules in the following situations:
- When you create or update a tag
- Tenable One Vulnerability Management imports new scan or connector data
- Every 12 hours (background sweep)
Tenable One Tags in Tenable Exposure Management follow the same re-evaluation cadence: on data import and on a 12-hour background sweep. Tenable Security Center Dynamic Asset Tags refresh using results from Tenable Security Center scans rather than on a fixed interval, and Combination Asset Tags update immediately when a source Asset Tag changes. Tenable One Attack Surface Management tags are always manual, so Tenable One Attack Surface Management has no re-evaluation cycle to consider.
Product Terminology at a Glance
The naming and capabilities of the tagging feature differ across Tenable products, as the following table shows.
| Product | Feature Name | Applies To | Supports Rules? | Flows to Tenable One? |
|---|---|---|---|---|
| Tenable One Vulnerability Management (cloud) | Tags (Category:Value) | Assets | Yes — dynamic/automatic tags | Yes — as Business Context |
| Tenable Exposure Management | Tags (Tenable One, Tenable One Vulnerability Management, and External) | Assets, Exposure View Cards, Dashboards (varies by tag type) | Inherited from Tenable One Vulnerability Management tags | Not applicable — native |
| Tenable Security Center (on-premises) | Asset Tags | Assets | Yes — Dynamic and Combination Asset Tags | Partially — via optional Tenable One Synchronization (IPv4 Static/Dynamic Asset Tags only, requires a Tenable Lumin or Tenable One license) |
| Tenable One Attack Surface Management | Tags (name + value type) | External attack surface assets (domains, IP addresses, web applications, cloud services) | No — manual assignment only | No — isolated to the Tenable One Attack Surface Management inventory |