Skip to main content

Vulnerability Management Overview

Cloudaware Vulnerability Management brings together vulnerability findings from Cloudaware Vulnerability Scanning (VSaaS), cloud‑native scanners, and third-party security tools, enriching them with CMDB ownership and criticality data. The result is a single, actionable view of risk across clouds, data centers, and container platforms. It helps teams track scan coverage, prioritize risk using business and ownership context, and coordinate remediation through Patch Management, tasks, and ITSM workflows.

info
  • Audience: Security engineers, cloud and platform teams, operations teams, and compliance owners
  • Outcome: Centralized vulnerability intake, prioritization, remediation tracking, and shared visibility across CMDB, Patch Management, and ITSM tools

Use Vulnerability Management when you need to:

  • Consolidate findings from multiple scanners and security services.
  • Identify assets that are unscanned or have stale scan data.
  • Relate vulnerabilities to applications, environments, owners, and business criticality.
  • Prioritize remediation using severity, exploitability, asset context, and vulnerability age.
  • Route findings to responsible teams, ticket queues, and remediation workflows.
  • Manage exceptions, risk acceptance, due dates, and SLA policies.
  • Track remediation progress through dashboards, reports, and scheduled outputs.
  • Coordinate vulnerability remediation with Patch Management, Change Management, and ITSM tools.

Core Capabilities

Cloudaware Vulnerability Management provides:

  • Multi-source vulnerability intake – findings from multiple sources are stored as Cloudaware Vulnerability Scan records (see Findings & Data Model).
  • Scan coverage analysis – scan status and Last Scan Date used to identify unscanned assets, stale scan results, and coverage gaps.
  • Normalized findings – CVEs, severity, exploitability, evidence, source details, and status represented consistently across scanner sources.
  • CMDB-based enrichment – findings associated with infrastructure resources, applications, environments, owners, organizational units, and business criticality.
  • Risk prioritization – severity, CVSS/ExPRT rating, exploitability, vulnerability age, asset context, and configurable risk models used to rank remediation work.
  • Finding deduplication – overlapping findings from multiple sources correlated according to supported normalization and deduplication rules.
  • Ownership and routing – remediation work directed to responsible teams, application owners, queues, and external systems.
  • Exceptions and SLA management – risk acceptance, due dates, SLA policies, escalation, and exception workflows associated with findings.
  • Remediation tracking – assignments, tickets, patch workflows, validation, and closure status tracked across Cloudaware and connected systems.
  • Dashboards and reporting – exposure, scanner coverage, vulnerability age, SLA compliance, ownership, and remediation progress available through dashboards, reports, exports, and scheduled delivery (see Dashboards & Reporting).

How Vulnerability Management Works

Cloudaware Vulnerability Management follows a source-to-remediation workflow:

  1. Collects vulnerability data. Findings are ingested from Cloudaware-managed scanning, cloud-native security services such as AWS Inspector, and supported third-party scanners.
  2. Normalizes findings. Source-specific records are mapped to a shared vulnerability data model with consistent severity, exploitability, evidence, status, and ownership fields.
  3. Adds CMDB context. Findings are related to affected assets, applications, environments, owners, organizational units, and other business context stored in CMDB.
  4. Evaluates coverage and priority. Scan status, last scan date, vulnerability age, severity, exploitability, and asset criticality help teams identify gaps and determine what to remediate first.
  5. Routes remediation work. Findings can be assigned through tasks to application owners, operations teams, ticket queues, Patch Management workflows, and external ITSM systems.
  6. Tracks resolution and exceptions. Remediation status, due dates, SLA performance, validation results, exceptions, and risk-acceptance decisions remain associated with the vulnerability records.
  7. Surfaces risk and progress. Dashboards, reports, exports, and scheduled notifications provide visibility into exposure, coverage, ownership, SLA performance, and remediation trends.

Vulnerability Sources and Scanning

Cloudaware Vulnerability Management can receive findings from several source types.

Cloudaware Vulnerability Scanning

Cloudaware Vulnerability Scanning is the Cloudaware-managed vulnerability scanning service. Depending on the configured scanning method, it can support:

Because the scanning infrastructure is operated by Cloudaware, customers do not need to deploy and maintain dedicated scanner servers for these workflows.

Cloud-Native Scanners

Cloud-native security services can provide vulnerability findings for supported provider resources. See Cloud-Native Scanners for supported sources and configuration guidance.

Third-Party Scanners

Supported third-party scanners and security platforms can send findings to Cloudaware for centralized analysis and remediation tracking. Examples:

See Sources & Scanners and Integrations for supported tools and implementation details.

Relationship to Other Modules and Services

Cloudaware Vulnerability Scanning (VSaaS) is the primary managed scanning service feeding this module. See Cloudaware Vulnerability Scanning for details. Related services and modules include:

  • Breeze Agent supplies OS‑level telemetry and automates deployment of scanning agents, enabling host‑based scanning.
  • Patch Management consumes prioritized vulnerability data to determine what to patch and when.
  • Change Management tracks approvals and implementation for remediation tasks.

Explore the Vulnerability Management Documentation

Use these guides together as the Cloudaware Vulnerability Management documentation set.

Prepare Vulnerability Management

  1. Review requirements. Confirm prerequisites for scanner sources, integrations, permissions, ownership data, and remediation workflows.

  2. Configure sources and scanners. Connect Cloudaware Vulnerability Scanning, cloud-native services, and supported third-party scanners.

  3. Understand findings and the data model. Review finding records, fields, relationships, normalization, and CMDB context.

Prioritize and Remediate Findings

  • Prioritization: Configure and interpret risk scoring, severity, exploitability, ownership, business context, and prioritization logic.
  • Remediation: Assign, track, validate, and close remediation work.
  • Exceptions & SLAs: Manage risk acceptance, due dates, SLA policies, escalations, and exception workflows.

Report and Integrate

  • Dashboards & Reporting: Monitor exposure, scan coverage, SLA compliance, vulnerability age, and remediation progress.
  • Integrations: Connect ITSM, collaboration, BI, reporting, and downstream workflow systems.

Operate Vulnerability Management

  • Operations: Manage data quality, scan coverage, synchronization health, governance, and recurring operational tasks.
  • Playbooks: Follow recommended workflows for common vulnerability management scenarios.
  • Reference: Review reference on Cloudaware Vulnerability Scan record types and limits and quotas.
  • FAQ: Find answers about sources, findings, prioritization, remediation, exceptions, scope, and troubleshooting.