Create a vulnerability calculator

A vulnerability calculator is a pre-defined formula to calculate the severities of security incidents when certain criteria are met. You can define your own vulnerability calculators as needed.

Before you begin

  • To let the vulnerability admin role see values to apply the template, give it full read, write (or save_as_template) capabilities on any table used by calculators.
  • Roles required: sn_vul.vulnerability_admin

Procedure

  1. Navigate to Vulnerability > Administration > Vulnerability Calculator Groups.
  2. Click the name of the group for which you want to create a calculator, or create a group.
  3. In the Vulnerability Calculators related list, click New.
  4. Fill in the fields on the form, as appropriate.
    Table 1. Vulnerability Calculator form
    Field Description
    Name The name of the vulnerability calculator.
    Table Select the table to be used for this calculator.
    Note: When you add calculators to tables other than Vulnerability [sn_vul_vulnerability] and Vulnerable Item [sn_vul_vulnerable_item], add business rules and UI Actions to those tables. To see examples:
    • Navigate to System Definition > Business Rules, and locate the Calculate Criticality business rule on the Vulnerable Item [sn_vul_vulnerable_item] table.
    • Navigate to System UI > UI Actions, and locate the Calculate Criticality UI action on the Vulnerable Item [sn_vul_vulnerable_item] table.
    Order The order in which the vulnerability calculator is run. A calculator with an order entry of 100 runs before a calculator with an order entry of 200.
    Active Turn the calculator on or off.
    Use advanced condition Check box to use a script condition to determine when this calculator is applied. In the Advanced condition field that appears under the Conditions tab, enter the script.
    Note: Before you define advanced conditions and write scripts for determining when the security incident calculators are applied, return to the Vulnerability Calculators list. Explore the vulnerability calculator records shipped with the base system.
    Use script values Check box to use script values. Enter the values in the Script values field that appears under the Values to Apply tab.
    Description A description of this calculator.
    Condition Basic filter conditions for determining when the calculator is used.
  5. Click Submit.