Data Governance
Vulnerability data often includes sensitive information about weaknesses in your environment. Data governance ensures that this information is retained appropriately, auditable, and accessible only to the right teams/users.
Use this guide to apply practical tips and considerations when working with vulnerability data in Cloudaware.
Retention and Archival
Consider policies for:
- Raw scan records – how long to retain detailed per‑scan data.
- Aggregated findings – how long to keep historical vulnerability and task records.
- Logs and events – retention of integration logs, change histories, and audit trails.
Recommendations:
- Retain at least several years of history for regulated systems to support audits.
- Use summarization or archival strategies for very old, closed findings to keep performance healthy.
Evidence and Auditability
Cloudaware can help provide audit evidence by:
- Linking Remediation Tasks to change records, patch jobs, and verification scans.
- Retaining status changes on Vulnerability Scan records (open, remediated, suppressed).
- Keeping exception records with approvals and expiry dates.
For audit packs and example reports, see Reports.
Access and Privacy
- Restrict access to vulnerability data based on role (see RBAC).
- Consider limiting visibility of certain asset types or OUs to specific groups.
- Treat exported data and offline copies as sensitive and control where they are stored.