Skip to content
ClearGRC User Guide

ClearGRC User Guide

  • Documentation
ClearGRC User Guide
ClearGRC User Guide

Getting Started

4
  • Signing In
  • Understanding the Dashboard
  • Navigation
  • Roles and Permissions

Common Workflows

9
  • Create and Approve a Policy
  • Complete an Assessment
  • Upload Artifacts
  • Review AI Artifact Analysis
  • Record and Assess a Risk
  • Create a Risk Response
  • Test a Control
  • Import Vulnerabilities
  • Complete a Vendor Assessment

Governance

6
  • Policy Center
  • Document Inventory
  • Third-Party Inventory
  • Company Setup
  • Process
  • Exception

Risk

5
  • Risk Register
  • Controls
  • Vulnerabilities
  • Assets
  • Threats

Compliance

3
  • Assessments
  • Cross Reference
  • Audit Inventory

Administration

5
  • Reports
  • Users and Roles
  • Framework Configuration
  • Notifications
  • Application Settings

FAQ

1
  • Frequently Asked Questions

Troubleshooting

1
  • Troubleshooting
View Categories
  • Home
  • Docs
  • Risk
  • Vulnerabilities

Vulnerabilities

1 min read

App navigation: Risk → Vulnerability

The Vulnerability module tracks security weaknesses identified across your asset inventory – whether discovered by a scanner, manually assessed, or imported from a third-party tool. Vulnerabilities are scored using the industry-standard CVSS scale and linked to risks via the ATVEC methodology.

Screen Layout #

Navigate to Risk → Vulnerability to open the Vulnerability Inventory screen. The summary panel shows total vulnerability counts and a breakdown by CVSS severity (Critical, High, Medium, Low).

[Screenshot: Vulnerability Inventory screen showing CVSS severity breakdown]

Creating a Vulnerability #

Select + on the toolbar. The Vulnerability Action dialog offers four options:

  • Create Manually – enter Title, Description, CVSS Severity score, Affected Assets, Status, and Owner.
  • Import from File – bulk import using a file upload.
  • Import from NVD – pull vulnerability data from the NIST National Vulnerability Database.
  • Import from Nessus – connect to your Nessus integration (configured via Admin → System → Integrations). ClearGRC creates records pre-populated with scan metadata and CVSS scores.

[Screenshot: Vulnerability Action dialog]

Linking Vulnerabilities to Risks #

Vulnerabilities can be linked to Risk Register entries via the ATVEC Mapping wizard step, providing a traceable chain from the specific vulnerability to the formal risk it contributes to.

Tip: Filter the Vulnerability Inventory by Critical and High CVSS severity to prioritize remediation of the most dangerous weaknesses first.

Updated on July 23, 2026

What are your Feelings

  • Happy
  • Normal
  • Sad

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
ControlsAssets
Table of Contents
  • Screen Layout
  • Creating a Vulnerability
  • Linking Vulnerabilities to Risks

© 2026 ClearGRC User Guide

  • Documentation