Asset risk and criticality
runZero helps you assign and evaluate risk and criticality levels for the assets in your inventory. With those levels set, you can spot the assets in your organization with the highest risk or criticality at a glance and prioritize risk mitigation or vulnerability remediation around them.
Defining risk and criticality
runZero assigns the risk level automatically, inferring it from the risk of the vulnerabilities or risky configurations on the asset; it defaults to none. A vulnerability’s risk level may come from the vulnerability management solution its records were ingested from, or from the risk level assigned to a query vulnerability. You can override the risk level, and the override stays until the asset or vulnerability is deleted. For vulnerabilities ingested from integrations, deletion may happen when the source no longer reports the vulnerability on that asset.
You assign the criticality level manually; it defaults to unset. Criticality denotes how important an asset is to your organization. For example, you might give business-critical systems such as database and web servers a critical level and normal end-user systems a medium level.
Assigning asset risk and criticality
You can assign both asset risk and criticality from the asset inventory. Alert rules can also assign criticality.
Superusers, administrators, and users can add or modify asset risk and criticality levels, reset a risk assignment, and remove a criticality assignment from assets.
Risk and criticality in the asset inventory
To set risk and criticality through the asset inventory:
- Select the assets you want to update, applying a query filter if needed.
- Click Modify asset risk or Modify asset criticality to open the popup.
- Select the level of risk or criticality to apply to the selected assets.
- Click Override risk or Set criticality to apply your changes.
Applying criticality with rules
To apply asset criticality automatically after each scan, create an alert rule: go to Alerts > Rules and click Create rule.
- Select the inventory query to use, such as the
asset-query-resultsrule type, then click Configure rule. - Configure any settings you want.
- Set the Action to Modify asset.
- Select an option from the Asset criticality menu.
- Save the rule.
When a scan completes, the rule adds the specified criticality level to every asset that matches it.
Asset risk report
The Asset risk report shows the risk and criticality levels across your asset inventory. To run it, go to Reports > Asset risk report, click the Asset risk report button, and configure these fields:
- Sites: Select a site of assets to include in the report, or leave the default All Sites.
- Minimum risk: Choose the lowest asset risk level to include.
- Minimum criticality: Choose the lowest asset criticality to include.
- Top vulnerabilities per asset: Set an integer between 0 and 20. With a value from 1 to 20, the report lists up to that many of the top vulnerabilities detected on each asset. runZero picks them by sorting each asset’s vulnerabilities by risk rank, then risk score, then severity rank, then severity score.
- Click Create report to generate the results.
The report is grouped by asset criticality level and then sorted by risk level. You can export the results as JSON Lines (.jsonl), a JSON document (.json), or CSV (.csv).