Routine tasks in the Unified Portal
|
Task |
Recommended frequency |
|---|---|
|
Weekly or monthly |
|
|
Weekly or monthly |
|
|
Monthly |
|
|
Monthly or quarterly |
|
|
Monthly or quarterly |
|
|
Monthly or quarterly |
|
|
Optional |
Review unresolved risks
It is good practice to review your unresolved risks on a weekly or monthly schedule. This helps you to maintain an accurate risk score, provides you with more visibility into your network activity, and helps you to proactively identify and address potential vulnerabilities.
Review the state of risks
On a weekly or monthly basis, review the State of each risk to make sure it is appropriate and to verify that risks are resolved as expected.
Review your scan exclusion list
To reduce risk to your organization, review your scan exclusions list each month to make sure it only includes exclusions that you need.
Review assets
On a monthly or quarterly basis, review your assets.
- Delete assets — Delete any assets that are no longer needed because they impact your metrics. When deleted, the Asset State changes to Inactive, and then the asset is removed after 120 days.
- Edit an asset category — When you add a new asset, assign a Category to it that accurately identifies the purpose of the asset.
- Edit asset criticality — When you add a new asset, assign an Asset Criticality value to it. This value is optional. It displays for any risks that are discovered on an asset and it can help you with risk mitigation planning.
- Apply a tag to an asset — When you add a new asset, apply tags to it. The tags allow you organize assets into different groups and they help you identify them.
For more information, see Remove a tag from an asset and Tag management.
- If you uninstall Agent from an asset that has more than one Source, manually set the State of any risks associated with that Agent to Accepted or Mitigated so the risks do not impact your risk score. You need to do this because when you uninstall Agent from an asset, one these actions occur:
- If the asset had only Agent as a Source , the Asset State automatically changes to Inactive , and the Status of all associated risks changes to Resolved.
- If the asset had more than one Source, for example, Agent, IVA, and DHCP, Agent is no longer listed as a Source on the Asset page, the Asset State and risk Status do not change, and the State of any risks associated with the Agent does not change so the State must be manually set.
Review scanner health
Monitor your progress
On an ongoing basis you should monitor the vulnerabilities in your environment to identify your risk remediation state and progress.
- Review your Risk Exposure Score — Your Risk Exposure Score indicates how at risk your network environment is. It is a weighted average of the scores of all unresolved risks in your network at a particular time. The Risk Exposure Score updates automatically when new risks are found, existing risks are mitigated or accepted, or when the Common Vulnerability Scoring System (CVSS) score for the existing risks change.
Evaluate your Risk Exposure Score on a monthly or quarterly basis, and note the risks that impact your risk score the most. Risks with a high score affect your Risk Exposure Score more than risks with a low score.
For more information, see View your risk score and View assets impacted by remediation.
- Review the Risk Remediation Trends widget — The graph allows you to view the results of your remediation efforts over a specific time range and compare it with incoming risks. Make sure Unresolved risks line is not flat because this could indicate that scans are not working as expected or that schedules are not configured, and make sure the Resolved risks line is not flat because this can indicate that no new risk remediation has occurred.
For more information, see View your risk metrics.
Integrate your data with your workflows
Arctic Wolf® provides you with the option of integrating your data with workflows that you currently have at your organization.
- Export remediation data from the Unified Portal so that you can process, share, or import it into other software at your organization.
For more information, see Export remediation data.
- If your IT service management (ITSM) solution is integrated with Arctic Wolf, create ITSM tickets for each risk in the Unified Portal.
For more information, see Create an ITSM ticket for the risks in your organization.