Skip to content
ClearGRC User Guide

ClearGRC User Guide

  • Documentation
ClearGRC User Guide
ClearGRC User Guide

Getting Started

4
  • Signing In
  • Understanding the Dashboard
  • Navigation
  • Roles and Permissions

Common Workflows

9
  • Create and Approve a Policy
  • Complete an Assessment
  • Upload Artifacts
  • Review AI Artifact Analysis
  • Record and Assess a Risk
  • Create a Risk Response
  • Test a Control
  • Import Vulnerabilities
  • Complete a Vendor Assessment

Governance

6
  • Policy Center
  • Document Inventory
  • Third-Party Inventory
  • Company Setup
  • Process
  • Exception

Risk

5
  • Risk Register
  • Controls
  • Vulnerabilities
  • Assets
  • Threats

Compliance

3
  • Assessments
  • Cross Reference
  • Audit Inventory

Administration

5
  • Reports
  • Users and Roles
  • Framework Configuration
  • Notifications
  • Application Settings

FAQ

1
  • Frequently Asked Questions

Troubleshooting

1
  • Troubleshooting
View Categories
  • Home
  • Docs
  • Common Workflows
  • Import Vulnerabilities

Import Vulnerabilities

1 min read

App navigation: Risk → Vulnerability

ClearGRC supports importing vulnerabilities from external sources (NVD, Nessus) as well as manual entry. This workflow covers all paths.

Option A – Import from NVD #

  1. Navigate to Risk → Vulnerability.
  2. Select the + control on the toolbar.
  3. In the Vulnerability Action dialog, select Import from NVD.
  4. Search for or select CVE entries from the NIST National Vulnerability Database.
  5. ClearGRC creates Vulnerability records pre-populated with CVSS severity scores and NVD metadata.

Option B – Import from Nessus #

  1. Navigate to Risk → Vulnerability.
  2. Select the + control on the toolbar.
  3. In the Vulnerability Action dialog, select Import from Nessus.
  4. Select the Nessus scan file or connect to the Nessus integration (configured via Admin → System → Integrations), then confirm the import.
  5. ClearGRC creates Vulnerability records from the scan data, pre-populated with CVSS severity scores and scan metadata.

[Screenshot: Vulnerability Action dialog showing import options]

Option C – Create Manually #

  1. Navigate to Risk → Vulnerability.
  2. Select + and choose Create Manually.
  3. Enter the vulnerability details:
    • Title and Description.
    • CVSS Severity score.
    • Affected Assets – link to records in the Asset inventory.
    • Status and Owner.
  4. Save the record.

Linking Vulnerabilities to Risks #

Once imported or created, vulnerabilities can be linked to risk records in the Risk Register via the ATVEC Mapping wizard step (Vulnerability field). This provides traceability from the vulnerability to the formal risk it contributes to.

Tip: Use the Vulnerability Summary panel on the inventory screen to filter by CVSS severity level and prioritize remediation of critical and high vulnerabilities first.

Updated on July 23, 2026

What are your Feelings

  • Happy
  • Normal
  • Sad

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
Test a ControlComplete a Vendor Assessment
Table of Contents
  • Option A – Import from NVD
  • Option B – Import from Nessus
  • Option C – Create Manually
  • Linking Vulnerabilities to Risks

© 2026 ClearGRC User Guide

  • Documentation