Add Recast or Accept Rules in Findings

In Tenable Vulnerability Management, you can create rules for your vulnerability findings to customize how they present risk. While Recast rules change the severity of your findings, Accept rules accept their risk without modifying severity.

Tip: This topic describes how to create rules from the Findings workbench, but you can also create rules from the Tenable Vulnerability Management Settings. For more information, including examples on when to create rules, see Recast/Accept Rules.

Note: If a rule is targeted by IP address, that rule applies to the specified IP in each network in which it is found. For more information, see Networks.

Create a Recast Rule in Findings

To create a Recast rule from the Findings workbench:

  1. In the upper-left corner, click the Menu button.

    The left navigation plane appears.

  2. In the left navigation plane and the Explore section, click Findings.

    The Findings page appears with the Vulnerabilities tab active and your findings shown in a table view.

  3. (Optional) Click Web Application Findings.

    The Web Application Findings tab appears.

  4. In the row for the finding to create a rule for, click the button.

    A drop-down menu appears.

  5. Click Recast.

    The Add Rule plane appears.

  6. Click Save.

    Tenable Vulnerability Management starts applying the rule to existing findings. This process may take some time, depending on the system load and the number of matching findings. Tenable Vulnerability Management updates your dashboards, where a label appears to indicate how many instances of affected findings were recast.

    Note: A recast rule does not affect the historical results of a scan.

Create an Accept Rule in Findings

To create an Accept rule from the Findings workbench:

  1. In the upper-left corner, click the Menu button.

    The left navigation plane appears.

  2. In the left navigation plane and the Explore section, click Findings.

    The Findings page appears with the Vulnerabilities tab active and your findings shown in a table view.

  3. (Optional) Click Web Application Findings.

    The Web Application Findings tab appears.

  4. In the row for the finding to create a rule for, click the button.

    A drop-down menu appears.

  5. Click Recast.

    The Add Recast Rule plane appears.

  6. On the Add Recast Rule plane, in the Action section, click Accept.

  7. Click Save.

    Tenable Vulnerability Management starts applying the rule to existing findings. This process may take some time, depending on the system load and the number of matching findings.