- Findings are presented in a table view that provides a single place to sort, filter, analyze, comment on, track your remediation efforts, and export the findings.
- Findings are reported in Coordinated Universal Time (UTC).
Actions
Below is a list of all the actions that a user can perform on the Findings page.
Add a Vendor to a Folder
Add the current company to a folder.
Instructions: Select Actions ➔ Add to Folder at the top-right of the table.
Company Notes
Add or view notes.
Instructions: Select Actions ➔ Add/View Notes at the top-right of the table.
Company Comparison
Compare the current company to other companies in your portfolio.
Instructions: Select Actions ➔ Compare at the top-right of the table. This opens the Compare Companies page with the current company already selected.
Customize the Data
Customize the data in the table.
Download the Data
Download the table data (.csv).
- If the .csv contains 9000 or fewer rows of data, the download begins immediately.
- If the .csv contains greater than 9000 and less than 100,000 rows of data, the download runs asynchronously. When the download is ready, the user who requested it is notified with an email and a notification.
Edit the Tier
Edit the tier of the current company.
Instructions: Select Actions ➔ Edit Tier at the top-right of the table.
Filter the Table
Generate Reports and Assessments
Instructions: Select Reports and Assessments at the top-right of the Findings Table.
Search Findings
Instructions: Do a text search using the search bar at the top-right. Text with matches is highlighted.
View the Service Providers Sheet
Instructions: Select Actions ➔ Service Providers at the top-right of the Findings page.
View the Products Sheet
Instructions: Select Actions ➔ Products at the top-right of the Findings page.
View the Finding Details Sheet
See the Finding Details sheet.
Instructions: Select a finding from the table.
Unsubscribe from the Vendor
Instructions: Select Actions ➔ Unsubscribe at the top-right of the table.
Collaboration
Invite the vendor to collaborate and enable their access in the Client/Vendor Access Program.
Instructions:
- Select Actions ➔ Enable Vendor Access at the top-right of the table.
- Select the checkboxes next to a number of findings in the table, then select the Vendor Access button.
Default View: "Priority Issues"
The following fields appear in the table by default using the following filters:
- Impacts Rating: Yes
- Grade: Bad + Warn
- Severity: Severe + Moderate
You can customize the table to include additional fields per your needs.
- Risk Vector
The Bitsight risk vector.
- Finding Identifier
The asset (e.g., IP, domain, host, application, port) and its status (e.g. online/offline, version, support status) that identifies the finding.
- Details
Details about the finding. Select the text for a more detailed explanation.
- [Date] First Seen
The date when the finding was first observed.
- [Date] Last Seen
The date when the finding was last observed.
- Impacts Risk Vector Grade
Indicates whether a finding impacts the associated risk vector grade.
- Grade
The current finding grade.
- Finding Severity
The severity of the finding.
- Asset Importance
The asset importance assigned to the asset associated with the finding.
- Remaining Lifetime
The remaining finding lifetime in days.
-
Indicates whether a finding has Threat Insights data available.
- Yes – The finding is associated with one or more TTPs and/or threat groups
- No – No threat intelligence is currently available for that finding
Identifies which threat actors are surging in activity versus those becoming less relevant.
Lists instructions for how to remediate a finding.
Refer to the Certificate Serial Number to identify TLS/SSL Certificate findings.
Risk Vector Fields
The finding details in the table vary depending on the risk vector. See details for:
- Compromised Systems Findings
- Diligence
- File Sharing (User Behavior Forensics)
- Public Disclosures
- December 5, 2024: Separated Finding Details sheet and filters to new articles.
- May 29, 2024: Certificate Serial Number replaces Finding Identifier as the TLS/SSL Certificates finding identifier.
- January 18, 2024: New Findings page overview specific to the Continuous Monitoring app.
Comments
Please sign in to leave a comment.