Skip to main content

Vulnerability Management FAQ

This FAQ covers common questions about scan cadence, severity, ownership, and exceptions in Cloudaware Vulnerability Management.

Can I Run On‑Demand Scans?

Yes. If you use Cloudaware Vulnerability Scanning (VSaaS), Cloudaware can enable a Scan Request action that lets you request on‑demand scans for specific assets or scopes. These run in addition to the regular scheduled cadence.

How Often Are Assets Scanned?

For Cloudaware VSaaS, assets are typically scanned at least once every 7 days using an internal scheduling algorithm. The exact cadence can vary by asset type and service agreement. You can track scan coverage and Last Scan Date data in CMDB and in Vulnerability Management dashboards and reports.

Which Scan Types Are Supported?

Cloudaware can ingest and manage vulnerabilities from:

See Sources & Scanners and Cloudaware Vulnerability Scanning for details.

Do I Need to Run My Own Scanner Infrastructure?

Not necessarily. With Cloudaware VSaaS, Cloudaware operates the scanning infrastructure and manages vendor relationships. You can also connect your existing scanners and let Cloudaware focus on normalization, ownership, and reporting.

How Does Cloudaware Handle False Positives?

False positives and acceptable risks are managed through Vulnerability Exceptions:

  • You create exception records linked to one or more vulnerability findings.
  • Exceptions can include justification, owner, and expiry date.
  • When an active exception exists, affected findings are marked as suppressed and excluded from standard remediation/SLA calculations.

See Exceptions & SLAs for more details.

How Are Severities and Risk Scores Calculated?

Cloudaware stores vendor‑provided severity (e.g., CVSS) and may enrich it with additional risk signals, such as exploit availability, asset criticality, and data sensitivity. You can define risk models that combine these signals into a single prioritization score.

See Severity & Risk Scoring and Risk Models.

How Do Vulnerabilities Map to Owners and Teams?

Ownership is derived from CMDB relationships:

  • Each asset belongs to one or more applications, OUs, or platform teams.
  • Vulnerabilities inherit ownership from their related assets or application records.
  • Routing rules use this ownership information to assign remediation work or tickets.

See Ownership & Routing.

How Does Vulnerability Management Interact with Patch Management?

Vulnerability Management helps teams to identify and prioritize issues; Patch Management implements the fixes:

  • Vulnerability findings feed into patch baselines and patch jobs.
  • After patch deployment, verification and rescans can update vulnerability status.
  • Dashboards can show how many vulnerabilities were remediated by specific patch cycles.

See Patch Management, Remediation, and Verification & SLAs.