Skip to main content

Data Governance

Vulnerability data often includes sensitive information about weaknesses in your environment. Data governance ensures that this information is retained appropriately, auditable, and accessible only to the right teams/users.

Use this guide to apply practical tips and considerations when working with vulnerability data in Cloudaware.

Retention and Archival

Consider policies for:

  • Raw scan records – how long to retain detailed per‑scan data.
  • Aggregated findings – how long to keep historical vulnerability and task records.
  • Logs and events – retention of integration logs, change histories, and audit trails.

Recommendations:

  • Retain at least several years of history for regulated systems to support audits.
  • Use summarization or archival strategies for very old, closed findings to keep performance healthy.

Evidence and Auditability

Cloudaware can help provide audit evidence by:

  • Linking Remediation Tasks to change records, patch jobs, and verification scans.
  • Retaining status changes on Vulnerability Scan records (open, remediated, suppressed).
  • Keeping exception records with approvals and expiry dates.

For audit packs and example reports, see Reports.

Access and Privacy

  • Restrict access to vulnerability data based on role (see RBAC).
  • Consider limiting visibility of certain asset types or OUs to specific groups.
  • Treat exported data and offline copies as sensitive and control where they are stored.