Prioritization Workflow

This workflow helps you identify the most important vulnerabilities and misconfigurations to remediate based on business context, risk, and available remediation options.

Workflow Overview

  1. Start Prioritization
  2. Define the Scope
  3. Select a Prioritization Approach
  4. Run Prioritization
  5. Save the Plan

1. Start Prioritization

Navigate to Risk Management > Risk Workbench and click Start Prioritizing.

2. Define the Scope

  • Select one or more Business Entities.
  • Or click Choose Tags Instead to prioritize tagged assets.
    • Click Choose Tags Instead. The Select Tags dialogue box is displayed.
    • Select the desired tags and then click Add Tag.

3. Select a Prioritization Approach

Decide the prioritization approach to discern and filter the findings requiring immediate attention. To do this effectively, structure the approach based on certain  filters :

Highest Risk Reduction

Use the default template when you want the system to automatically prioritize findings that provide the greatest reduction in organizational risk.

Create a Custom Template

You can prioritize active vulnerabilities and misconfigurations on-demand across tagged assets or selected Business Entities.

  1. Click Let Me Decide.
  2. Add Common, Vulnerability, and Misconfiguration filters.
    • Common Attributes: These filters  are common across both the finding types (vulnerabilities and misconfigurations)
    • Vulnerabilities: These filters are only applicable to vulnerabilities.
    • Misconfigurations: These filters are only applicable to misconfigurations.

  3. Expand each filter type and then drag and drop the desired filters to build your custom template.
  4. Click Add.
  5. Click Save as Template if you desire to save this custom template for future use.
  6. In the Save Filter As A Template dialog box, enter the Name and Description of the template and click Save.

    The saved template is displayed on the Select Prioritization Approach page.

4. Run Prioritization

Click Prioritize Now. The application calculates the prioritized findings and projected TruRisk reduction. If calculations continue in the background, informational status messages are displayed until processing completes.

Status Messages During On-Demand Plan Workflow
The following messages assist you during various stages of the on-demand plan workflow:

  • While creating an On-Demand Plan:
    'Save the updated plan and you will be able to see potential risk reduction once recalculations are complete.'
  • After Saving the On-Demand Plan:
    'Your plan has been saved. Recalculation is in progress, and your updated TruRisk™Risk score will appear shortly.'
  • In the Risk Workbench listing page (during recalculation):
    An informational message is displayed for plans where the projected score calculation is still in progress.
  • While opening a saved plan (pending score calculation):
    'Your saved plan is being recalculated. The updated TruRisk™Risk score will be available soon.'
  • After projected score calculation is complete: Projected score calculation is done (Approx 2-3Min), you can view the score on the Risk workbench along with the Formula is TruRisk™Risk V2 is enabled.

5. Save the Plan

  1. Click Save Prioritization Plan.
  2. Enter a name and description.

The saved plan is displayed on the prioritization listing page on the Risk Workbench tab.

Actions and Quick Actions for Prioritization

You can now perform the following actions from the Actions menu and the Quick Actions menu of selected Findings from the Prioritization tab.

The following table describes the purpose of the actions:

Action Purpose
Accept Risk Accept the business risk.
Mark False Positive Exclude invalid findings.
Add Supporting Artifacts Attach evidence or documentation.
Launch TruConfirm Assessment Validate exploitability.

Export Results

You can download the Prioritization report from hamburger menu. The generated report now includes enhanced, plan‑level contextual details, such as:

  • Plan title and description
  • Scope and applied filters
  • CVSS metadata
  • Vulnerability count
  • Impacted findings
  • Asset details and asset IDs
  • Additional relevant metadata