Forum Discussion
Tenable product update: Standardizing Tenable risk scoring
Hi,
The new VPR model is already available in Tenable Security Center (on-prem) as VPR (Beta). With this update, the beta label is expected to be removed and the same model is expected to continue as the standard VPR. Therefore, on-prem Security Center customers are also expected to continue benefiting from the updated VPR scoring.
Thanks for your response.
Could you please guide me where to find the VPR (Beta) cause I search for it but didn't find anything the least feature I have in my security center is the Asset Explorer my Security Center version is 6.8 which I believe it's the latest update.
Thanks again.
- metehanefe1 month agoConnect Contributor III
Hi,
You can view the VPR (Beta) score by using the search bar located in the upper-right corner of Security Center. Simply enter the relevant CVE value.
From there, you should be able to see both the VPR and VPR (Beta) scores, including the metrics used to calculate them, as well as the historical score changes.
- aamin1 month agoConnect Contributor II
Thank you very much — I was able to find it.
I was actually looking into Asset Criticality Risk (ASR), since cloud security platforms provide the ability to assign risk scores based on the importance of hosts or assets. This is something that on-premises solutions currently lack, and I was hoping this new feature might address that gap.
At the moment, Tenable on-prem scoring isn’t very meaningful in this context. For example, it may assign a vulnerability a CVSS score of 10 without considering the nature of the host itself. If the affected system is just a development server isolated within a VLAN, treating it as a critical risk doesn’t really make sense.
Additionally, attempting to recast the risk applies the change across all vulnerabilities and all hosts, which is not an efficient or practical approach.
In any case, thank you again for your support and response.
- metehanefe1 month agoConnect Contributor III
Hi,
You are absolutely right in your point.
In the on-premises Tenable Security Center+ offering, the Asset Criticality Rating (ACR) capability is available. ACR allows assets to be evaluated based on their relative business criticality, which may help address the use case you described.
In this context, Security Center+ could be evaluated as a possible option to better reflect the importance of the affected asset in risk prioritization.
Thank you again for sharing your feedback.