Tags in Tenable Exposure Management

Overview

Tenable Exposure Management (within Tenable One) presents three distinct tag types, each with different origins, capabilities, and edit permissions. Understanding which type a tag belongs to determines what you can do with it and where you can use it.

Tag Type Origin Editable in Tenable Exposure Management?
Tenable One Tags Created natively in Tenable Exposure Management or Tenable One Yes — full create/edit/delete
Tenable One Vulnerability Management Tags Synchronized from Tenable One Vulnerability Management (cloud) No — read-only; edit in Tenable One Vulnerability Management
External Tags Imported from Tenable One Cloud Exposure, Tenable One Identity Exposure, or third-party integrations No — read-only; asset-level only

Tag Type Capabilities

The three tag types differ in which Tenable Exposure Management features they can drive.

Capability Tenable One Tags Tenable One Vulnerability Management Tags External Tags
Filter Inventory (asset search) Yes Yes Yes
Exposure View Cards (scope) Yes Yes No
Dashboard Filters Yes No No
Dynamic Tag Rule Input (filter assets by tag) Yes Yes Yes
Role-based access control Yes Yes No
Cyber Exposure Score per tag Yes Yes No

Tenable One Tags

Tenable One Tags are created and managed directly in Tenable Exposure Management. They follow the same Category:Value pair structure as Tenable One Vulnerability Management Tags. Because they are native to the Tenable One platform, they carry the broadest set of capabilities: Exposure View Card scoping, Dashboard filtering, role-based access control, and a per-tag Cyber Exposure Score.

When you create a tag in Tenable Exposure Management, it is stored as a Tenable One Tag. If you want a tag to appear in Tenable One Vulnerability Management as well, create it in Tenable One Vulnerability Management — it will sync into Tenable Exposure Management as a Tenable One Vulnerability Management Tag (read-only in Tenable Exposure Management).

Tenable One Vulnerability Management Tags

Tags created in Tenable One Vulnerability Management sync into Tenable Exposure Management and appear alongside Tenable One Tags. In Tenable Exposure Management they are read-only — to change the tag definition, tag rules, or values, navigate to Settings → Tagging in Tenable One Vulnerability Management.

Tenable One Vulnerability Management Tags support all capabilities except Dashboard Filters. They carry a Cyber Exposure Score value, can scope Exposure View Cards, and can define access group membership for role-based access control.

External Tags

External Tags originate from Tenable One Cloud Exposure, Tenable One Identity Exposure, or third-party data integrations. They are applied at the individual asset level and are read-only in Tenable Exposure Management. Their primary use is as search and filter inputs in the Inventory — they cannot scope Exposure View Cards, Dashboards, or role-based access control.

Structure and Limits

  • Maximum 100 tag categories per Tenable One instance
  • Maximum 100,000 tag values per category
  • Maximum 1,000 tag rules per tag value
  • Maximum request body size: 1 MB
  • Tag categories cannot be renamed after a tag value has been saved under them. Plan category names carefully before creating your first value in a category.
Caution: Unlike Tenable One Vulnerability Management, the category name in Tenable Exposure Management is locked once any value is saved to that category. If you need to rename a category, you must delete all values under it first, then recreate the category with the new name.

Static vs. Dynamic Tags in Tenable Exposure Management

Attribute Static Tag Dynamic Tag
Assignment method Manual Rule-based, automatic
Re-evaluation Never (persists until manually removed) Triggered on data import; background sweep every 12 hours
Manual override Not applicable Manually applied tag exempts asset from rule evaluation
Dashboard data lag Up to 24 hours Up to 24 hours

The Tags Page

Navigate to Inventory → Tags to access the Tags management page. Each row in the tag list displays:

  • Tag Name — the Category:Value pair
  • Cyber Exposure Score — the score for assets in that tag (0–1000)
  • Related Assets — the count of assets carrying the tag
  • Weakness Count — total weaknesses across tagged assets
  • Last Updated — when the tag data was last recalculated

Create a Tag

Create a tag in Tenable Exposure Management when you want a tag that is native to Tenable One and fully editable there, rather than one synchronized read-only from Tenable One Vulnerability Management.

Before You Begin

  • Choose the Category name carefully — category names cannot be changed after a value is saved under them.

  • Decide whether the tag should be Static (manually applied) or Dynamic (rule-based).

From the Tags Page

To create a tag from the Tags page:

  1. In the left navigation bar, go to Inventory → Tags.

    The Tags page appears.

  2. Click Create Tag.

    The Create Tag pane appears.

  3. Enter a Category name (new or existing). If selecting an existing category, note that the name cannot be changed after a value is saved.

  4. Enter a Value name.

  5. Optionally add a description.

  6. Choose Static (manual) or Dynamic (rule-based). For dynamic tags, configure one or more rules.

  7. Click Save.

    The new tag appears on the Tags page.

From the Assets Page

To create a tag from the Assets page:

  1. In the left navigation bar, go to Inventory → Assets.

    The Assets page appears.

  2. Select one or more assets.

  3. Click the Actions menu, then click Tag Assets.

    The Tag Assets dialog appears.

  4. Select an existing tag or create a new one inline.

  5. Click Apply.

    Tenable Exposure Management applies the tag to the selected assets.

What To Do Next

Use the tag to scope an Exposure View Card or Dashboard (see the following sections), or configure a tag-scoped role for role-based access control.

Editing and Deleting Tags

To edit a Tenable One Tag, open the tag from Inventory → Tags and click the Edit button. You can modify the value name, description, and rules. You cannot change the category name if values already exist under it.

To delete a tag value, click the overflow menu on the tag row and select Delete. Deleting a value removes it from all assets immediately. Deleting all values in a category removes the category.

Tenable One Vulnerability Management Tags and External Tags display no Edit or Delete controls in Tenable Exposure Management — those operations must be performed in their respective source products.

Using Tags in Exposure View Cards

Exposure View Cards can be scoped to a specific tag, allowing each card to report Cyber Exposure Score, Asset Exposure Score, and vulnerability counts for a defined segment of your environment. Tenable One Tags and Tenable One Vulnerability Management Tags both support card scoping; External Tags do not.

To scope a card to a tag, open the card configuration and set the Tag field to the desired Category:Value pair.

Using Tags in Dashboards

Dashboard-level tag filtering is available for Tenable One Tags only. When a dashboard is filtered by a Tenable One Tag, all widgets on the dashboard reflect data scoped to that tag's asset population.

Allow up to 24 hours for Dashboard data to reflect tag membership changes after a tag rule runs or assets are manually tagged.

Using Tags for Role-Based Access Control

Tenable One Tags and Tenable One Vulnerability Management Tags can define the scope of a user role's permissions in Tenable One. When a role is scoped to a tag, users assigned that role see only assets, findings, and metrics associated with that tag's asset population.

Configure tag-scoped roles under Settings → Access Control → Roles.

Note — Permission Scope Clarification: Tag-scoped role permissions control which assets, findings, and metrics a user can view in Tenable One and Tenable Exposure Management. They do not restrict what a user can manually type into a scan target field in Tenable One Vulnerability Management. A user whose visibility is scoped to a specific tag can still launch a scan against a manually entered IP address or hostname outside that tag's scope. To prevent out-of-scope scanning, pair tag-scoped roles with scan-level target restrictions rather than relying on tag permissions alone. For more information, see Tag-Based Scanning.

Additional Resources

For complete tagging documentation, see Tags in the Tenable Exposure Management User Guide.