Vendor Risk: Findings

The Findings page [menu-vendor-risk.png Vendor Risk ➔ Findings] in the Continuous Monitoring application presents a selected vendor's findings, which are the culmination of observed internet traffic and configurations. They are recorded as events and records.

  • Findings are presented in a table view that provides a single place to sort, filter, analyze, comment on, track your remediation efforts, and export the findings.
  • Findings are reported in Coordinated Universal Time (UTC).

Bitsight API: GET /v1/companies/entity_guid/findings

Actions

Below is a list of all the actions that a user can perform on the Findings page.

Add a Vendor to a Folder

Add the current company to a folder.

Instructions: Select ActionsAdd to Folder at the top-right of the table.

Company Notes

Add or view notes.

Instructions: Select ActionsAdd/View Notes at the top-right of the table.

Company Comparison

Compare the current company to other companies in your portfolio.

Instructions: Select ActionsCompare at the top-right of the table. This opens the Compare Companies page with the current company already selected.

Customize the Data

Customize the data in the table.

Instructions: Use the columns.png Customize columns button at the top-right. This allows you to select the fields that are displayed in the Findings Table.

Download the Data

Download the table data (.csv).

Instructions: Use the download.png Download button at the top-right.

  • If the .csv contains 9000 or fewer rows of data, the download begins immediately.
  • If the .csv contains greater than 9000 and less than 100,000 rows of data, the download runs asynchronously. When the download is ready, the user who requested it is notified with an email and a notification.

Edit the Tier

Edit the tier of the current company.

Instructions: Select ActionsEdit Tier at the top-right of the table.

Filter the Table

Instructions: Select the filters.png Filter button to expand or collapse the filters and then use a filter set or any of the available filters. See Findings filters.

Generate Reports and Assessments

Instructions: Select Reports and Assessments at the top-right of the Findings Table.

Search Findings

Instructions: Do a text search using the search bar at the top-right. Text with matches is highlighted.

View the Service Providers Sheet

Instructions: Select ActionsService Providers at the top-right of the Findings page.

View the Products Sheet

Instructions: Select ActionsProducts at the top-right of the Findings page.

View the Finding Details Sheet

See the Finding Details sheet.

Instructions: Select a finding from the table.

Unsubscribe from the Vendor

Instructions: Select ActionsUnsubscribe at the top-right of the table.

Collaboration

Invite the vendor to collaborate and enable their access in the Client/Vendor Access Program.

Instructions:

  • Select ActionsEnable Vendor Access at the top-right of the table.
  • Select the checkboxes next to a number of findings in the table, then select the Vendor Access button.

Default View: "Priority Issues"

The following fields appear in the table by default using the following filters: 

  • Impacts Rating: Yes
  • Grade: Bad + Warn
  • Severity: Severe + Moderate

You can customize the table to include additional fields per your needs.

Risk Vector

The Bitsight risk vector.

Finding Identifier

The asset (e.g., IP, domain, host, application, port) and its status (e.g. online/offline, version, support status) that identifies the finding.

Refer to the Certificate Serial Number to identify TLS/SSL Certificate findings.

Details

Details about the finding. Select the text for a more detailed explanation.

[Date] First Seen

The date when the finding was first observed.

[Date] Last Seen

The date when the finding was last observed.

Impacts Risk Vector Grade

Indicates whether a finding impacts the associated risk vector grade.

Grade

The current finding grade.

Finding Severity

The severity of the finding.

Asset Importance

The asset importance assigned to the asset associated with the finding.

Remaining Lifetime

The remaining finding lifetime in days.

Threat Insights

Indicates whether a finding has Threat Insights data available.

  • Yes – The finding is associated with one or more TTPs and/or threat groups
  • No – No threat intelligence is currently available for that finding
Threat Activity Score

Identifies which threat actors are surging in activity versus those becoming less relevant.

Remediation Instructions

Lists instructions for how to remediate a finding.

Risk Vector Fields

The finding details in the table vary depending on the risk vector. See details for:

  • December 5, 2024: Separated Finding Details sheet and filters to new articles.
  • May 29, 2024: Certificate Serial Number replaces Finding Identifier as the TLS/SSL Certificates finding identifier.
  • January 18, 2024: New Findings page overview specific to the Continuous Monitoring app.
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.