Skip to main content

Tenable Vulnerability Management (Tenable.io)

Integrate Tenable Vulnerability Management with Cloudaware to inventory vulnerability data for unified risk reporting and remediation workflows.

info
  • Audience: Cloudaware administrators, SecOps teams, vulnerability management teams, and cloud operations teams
  • Outcome: Tenable.io vulnerability data is available in Cloudaware for risk visibility, asset correlation, remediation prioritization, and reporting

Capabilities

The integration supports:

  • Read-only discovery of Tenable.io vulnerability data through the Tenable Vulnerability Management API
  • Vulnerability context in Cloudaware for affected cloud assets, physical servers, and container images
  • Risk reporting and remediation prioritization using Cloudaware CMDB context
  • Search and reporting for Tenable vulnerability data using CMDB Navigator, CMDB list views, and reports

Prerequisites

Before you begin, make sure you have:

  • Access to a Cloudaware account.
  • A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
  • Tenable.io API Access Key.
  • Tenable.io API Secret Key.

Add a Tenable Vulnerability Management Account to Cloudaware

  1. In Cloudaware, go to Admin.
  2. Find Tenable Vulnerability Management, then click + ADD.
  3. Enter the following values:
    • Name: A display name for the Tenable Vulnerability Management integration.
    • Access Key: The Tenable.io API Access Key.
    • Secret Key: The Tenable.io API Secret Key.
  4. Click Save.
  5. Confirm that the integration status indicator is green.
tip

Allow the initial discovery cycle to complete after enabling the integration.

Supported Objects

Cloudaware ingests Tenable.io vulnerability data into Cloudaware Vulnerability Scan records.

Vulnerability Record TypeDescription
Tenable Asset VulnerabilityVulnerabilities found on assets scanned by Tenable.io or Tenable.sc
Tenable Image VulnerabilityContainer image vulnerabilities discovered by Tenable

Troubleshooting

note

Initial data collection may take time to complete.

Authentication Fails or Integration Shows Red Status

  • Verify that the Access Key and Secret Key are correct.
  • Confirm that the Tenable.io API keys are active.
  • Check whether the API keys have read access to the vulnerability data expected in Cloudaware.

No Tenable.io Data Appears in Cloudaware

  • Allow the initial discovery cycle to complete.
  • Confirm that Tenable.io contains vulnerability scan data for the expected assets.
  • In CMDB Navigator, verify that you are viewing the related vulnerability records.

Some Vulnerabilities Are Missing

  • Confirm that the missing vulnerabilities are visible in Tenable.io.
  • Verify that the API keys have access to the asset, scan, tag, or organization scope that contains the missing data.
  • Review recent Tenable.io scan updates after the next Cloudaware discovery cycle completes.

Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.

Reconfigure or Remove the Integration

warning

To rotate Tenable.io API keys, edit the existing integration instead of deleting and re-creating it.

Update the Integration Details

  1. Go to Admin.
  2. Select Tenable Vulnerability Management.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Edit.
  5. Update the required fields.
  6. Click Save.

Remove the Integration from Cloudaware

  1. Go to Admin.
  2. Select Tenable Vulnerability Management.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Delete.
  5. Confirm the deletion if prompted.

Security Notes

  • Use dedicated Tenable.io API keys for Cloudaware discovery.
  • Grant the API keys only the read access required for vulnerability data discovery.
  • Do not reuse personal administrator keys for production integrations.
  • Rotate Tenable.io API keys according to your organization's credential management policy.
  • Review Tenable.io data visibility with your vulnerability management team, because vulnerability records may include asset identifiers, image names, plugin output, and remediation context.
  • Revoke unused Tenable.io API keys when the integration is retired.