Findings Data: Critical Vulnerability Management (CVM)

The Critical Vulnerability Management (CVM) data feed provides details on CVM findings along with several other data sets.

Schemas:

Other data sets:

Data Structure Diagram

Data Solutions data feeds are optimized for relational databases. Use the structure conveyed in the following diagram to make the best use of entity relationships within the Critical Vulnerability Management (CVM) Intelligence data feed:

Schemas

Finding Details

Field Description
temporary_finding_id

String [temp_finding_guid]

The temporary unique identifier for this finding.
company_guid

String [entity_guid]

The unique identifier of the company.
event_date

String [YYYY-MM-DD]

When the finding was first observed.
affects_rating

Boolean

true = This finding affects the rating.
country

String

The country where the asset attributed with this finding is located.
country_code

String

The country code where the asset attributed with this finding is located.
decay_date

String [YYYY-MM-DD]

The date when this finding stops impacting the rating if nothing else changes.
event_grade

String

The finding grade.
evidence_key

String

The source of evidence for the finding. It may be from an IP address, domain, IP/domain combination, or port.
first_seen

String [YYYY-MM-DD HH:MM:SS]

The first time the finding was observed.
impacts_risk_vector_code

String

A reason code for why the finding does not impact on the rating.

impacts_risk_vector_label

String

The reason why the finding no longer impacts the rating.

is_remediated

Boolean

true = This finding has been remediated.
last_seen

String [YYYY-MM-DD HH:MM:SS]

The most recent time the finding was observed.
observation_id

String

The unique identifier of this observation.
remediation_duration

Integer

The number of days it took to remediate the finding.
risk_category

String

The risk category.
risk_vector

String

The risk vector slug name.
risk_vector_label

String

The risk vector name.
rollup_start_date

String [YYYY-MM-DD]

The date when this finding was first observed.
rollup_end_date

String [YYYY-MM-DD]

The date when the infection was last observed.
rolledup_observation_id

String

A stable and randomized identifier for findings. It is assigned to a finding when one or more observations with largely similar key properties occur in close succession.
severity

Decimal

This finding’s Bitsight severity.
severity_category

String

This finding’s Bitsight severity.

Remediation Dates

Field Description
temporary_finding_id

String

The temporary unique identifier for this finding.
first

String [YYYY-MM-DD HH:MM:SS]

The date and time when the finding first appeared.
last

String [YYYY-MM-DD HH:MM:SS]

When the finding is remediated.
  • September 11, 2024: Published.
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.