Prioritize and Remediate Vulnerabilities from ETM

The Enterprise TruRisk Management (ETM) integration with TruRisk Eliminate™ (TRE) connects risk prioritization directly to patch remediation. It helps security analysts prioritize vulnerabilities in the ETM Risk Workbench, hand off the plan to IT Ops, and Patch Managers act on the elimination plan in TruRisk Eliminate™. This connected workflow moves vulnerabilities from prioritization to patch deployment without leaving the platform, helping you reduce Mean Time to Remediate (MTTR) and keep remediation tied to risk.

Prerequisites

  • ETM Version 1.11.0 (Quasar 4.0.0.0) or later.
  • Patch Manager permissions for users who receive plans and create remediation jobs.
  • ETM and TRE integration enabled on your subscription.

Prioritize Vulnerabilities in ETM

To prioritize your workflow, follow these steps:

  1. On the ETM platform, navigate to ETM > Risk Management > Risk Workbench.
  2. Click Start Prioritizing.
  3. Define Scope

    Set the business context and drive prioritization:

    • Click the desired business entity/entities.

      OR
    • Click Choose Tags Instead to use asset tags for the prioritization scope.
      1. Click Choose Tags Instead. The Select Tags dialogue box is displayed.
      2. Select the desired tags and then click Add Tag.
  4. Filter Findings

    Decide the prioritization approach to discern and filter the findings requiring immediate attention. To do this effectively, structure the approach based on certain filters :
    1. Select the system-defined template (Highest Risk Reduction) with default filters. 
       
      OR
    2. Create a custom template.
      You can prioritize active vulnerabilities and mis-configurations on-demand across tagged assets or selected Business Entities.

      Show me the steps to create a custom templateShow me the steps to create a custom template
      1. Click Let Me Decide.
      2. The Filters page appears with three different types of filters:
        1. Common Attributes: These filters  are common across both the finding types (vulnerabilities and misconfigurations)
        2. Vulnerabilities: These filters are only applicable to vulnerabilities.
        3. Misconfigurations: These filters are only applicable to misconfigurations.
      3. Expand each filter type and then drag and drop the desired filters to build your custom template.
      4. Click Add.
      5. Click Save as Template if you desire to save this custom template for future use.
      6. In the Save Filter As A Template dialog box, enter the Name and Description of the template and click Save.
      7. The saved template appears on the Select Prioritization Approach page.
  5. Start Prioritization

    Click Prioritize Now.
  6. Take Actions on Prioritized Findings

    1. Filter Using Group By:
      If desired, you can further filter these findings using various Group By options. To do so, click Group By, and use any one of the specified options to group and filter the findings further.
    2. Download Findings in CSV Format:
      If desired, you can download these findings in CSV format. To do so, click the ellipsis near Save Plan at the top right corner and then click Download Report as CSV.
    3. Save Prioritization Plan:
      1. Click Save  Plan if you want to save the prioritization scope, findings, and filters for future use. 
      2. In the Save Prioritization Plan dialog box, enter the name and description of the plan and then click Save.
      3. The saved plan is displayed on the prioritization listing page on the Risk Workbench tab
      4. If desired, you can download the prioritization plan in CSV format. To do so, click the ellipsis near View Elimination Plan  at the top right corner and then click Download Report as CSV.
  7. Hand Off to IT Ops 

    To create the Elimination Plan, select a user with Patch Management permissions, and hand off the prioritization plan to the IT Ops team. 
    1. Click Hand Off to IT Ops. A Create Elimination Plan window is displayed. 
    2. Select the Remediation Owner and Priority from the list.
    3. Click Hand Off to IT Ops. The elimination plan is saved successfully. The plan is now replicated to TRE.
    4. If desired, you can download the elimination plan in CSV format. To do so, click the three dots near View Elimination Plan at the top right corner and then click Download Report as CSV.
  8.  View the Elimination Plan

    Select the View Elimination Plan to open the replicated plan in TRE. The plan displays the number of findings, affected assets, and available eliminations for the filter/scope you selected when creating the plan.
    Use Pivot Views to Analyze the Plan

    Group plan data in four ways to decide how to remediate.

    1. Findings: View vulnerabilities at the finding level. This is the default view.

    2. CVE: Group findings by CVE to see how many assets each CVE affects.

    3. Asset: Group findings by asset to see the vulnerabilities and available eliminations per asset.

    4. Elimination: Group findings by patch to see which patches are missing and across how many assets.

             Select a clickable metric, such as the affected vulnerabilities count, to filter the list to those findings.              To remediate the vulnerabilities, perform the following: 

  • To remediate an individual CVE, select the CVE and click Create Remediation Job. A Windows/Linux Deployment Job window is displayed. 
  • To remediate multiple CVEs, select them and from the Actions menu, click  Create Remediation Job.  The Windows/Linux Deployment Job window is displayed. 
  1. Create Remediation Jobs

    To complete the steps for Windows job creation, refer to Creating Patch Job for Windows Assets, and for Linux job creation, refer to Creating Patch Job for Linux Assets.
    1. In step 2, on the Select Assets tab, assets from the elimination plan are pre-populated under the Assets Selected from Elimination Plan section. 
    2. In step 4, on the Select Patches tab, patches from the elimination plan are pre-populated under the Assets Selected from Elimination Plan section.