Skip to content
ClearGRC User Guide

ClearGRC User Guide

  • Documentation
ClearGRC User Guide
ClearGRC User Guide

Getting Started

3
  • Navigation
  • Understanding the Dashboard
  • Signing In

Governance

6
  • Exception
  • Process
  • Company Setup
  • Third-Party Inventory
  • Document Inventory
  • Policy Center

Risk

5
  • Threats
  • Assets
  • Vulnerabilities
  • Controls
  • Risk Register

Compliance

3
  • Audit Inventory
  • Cross Reference
  • Assessments

Administration

5
  • Roles and Permissions
  • Reports
  • Application Settings
  • Notifications
  • Users and Roles

FAQ

1
  • Frequently Asked Questions

Troubleshooting

1
  • Troubleshooting
View Categories
  • Home
  • Docs
  • Risk
  • Vulnerabilities

Vulnerabilities

1 min read

App navigation: Risk → Vulnerability

The Vulnerability module tracks security weaknesses identified across your asset inventory – whether discovered by a scanner, manually assessed, or imported from a third-party tool. Vulnerabilities are scored using the industry-standard CVSS scale and linked to risks via the ATVEC methodology.

Screen Layout #

Navigate to Risk → Vulnerability to open the Vulnerability Inventory screen. The summary panel shows total vulnerability counts and a breakdown by CVSS severity (Critical, High, Medium, Low).

[Screenshot: Vulnerability Inventory screen showing CVSS severity breakdown]

Adding Vulnerabilities #

Select + on the toolbar. The Vulnerability Action dialog offers four options:

Create Manually #

Enter Title, Description, CVSS Severity score, Affected Assets, Status, and Owner directly.

Import from File #

Bulk import using a file upload (use the downloadable template).

Import from NVD #

  1. Select Import from NVD in the Vulnerability Action dialog.
  2. Search for or select CVE entries from the NIST National Vulnerability Database.
  3. ClearGRC creates Vulnerability records pre-populated with CVSS scores and NVD metadata.

Import from Nessus #

  1. Select Import from Nessus in the Vulnerability Action dialog.
  2. Select the Nessus scan file or connect to the Nessus integration (configured via Admin → System → Integrations).
  3. ClearGRC creates Vulnerability records pre-populated with CVSS severity scores and scan metadata.

[Screenshot: Vulnerability Action dialog showing the four options]

Linking Vulnerabilities to Risks #

Once imported or created, vulnerabilities can be linked to Risk Register entries via the ATVEC Mapping wizard step. This provides a traceable chain from the specific vulnerability to the formal risk it contributes to.

Tip: Filter the Vulnerability Inventory by Critical and High CVSS severity to prioritize remediation of the most dangerous weaknesses first.

Updated on July 23, 2026

What are your Feelings

  • Happy
  • Normal
  • Sad

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
AssetsControls
Table of Contents
  • Screen Layout
  • Adding Vulnerabilities
    • Create Manually
    • Import from File
    • Import from NVD
    • Import from Nessus
  • Linking Vulnerabilities to Risks

© 2026 ClearGRC User Guide

  • Documentation