App navigation: Risk → Vulnerability
The Vulnerability module tracks security weaknesses identified across your asset inventory – whether discovered by a scanner, manually assessed, or imported from a third-party tool. Vulnerabilities are scored using the industry-standard CVSS scale and linked to risks via the ATVEC methodology.
Screen Layout #
Navigate to Risk → Vulnerability to open the Vulnerability Inventory screen. The summary panel shows total vulnerability counts and a breakdown by CVSS severity (Critical, High, Medium, Low).
[Screenshot: Vulnerability Inventory screen showing CVSS severity breakdown]
Adding Vulnerabilities #
Select + on the toolbar. The Vulnerability Action dialog offers four options:
Create Manually #
Enter Title, Description, CVSS Severity score, Affected Assets, Status, and Owner directly.
Import from File #
Bulk import using a file upload (use the downloadable template).
Import from NVD #
- Select Import from NVD in the Vulnerability Action dialog.
- Search for or select CVE entries from the NIST National Vulnerability Database.
- ClearGRC creates Vulnerability records pre-populated with CVSS scores and NVD metadata.
Import from Nessus #
- Select Import from Nessus in the Vulnerability Action dialog.
- Select the Nessus scan file or connect to the Nessus integration (configured via Admin → System → Integrations).
- ClearGRC creates Vulnerability records pre-populated with CVSS severity scores and scan metadata.
[Screenshot: Vulnerability Action dialog showing the four options]
Linking Vulnerabilities to Risks #
Once imported or created, vulnerabilities can be linked to Risk Register entries via the ATVEC Mapping wizard step. This provides a traceable chain from the specific vulnerability to the formal risk it contributes to.
Tip: Filter the Vulnerability Inventory by Critical and High CVSS severity to prioritize remediation of the most dangerous weaknesses first.
