App navigation: Risk → Vulnerability
ClearGRC supports importing vulnerabilities from external sources (NVD, Nessus) as well as manual entry. This workflow covers all paths.
Option A – Import from NVD #
- Navigate to Risk → Vulnerability.
- Select the + control on the toolbar.
- In the Vulnerability Action dialog, select Import from NVD.
- Search for or select CVE entries from the NIST National Vulnerability Database.
- ClearGRC creates Vulnerability records pre-populated with CVSS severity scores and NVD metadata.
Option B – Import from Nessus #
- Navigate to Risk → Vulnerability.
- Select the + control on the toolbar.
- In the Vulnerability Action dialog, select Import from Nessus.
- Select the Nessus scan file or connect to the Nessus integration (configured via Admin → System → Integrations), then confirm the import.
- ClearGRC creates Vulnerability records from the scan data, pre-populated with CVSS severity scores and scan metadata.
[Screenshot: Vulnerability Action dialog showing import options]
Option C – Create Manually #
- Navigate to Risk → Vulnerability.
- Select + and choose Create Manually.
- Enter the vulnerability details:
- Title and Description.
- CVSS Severity score.
- Affected Assets – link to records in the Asset inventory.
- Status and Owner.
- Save the record.
Linking Vulnerabilities to Risks #
Once imported or created, vulnerabilities can be linked to risk records in the Risk Register via the ATVEC Mapping wizard step (Vulnerability field). This provides traceability from the vulnerability to the formal risk it contributes to.
Tip: Use the Vulnerability Summary panel on the inventory screen to filter by CVSS severity level and prioritize remediation of critical and high vulnerabilities first.
