---
title: "Vulnerability Management in Nessus"
canonical: "https://kb.uconn.edu/space/IKB/10866032900/Vulnerability%20Management%20in%20Nessus"
format: markdown
---
Staff can view risks and vulnerabilities in Nessus, remediate them, request a risk exception.

## Drilling Down into Vulnerabilities & Risks

1. To get details on a specific vulnerability or risk, each module on the **Dashboard** allows you to drill down into specifics. Most modules can be expanded by clicking on the **light blue arrow** in each pane.
  1. If the module does not have the light blue arrow on the right-hand side, you can click on the machines/IPs/vulnerabilities in the module, itself.
2. The **Vulnerability Analysis** page will change depending on what Tool is selected. For this example, we will be looking at the **Remediation Summary** **Tool**. This page shows you **Solutions** that will reduce the risk by a percentage throughout the organization.  
:check_mark: Tip: For more information on the Vulnerability Analysis page and what each Tool does, see [Tenable's Documentation](https://docs.tenable.com/tenablesc/Content/VulnerabilityAnalysisTools.htm).
3. Clicking any of the Solutions above will drill down into that particular Solution by bringing up the **Vulnerability Summary Tool.** This Tool displays a table of all plugins associated with vulnerabilities on your network, organized by plugin ID. > Macro (inline-media-image)
4. Clicking any of the Vulnerabilities shown above will show you the **Vulnerability List Tool. **This Tool displays all of the machines on the network that are currently affected by the selected vulnerability.  
> Macro (inline-media-image)
5. From there, you can select the machine that you would like to view the vulnerability on. Doing so will bring you to the **Vulnerability Detail List Tool.** This tool is useful for identifying where the vulnerability resides on the machine, when it was first and last detected, and what steps need to be taken to resolve the vulnerability.  
> Macro (inline-media-image)

> ℹ️ <span style="color: #ff0000">**The Red Box**</span> shows when the vulnerability was first discovered, as well as last observed.
> ℹ️ 
> ℹ️ <span style="color: #339966">**The Green Box**</span> shows what needs to be applied to fix the vulnerability.
> ℹ️ 
> ℹ️ <span style="color: #0000ff">**The Blue Box**</span>** **shows the exact location the vulnerability was found. It will also display any changes that may need to be made to the system for the patch to be applied correctly (e.g., a registry change is required, or a reboot is needed).
> ℹ️ 
> ℹ️ <span style="color: #ff6600">**The Orange Box**</span> shows if the vulnerability is exploitable, and how easily it can be exploited.

## Remediating a Vulnerability

1. Once you have taken the appropriate steps to fix a vulnerability, you can perform a **Remediation Scan** that will check to see if the fix has been applied. In the **Vulnerability Detail List Tool**, click on **Launch Remediation Scan **in the right-hand side of the menu.  
> Macro (inline-media-image)
2. From there, you will be brought to the **Launch Remediation Scan** wizard.
  1. Under **General**, you can pick a name for your scan and enter a description for it.  
> Macro (inline-media-image)
  2. Under **Settings**, make sure that the **Scan Zone** is set to **ISO Nessus Scanner.** This tells Nessus to use the scanners we have placed throughout the network to scan the machine. The rest of the settings can be left as-is.  
> Macro (inline-media-image)
  3. Under **Targets**, typically there is nothing to change. However, if you had multiple servers with the same vulnerability and you have fixed them all, it is possible to scan all the targets for that one particular vulnerability by entering all the IPs of the servers here.> Macro (inline-media-image)
  4. In the **Credentials **section, you can manage which credentials should be used to scan your machines.
    1. For Windows Machines, please select **Windows**, and then choose **SSG-Windows**.
    2. For Unix Machines, please select **SSH,** and then choose **SSG-Unix Credentials.**
    3. For Linux Machines, please select **SSH,** and then choose **SSG-Linux Credentials.**  
> Macro (inline-media-image)
  5. In the **Post Scan** section, you can opt to have Nessus email you when the Remediation Scan launches or completes. If you have configured a custom report template, you can choose to have the scan results sent to that report template.  
> Macro (inline-media-image)
  6. When you have completed all of the sections, click **Submit** to begin the scan. You will be returned to the previous screen with the following pop-up in the bottom, right-hand corner.  
> Macro (inline-media-image)
3. By clicking **View Scan Results, **you will be brought to the **Scan Results** page, which shows the results of all previous scans, as well as scans that are currently ongoing, including the remediation scan you ran.   
> Macro (inline-media-image)
4. When the scan is complete, you can click on it to view the results. If you have successfully mitigated the vulnerability, the results will be blank. If the vulnerability still exists, it will appear here again.   
> Macro (inline-media-image)

## Requesting a Risk Exception

### If You Need to Mitigate the Risk Another Way

1. If your Nessus scans are showing a vulnerability that you think should be removed from the report because you have other controls to protect the machine, email [security@uconn.edu](mailto:security@uconn.edu) with the subject line including "Nessus Risk Mitigation."
  1. In the email, include all relevant information regarding the vulnerability, including the plugin ID (if possible) and your current proposal for risk mitigation.
2. The ISO team will reach out to you to confirm what you are seeing and review your risk mitigation strategy for the vulnerability. We will work with you on the mitigation strategy, including any other compensating controls that may be necessary to minimize the risk.
3. After a risk mitigation plan is created, the plan will be presented to the Risk Council for approval.
  1. If the plan is not approved, the ISO will bring back their recommendations to retool the plan with you.
4. If the plan is approved, the ISO will wait for you to implement the mitigation plan. Once the mitigation plan is in place, an Accept Risk Rule will be created for the particular risk for the time of one year by default. When the rule expires, the risk will have to be re-assessed to see if it can be resolved.

### If the Risk is a False Positive

1. If your Nessus scans are showing a vulnerability that you have fixed, email [security@uconn.edu](mailto:security@uconn.edu) with the subject line including "Nessus False Positive."
  1. In the email, include all relevant information and provide documentation that shows how it is a false positive, including the plugin ID (if possible).
2. The ISO team will review and confirm the false positive reading in Nessus.
3. The ISO team will present the false positive to the Risk Council for approval.
  1. If the proof is not adequate for the Risk Council, the ISO team will relay to you what is adequate proof.
4. If approved, the ISO team will create an Accept Risk Rule for that false positive for the time of one year by default. When the rule expires, the risk will have to be re-assessed to see if it can be resolved.

## Related Articles

> Macro (contentbylabel)

> Macro (details)
> 
> | Related issues |  |
> | --- | --- |