Widgets
The widgets on the Continuous Controls Monitoring & Management dashboard are categorized into distinct classes of information. Each class provides a specific perspective for monitoring, evaluating and optimizing operations. These classifications enable users to efficiently identify trends, measure performance and support data-driven decision-making.
The dashboard offers the following features:
Control overview
Identify
Capability / Widget | Description |
|---|---|
Identify | Maintains awareness of current cybersecurity risks, enabling informed decision-making and prioritization of security efforts. |
Risk Assessment | Evaluates cybersecurity risks to organizational operations, assets, and individuals, providing the foundation for control implementation and monitoring. |
Average Vulnerabilities per Scan | Displays the average number of vulnerabilities detected during each scan. |
Oldest Unremediated Critical Vulnerability | Identifies the oldest critical vulnerability that remains unresolved. |
Active Vulnerabilities by Severity | Displays unresolved vulnerabilities grouped by severity level. |
Vulnerability Discovery Over Time | Tracks the number of vulnerabilities detected during each scan over time. |
Recent Scans & KEV Detection | Summarizes the five most recent scan dates and the vulnerabilities identified, including Known Exploited Vulnerabilities (KEVs). |
Scanned Vulnerability Severity Trend | Shows monthly trends of vulnerabilities categorized by severity. |
Scan Coverage Adherence | Measures the percentage of assets scanned according to the defined scanning schedule. |
Engine Signature Freshness | Indicates the number of days since the vulnerability scanning engine was last updated. |
Protect - Configuration management
Capability / Widget | Description |
|---|---|
Protect | Focuses on implementing and actively managing safeguards to reduce cybersecurity risks and improve organizational resilience. |
Configuration Management | Ensures configuration management practices are defined, enforced, and monitored to maintain system integrity and reduce vulnerabilities. |
Overall Compliance Posture (KPI) | Percentage of assets requiring a HealthCheck that have a valid HealthCheck scan. |
Compliance Depth View (KCI) | Percentage of HealthCheck-required assets achieving at least 75% policy compliance. |
Non-Compliant Asset Count | Number of HealthCheck-required assets whose latest HealthCheck status is missing or expired. |
Newly Detected Non-Compliance | Number of HealthCheck-required assets with more than one finding in their latest HealthCheck scan. |
Top 10 Policy Failures | Lists the ten most common HealthCheck violations grouped by check description. |
Compliance Scan Coverage | Shows the distribution of HealthCheck scans performed automatically versus manually. |
Compliance by Platform Category | Compares operating system families against HealthCheck status. |
Unsupported Assets Overview | Displays the total number of systems that are End-of-Life (EOL) or End-of-Support (EOS). |
Device Lifecycle Breakdown | Compares EOL and EOS percentages for hardware and software assets in production environments. |
Protect - Change & Vulnerability Management
Capability / Widget | Description |
|---|---|
Change Management (Deployed) | Percentage of changes successfully deployed to production. |
Change Management (Emergency) | Percentage of emergency changes deployed to production. |
Open Changes – Age Range vs Priority | Tracks open changes by age and priority level. |
Open Changes – Category vs Priority | Shows the distribution of open changes by category and priority. |
SLA Breach – Critical Vulnerabilities | Tracks critical vulnerabilities that were not remediated before their SLA due dates. |
Critical Vulnerabilities Patched Within SLA (KPI) | Percentage of critical vulnerabilities remediated within the defined SLA timeframe. |
Patch Backlog (Pending Systems) | Number of systems awaiting patch deployment following a vulnerability scan. |
Average Time to Patch (KPI) | Average time between vulnerability identification and remediation. |
Vulnerabilities Patched by Severity | Monthly count of patched vulnerabilities grouped by severity. |
Patch Success Rate Over Time | Monthly trend of patching outcomes, such as successful, failed, or pending. |
Pending Patch Volume by Platform | Lists systems with pending patches grouped by platform. |
Vulnerabilities Patched by Time-to-Remediate Range | Categorizes patched vulnerabilities by remediation time. |
Patch Backlog by Severity | Displays outstanding vulnerabilities grouped by severity level. |
Remediation Progress Trend | Tracks monthly trends in vulnerability remediation activity. |
Known Exploited Vulnerabilities | Total active vulnerabilities detected on production devices. |
Last Scan Date | Most recent completed vulnerability scan date. |
Protect - Identity Management, Authentication and Access Control
Capability / Widget | Description |
|---|---|
Identity Management, Authentication, and Access Control | Ensures access to physical and logical assets is restricted to authorized users, services, and devices through risk-based authentication and authorization controls. |
Shared Credentials in Vault | Verifies that shared credentials are stored in a managed vault to support accountability and protect sensitive information. |
Shared UIDs in Vault (Distribution) | Shows the distribution of shared user IDs based on whether they are stored in a vault. |
UID Actions by Type & Outcome | Displays pending local user IDs by action type and outcome, such as suspensions or removals. |
Pending Local UID Removals | Number of local user IDs that remain active despite being scheduled for removal. |
Access Revalidation (KPI) – Non-Privileged UID Revalidation | Percentage of systems that have completed non-privileged user ID revalidation. |
Access Revalidation (KPI) – Privileged UID Revalidation | Percentage of systems that have completed privileged user ID revalidation. |
Access Revalidation (KPI) – Role Entitlement Revalidation | Percentage of systems that have completed role entitlement reviews. |
Access Revalidation (KPI) – Role Membership Revalidation | Percentage of systems that have completed role membership reviews. |
Asset Access Revalidation (KPI) | Measures completion of required access revalidation activities across managed assets. |
Employee Access Termination (KPI) | Measures the percentage of user IDs removed within the required timeframe after employee termination. |