FAQs: Getting Started with SAFE CTEM

Next

How does SAFE CTEM prioritize exposures?

SAFE CTEM prioritizes exposures via Finding Scores that combine technical context, business relevance, and real-world threat intelligence for a data-driven, explainable, holistic and risk-based approach.

The Finding Score is a 0-10 risk metric (10 representing the greatest risk) that combines vulnerability characteristics with real-world environmental context to answer the question: "How much risk does this vulnerability pose to my organization right now?”.

The Finding Score is designed to take all relevant vulnerability and real-world context into account, so that cybersecurity teams can focus their efforts on the small percentage of truly critical exposures.

SAFE automatically calculates a Finding Score for each finding instance (one finding on a single asset) and dynamically updates scores to reflect the latest vulnerability, threat, and contextual data available.

Refer to Understanding Finding Score.

What factors are used in SAFE CTEM’s exposure scoring?

SAFE CTEM Finding Scores are calculated based on a set of factors across four component groups: Access, Threat, Impact and Mitigation. These components help users understand why a finding is prioritized and what remediation teams should act on first.

Refer to Understanding Finding Score.

How does SAFE CTEM determine exploitability and business impact?

For exploitability, SAFE CTEM considers Access-related parameters (such as network zone, exposure attack vector) along with Mitigation-related parameters (mitigating controls such as EDR and CIS Benchmark system hardening) to determine the level of exploitability of each finding, incorporating into the Finding Score.

For business impact, SAFE CTEM considers attributes related to environment criticality (e.g., Production vs. Development), mission criticality, asset status, and relevant CMDB tags. Note that SAFE CRQ values are not currently used to set business impact related to individual findings.

Refer to Understanding Finding Score.

How does SAFE CTEM collect, correlate, and normalize exposure data?

SAFE CTEM collects exposure data by two mechanisms:

  1. Ingestion from vulnerability assessment data sources, such as Qualys VMDR, Tenable VM, or CrowdStrike Exposure Management.

  2. Native inference of CVE vulnerabilities or EOL/EOS software based on analysis of software information provided by high-fidelity data sources, such as Tanium or Windows Defender for Endpoint.

SAFE CTEM correlates exposure data in a two step process:

  • Asset deduplication: ensures that the asset inventory is clean, deduplicated, normalized and accurate - providing a solid foundation for exposure management. For infrastructure assets this is done by analyzing key attributes for comparison including hostname, MAC Address, IP Address, Cloud URN, Serial Number, SNMP Management IP, while handling partial matches, exact matches, and missing data. Refer to Asset Deduplication in SAFE.

  • Finding deduplication: analyzes findings from all sources detected on each asset and deduplicates based on key attributes such as vulnerability name or ID (e.g., CVE ID), the vulnerable software context, and data source. Refer to Finding Deduplication in SAFE.

SAFE CTEM then normalizes exposure data into standardized categories, considering the presence of vulnerability id’s (e.g., CVE ID), misconfiguration names, and the specific data sources and APIs used to ingest each finding.

Yes, SAFE CTEM enriches each finding with relevant EPSS, CVSS, CISA KEV, threat intelligence, and attack path analysis in order to compute accurate and explainable Finding Scores for prioritization.

  • EPSS: The Exploit Prediction Scoring System score estimates the likelihood, between 0 and 100%, that exploit evidence will be observed within the next 30 days, from https://www.first.org/epss/

  • CVSS: The Common Vulnerability Scoring System delivers a vendor-neutral, quantitative assessment of software flaw severity, assigning a 0-10 metric based on inherent vulnerability traits according to https://www.first.org/cvss/

  • CISA KEV: CISA's Known Exploited Vulnerabilities Catalog is an authoritative list of security flaws that have been confirmed by the Cybersecurity and Infrastructure Security Agency (CISA) to be actively exploited in the wild from https://www.cisa.gov/known-exploited-vulnerabilities-catalog  

  • Threat Intelligence: Contextual data on active adversaries and real-world exploits associated with individual CVEs and other findings, sources from numerous feeds on a continuous basis, including VulnCheck

  • Attack Path Analysis: Considers Access-related parameters (such as network zone, vulnerability attack vector) along with Mitigation-related parameters (mitigating controls such as EDR and CIS Benchmark system hardening) to determine the level of exploitability of each finding

Refer to Understanding Finding Score.

How does SAFE CTEM identify truly exploitable exposures and reduce remediation noise?

SAFE CTEM considers Access-related parameters (such as network zone, vulnerability attack vector) along with Mitigation-related parameters (mitigating controls such as EDR and CIS Benchmark system hardening) to identify truly exploitable exposures. Findings that are effectively mitigated by controls in place such as EDR or CIS Benchmark hardening have their Finding Score lowered to reduce the number of critical exposures for priority remediation. Refer to Understanding Finding Score.

How does SAFE CTEM recommend and automate remediation actions?

For each finding instance, SAFE CTEM identifies the associated remediation information, including fix version and remediation steps. This remediation information can be either ingested from data sources or inferred natively when high-fidelity software information is available.

Users can drive remediation action by the creation of tickets. SAFE CTEM supports both native tickets within the SAFE platform and the creation of tickets in 3rd party ticketing platforms such as ServiceNow ITSM or Jira (planned for GA), kept in sync via bi-directional integrations.

Agentic AI workflows in SAFE CTEM enable users to automatically create tickets based on defined filter criteria, in flexible workflows that match specific operational business needs (planned for GA).

How does SAFE CTEM use SAFE CRQ to quantify cyber risk financially?

Actually this question is best answered in the reverse: ‘How does SAFE CRQ use SAFE CTEM to quantify risk financially?’. SAFE CRQ uses data and telemetry from SAFE CTEM to more accurately quantify risk via several mechanisms

  • Increased fidelity of the detected findings via integrated data sources.

  • The findings then influence the Capability, Coverage and Reliability of the appropriate FAIR-CAM controls (e.g., Secured Software), which ultimately influence control maturity and the outputs of each risk scenario.

  • Additionally, integrated data sources for SAFE CTEM are used as signals to directly update the maturity of appropriate FAIR-CAM controls, e.g., (Endpoint Detection and Response), which again influence the outputs of relevant risk scenarios.

How does SAFE CTEM measure and demonstrate risk reduction over time?

Strictly within SAFE CTEM, risk reduction is illustrated based on improvement of key metrics and reduction in the count of critical findings over time, such as

  • Number of Findings

  • New Findings

  • Fixes

  • MTTR (Mean Time to Remediate)

  • MTTD (Mean Time to Detect)

  • ADF (Actionable Days Fresh)

Risk reduction can also be demonstrated by progress on opened tickets (0-100%), which are tracked on a continuous basis.

When both SAFE CRQ and CTEM modules are used together, risk reduction over time is demonstrated in the standard approaches for CRQ.

  • Likelihood, Loss Magnitude, Annualized Loss trends over time

  • Risk reduction via Treatment Plans covering Findings in scope

Which security tools, scanners, and data sources does SAFE CTEM integrate with?

Refer to Integrations Guides.