Tags in Tenable Exposure Management
Overview
Tenable Exposure Management (within Tenable One) presents three distinct tag types, each with different origins, capabilities, and edit permissions. Understanding which type a tag belongs to determines what you can do with it and where you can use it.
| Tag Type | Origin | Editable in Tenable Exposure Management? |
|---|---|---|
| Tenable One Tags | Created natively in Tenable Exposure Management or Tenable One | Yes — full create/edit/delete |
| Tenable One Vulnerability Management Tags | Synchronized from Tenable One Vulnerability Management (cloud) | No — read-only; edit in Tenable One Vulnerability Management |
| External Tags | Imported from Tenable One Cloud Exposure, Tenable One Identity Exposure, or third-party integrations | No — read-only; asset-level only |
Tag Type Capabilities
The three tag types differ in which Tenable Exposure Management features they can drive.
| Capability | Tenable One Tags | Tenable One Vulnerability Management Tags | External Tags |
|---|---|---|---|
| Filter Inventory (asset search) | Yes | Yes | Yes |
| Exposure View Cards (scope) | Yes | Yes | No |
| Dashboard Filters | Yes | No | No |
| Dynamic Tag Rule Input (filter assets by tag) | Yes | Yes | Yes |
| Role-based access control | Yes | Yes | No |
| Cyber Exposure Score per tag | Yes | Yes | No |
Tenable One Tags
Tenable One Tags are created and managed directly in Tenable Exposure Management. They follow the same Category:Value pair structure as Tenable One Vulnerability Management Tags. Because they are native to the Tenable One platform, they carry the broadest set of capabilities: Exposure View Card scoping, Dashboard filtering, role-based access control, and a per-tag Cyber Exposure Score.
When you create a tag in Tenable Exposure Management, it is stored as a Tenable One Tag. If you want a tag to appear in Tenable One Vulnerability Management as well, create it in Tenable One Vulnerability Management — it will sync into Tenable Exposure Management as a Tenable One Vulnerability Management Tag (read-only in Tenable Exposure Management).
Tenable One Vulnerability Management Tags
Tags created in Tenable One Vulnerability Management sync into Tenable Exposure Management and appear alongside Tenable One Tags. In Tenable Exposure Management they are read-only — to change the tag definition, tag rules, or values, navigate to Settings → Tagging in Tenable One Vulnerability Management.
Tenable One Vulnerability Management Tags support all capabilities except Dashboard Filters. They carry a Cyber Exposure Score value, can scope Exposure View Cards, and can define access group membership for role-based access control.
External Tags
External Tags originate from Tenable One Cloud Exposure, Tenable One Identity Exposure, or third-party data integrations. They are applied at the individual asset level and are read-only in Tenable Exposure Management. Their primary use is as search and filter inputs in the Inventory — they cannot scope Exposure View Cards, Dashboards, or role-based access control.
Structure and Limits
- Maximum 100 tag categories per Tenable One instance
- Maximum 100,000 tag values per category
- Maximum 1,000 tag rules per tag value
- Maximum request body size: 1 MB
- Tag categories cannot be renamed after a tag value has been saved under them. Plan category names carefully before creating your first value in a category.
Static vs. Dynamic Tags in Tenable Exposure Management
| Attribute | Static Tag | Dynamic Tag |
|---|---|---|
| Assignment method | Manual | Rule-based, automatic |
| Re-evaluation | Never (persists until manually removed) | Triggered on data import; background sweep every 12 hours |
| Manual override | Not applicable | Manually applied tag exempts asset from rule evaluation |
| Dashboard data lag | Up to 24 hours | Up to 24 hours |
The Tags Page
Navigate to Inventory → Tags to access the Tags management page. Each row in the tag list displays:
- Tag Name — the Category:Value pair
- Cyber Exposure Score — the score for assets in that tag (0–1000)
- Related Assets — the count of assets carrying the tag
- Weakness Count — total weaknesses across tagged assets
- Last Updated — when the tag data was last recalculated
Create a Tag
Create a tag in Tenable Exposure Management when you want a tag that is native to Tenable One and fully editable there, rather than one synchronized read-only from Tenable One Vulnerability Management.
Before You Begin
-
Choose the Category name carefully — category names cannot be changed after a value is saved under them.
-
Decide whether the tag should be Static (manually applied) or Dynamic (rule-based).
From the Tags Page
To create a tag from the Tags page:
-
In the left navigation bar, go to Inventory → Tags.
The Tags page appears.
-
Click Create Tag.
The Create Tag pane appears.
-
Enter a Category name (new or existing). If selecting an existing category, note that the name cannot be changed after a value is saved.
-
Enter a Value name.
-
Optionally add a description.
-
Choose Static (manual) or Dynamic (rule-based). For dynamic tags, configure one or more rules.
-
Click Save.
The new tag appears on the Tags page.
From the Assets Page
To create a tag from the Assets page:
-
In the left navigation bar, go to Inventory → Assets.
The Assets page appears.
-
Select one or more assets.
-
Click the
Actions menu, then click Tag Assets.
The Tag Assets dialog appears.
-
Select an existing tag or create a new one inline.
-
Click Apply.
Tenable Exposure Management applies the tag to the selected assets.
What To Do Next
Use the tag to scope an Exposure View Card or Dashboard (see the following sections), or configure a tag-scoped role for role-based access control.
Editing and Deleting Tags
To edit a Tenable One Tag, open the tag from Inventory → Tags and click the Edit button. You can modify the value name, description, and rules. You cannot change the category name if values already exist under it.
To delete a tag value, click the overflow menu on the tag row and select Delete. Deleting a value removes it from all assets immediately. Deleting all values in a category removes the category.
Tenable One Vulnerability Management Tags and External Tags display no Edit or Delete controls in Tenable Exposure Management — those operations must be performed in their respective source products.
Using Tags in Exposure View Cards
Exposure View Cards can be scoped to a specific tag, allowing each card to report Cyber Exposure Score, Asset Exposure Score, and vulnerability counts for a defined segment of your environment. Tenable One Tags and Tenable One Vulnerability Management Tags both support card scoping; External Tags do not.
To scope a card to a tag, open the card configuration and set the Tag field to the desired Category:Value pair.
Using Tags in Dashboards
Dashboard-level tag filtering is available for Tenable One Tags only. When a dashboard is filtered by a Tenable One Tag, all widgets on the dashboard reflect data scoped to that tag's asset population.
Allow up to 24 hours for Dashboard data to reflect tag membership changes after a tag rule runs or assets are manually tagged.
Using Tags for Role-Based Access Control
Tenable One Tags and Tenable One Vulnerability Management Tags can define the scope of a user role's permissions in Tenable One. When a role is scoped to a tag, users assigned that role see only assets, findings, and metrics associated with that tag's asset population.
Configure tag-scoped roles under Settings → Access Control → Roles.
Additional Resources
For complete tagging documentation, see Tags in the Tenable Exposure Management User Guide.