Tenable Security Center (Tenable.sc)
Integrate Tenable Security Center with Cloudaware to inventory vulnerability data for unified risk reporting and remediation workflows.
- Audience: Cloudaware administrators, SecOps teams, vulnerability management teams, and infrastructure teams
- Outcome: Tenable.sc vulnerability data is available in Cloudaware for risk visibility, asset correlation, remediation prioritization, and reporting
Capabilities
The integration supports:
- Read-only discovery of Tenable.sc vulnerability data through the Tenable.sc API
- Vulnerability context in Cloudaware for affected assets such as network devices, physical servers, and cloud resources
- Risk reporting and remediation prioritization using Cloudaware CMDB context
- Search and reporting for Tenable.sc vulnerability data using CMDB Navigator, CMDB list views, and reports
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
- Tenable.sc server URL.
- Tenable.sc API Access Key.
- Tenable.sc API Secret Key.
Add a Tenable Security Center Account to Cloudaware
- In Cloudaware, go to Admin.
- Find Tenable Security Center, then click + ADD.
- Enter the following values:
- Access Key: The Tenable.sc API Access Key.
- Secret Key: The Tenable.sc API Secret Key.
- Server URL: The Tenable.sc server URL.
- Click Save.
- Confirm that the integration status indicator is green.
Allow the initial discovery cycle to complete after enabling the integration.
View Tenable Security Center Data in CMDB
- In Cloudaware, open CMDB Navigator.
- In the left pane, select Tenable Security Center.
- Open the related vulnerability records to review Tenable.sc findings.
Supported Objects
Cloudaware ingests Tenable.sc vulnerability data into Cloudaware Vulnerability Scan records.
| Vulnerability Record Type Description | | --------------------------------- | -------------------------------------------------------------- | | Customer Tenable SC Vulnerability | Vulnerabilities imported from a customer-managed Tenable.sc deployment | | Tenable SC Vulnerability | Vulnerabilities imported from Tenable Security Center |
Troubleshooting
Initial data collection may take time to complete.
Authentication Fails or Integration Shows Red Status
- Verify that the Access Key, Secret Key, and Server URL are correct.
- Confirm that the Tenable.sc API keys are active.
- Check whether the Tenable.sc account has read access to the vulnerability data expected in Cloudaware.
No Tenable.sc Data Appears in Cloudaware
- Allow the initial discovery cycle to complete.
- Confirm that Tenable.sc contains vulnerability scan data for the expected assets.
- In CMDB Navigator, verify that you are viewing the related vulnerability records.
Some Vulnerabilities Are Missing
- Confirm that the missing vulnerabilities are visible in Tenable.sc.
- Verify that the API keys have access to the repository, scan, asset, or organization scope that contains the missing data.
- Review recent Tenable.sc scan updates after the next Cloudaware discovery cycle completes.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name, Tenable.sc server URL, and a brief description of the issue.
Reconfigure or Remove the Integration
To rotate Tenable.sc API keys, edit the existing integration instead of deleting and re-creating it.
Update the Integration Details
- Go to Admin.
- Select Tenable Security Center.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select Tenable Security Center.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Use dedicated Tenable.sc API keys for Cloudaware discovery.
- Grant the API keys only the read access required for vulnerability data discovery.
- Do not reuse personal administrator keys for production integrations.
- Rotate Tenable.sc API keys according to your organization's credential management policy.
- Review Tenable.sc data visibility with your vulnerability management team, because vulnerability records may include asset identifiers, network details, plugin output, and remediation context.
- Revoke unused Tenable.sc API keys when the integration is retired.