Lumin Exposure View Metrics

The following metrics are used to assess data within Lumin Exposure View:

Data Timing

Data within Lumin Exposure View refreshes on the following cadence:

  • Asset Data — Asset information is updated every time the asset is seen as part of a scan.

  • Tag Application — When a tag is first created, it can take several hours to assign the tag to the appropriate asset, depending on the number of assets and the tag's rules.

  • Tag Reevaluation — Every 12 hours, Lumin Exposure View automatically reevaluates tags to ensure they apply to newly discovered assets, and are removed from any inactive assets.

  • Tenable Cloud Security data — Lumin Exposure View automatically refreshes Tenable Cloud Security data every 24 hours.

Cyber Exposure Score (CES)

Lumin Exposure View calculates a dynamic CES that represents exposure risk as an integer between 0 and 1000, based on the Asset Exposure Score (AES) values for assets. Higher CES values indicate higher risk.

Note: Lumin Exposure View does not include assets older than 90 days in your CES.

CES Category CES Range
High 650 to 1000
Medium 350 to 649
Low

0 to 349

Asset Exposure Score (AES)

Lumin Exposure View calculates a dynamic AES for each asset on your network to represent the asset's relative exposure as an integer between 0 and 1000. A higher AES indicates higher exposure.

Note: Lumin Exposure View does not calculate an AES for unlicensed assets.

AES Category AES Range
High 650 to 1000
Medium 350 to 649
Low

0 to 349

Asset Criticality Rating (ACR)

Tenable assigns an ACR to each asset on your network to represent the asset's relative criticality as an integer from 1 to 10. A higher ACR indicates higher criticality.

ACR Category ACR Range
Critical

9 to 10

High 7 to 8
Medium 4 to 6
Low

1 to 3

Because Tenable Vulnerability Management calculates ACR values every 24 hours, you may need to wait up to 24 hours to view the ACR after scanning the asset on your network.

Lumin Exposure View Exposure Management Classes

Lumin Exposure View products refer to data sources as Exposure Management classes. For more information, see Data Sources.

Additionally, Lumin Exposure View uses specific icons to represent these within the user interface.

Category Icon
Vulnerability Management

Web Applications

Identity Exposure

Operational Technologies

Cloud Security

Scoring Caveats within Tenable One

The weakness counts and severities within the Score Breakdown tab and other areas within the Tenable Inventory user interface may not match because each segment counts instances differently:

For Tenable Vulnerability Management assets:

  • Weakness counts: Are distinct CVE counts

  • Exposure score counts: Distinct (plugin ID, CVE ID) counts to allow for recasted plugins to affect exposure scores

For Tenable Web App Scanning assets:

  • Weakness counts: Number of distinct CVEs + distinct plugins where the plugin has no CVEs but has a VPR

  • Exposure score counts: Distinct plugin ID counts with VPR > 0. This is to account for plugin ID vulnerabilities with no CVE and to allow for recasted plugins to affect exposure scores

For Tenable Identity Exposure assets:

  • Weakness counts: Distinct IoEs observed directly on the asset

  • Exposure score counts: Includes IoEs observed directly on the asset plus those inherited from related assets to account for inherited IoEs in exposure scores

For Tenable Cloud Security assets:

  • Weakness counts: Cloud Security misconfigurations plus any CVEs found on the asset

  • Exposure score counts: Only Cloud Security misconfigurations are counted for exposure scores.