Reports
Reports complement dashboards by delivering scheduled snapshots of risk and remediation performance to stakeholders, as well as providing audit‑ready evidence.
Use this guide to review report types, escalation workflows, audit-ready evidence, and export options for vulnerability oversight.
Scheduled Reports
Examples:
- Weekly OU reports
- Per‑OU summary of open vulnerabilities by risk band.
- Assets with overdue vulnerabilities or scans.
- Links to dashboards and list views for drill‑down.
- Monthly executive summary
- High‑level exposure trends.
- SLA performance and exception volume.
- Commentary on major initiatives and improvements.
Reports can be emailed or shared via subscriptions, often aligned with existing governance forums (e.g., weekly security reviews, monthly risk committees).
Escalation Reports
Cloudaware supports escalation‑style reporting where:
- OUs receive curated lists of vulnerabilities requiring action.
- Views allow mass updates and workflow actions.
- Schedules (e.g., every Wednesday) keep teams engaged with their backlog.
See Vulnerability Management Processes for details on Escalation Reports.
Audit and Compliance Packs
For regulated environments, prepare report bundles showing:
- Evidence of regular scanning (coverage, scan frequency).
- SLA adherence for in‑scope systems.
- Exceptions with justifications and approvals.
- Samples of tickets and change records linked to remediated vulnerabilities.
These packs can be generated periodically or on demand for audits.
Exports
Cloudaware supports exporting vulnerability and remediation data for:
- Offline analysis in BI tools.
- Integration with GRC platforms.
- Ad‑hoc sharing with teams that do not have direct access to Cloudaware.
When exporting, apply appropriate filters and masking to protect sensitive asset or vulnerability details.