Skip to main content

Tenable Security Center (Tenable.sc)

Integrate Tenable Security Center with Cloudaware to inventory vulnerability data for unified risk reporting and remediation workflows.

info
  • Audience: Cloudaware administrators, SecOps teams, vulnerability management teams, and infrastructure teams
  • Outcome: Tenable.sc vulnerability data is available in Cloudaware for risk visibility, asset correlation, remediation prioritization, and reporting

Capabilities

The integration supports:

  • Read-only discovery of Tenable.sc vulnerability data through the Tenable.sc API
  • Vulnerability context in Cloudaware for affected assets such as network devices, physical servers, and cloud resources
  • Risk reporting and remediation prioritization using Cloudaware CMDB context
  • Search and reporting for Tenable.sc vulnerability data using CMDB Navigator, CMDB list views, and reports

Prerequisites

Before you begin, make sure you have:

  • Access to a Cloudaware account.
  • A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
  • Tenable.sc server URL.
  • Tenable.sc API Access Key.
  • Tenable.sc API Secret Key.

Add a Tenable Security Center Account to Cloudaware

  1. In Cloudaware, go to Admin.
  2. Find Tenable Security Center, then click + ADD.
  3. Enter the following values:
    • Access Key: The Tenable.sc API Access Key.
    • Secret Key: The Tenable.sc API Secret Key.
    • Server URL: The Tenable.sc server URL.
  4. Click Save.
  5. Confirm that the integration status indicator is green.
tip

Allow the initial discovery cycle to complete after enabling the integration.

View Tenable Security Center Data in CMDB

  1. In Cloudaware, open CMDB Navigator.
  2. In the left pane, select Tenable Security Center.
  3. Open the related vulnerability records to review Tenable.sc findings.

Supported Objects

Cloudaware ingests Tenable.sc vulnerability data into Cloudaware Vulnerability Scan records.

| Vulnerability Record Type Description | | --------------------------------- | -------------------------------------------------------------- | | Customer Tenable SC Vulnerability | Vulnerabilities imported from a customer-managed Tenable.sc deployment | | Tenable SC Vulnerability | Vulnerabilities imported from Tenable Security Center |

Troubleshooting

note

Initial data collection may take time to complete.

Authentication Fails or Integration Shows Red Status

  • Verify that the Access Key, Secret Key, and Server URL are correct.
  • Confirm that the Tenable.sc API keys are active.
  • Check whether the Tenable.sc account has read access to the vulnerability data expected in Cloudaware.

No Tenable.sc Data Appears in Cloudaware

  • Allow the initial discovery cycle to complete.
  • Confirm that Tenable.sc contains vulnerability scan data for the expected assets.
  • In CMDB Navigator, verify that you are viewing the related vulnerability records.

Some Vulnerabilities Are Missing

  • Confirm that the missing vulnerabilities are visible in Tenable.sc.
  • Verify that the API keys have access to the repository, scan, asset, or organization scope that contains the missing data.
  • Review recent Tenable.sc scan updates after the next Cloudaware discovery cycle completes.

Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name, Tenable.sc server URL, and a brief description of the issue.

Reconfigure or Remove the Integration

warning

To rotate Tenable.sc API keys, edit the existing integration instead of deleting and re-creating it.

Update the Integration Details

  1. Go to Admin.
  2. Select Tenable Security Center.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Edit.
  5. Update the required fields.
  6. Click Save.

Remove the Integration from Cloudaware

  1. Go to Admin.
  2. Select Tenable Security Center.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Delete.
  5. Confirm the deletion if prompted.

Security Notes

  • Use dedicated Tenable.sc API keys for Cloudaware discovery.
  • Grant the API keys only the read access required for vulnerability data discovery.
  • Do not reuse personal administrator keys for production integrations.
  • Rotate Tenable.sc API keys according to your organization's credential management policy.
  • Review Tenable.sc data visibility with your vulnerability management team, because vulnerability records may include asset identifiers, network details, plugin output, and remediation context.
  • Revoke unused Tenable.sc API keys when the integration is retired.