Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Note
Home > Armor Complete - Product User Guide > Vulnerability Scanning

...

Topics Discussed

Table of Contents
maxLevel3
minLevel3
Note

To fully use this screen, you must add the following permissions to your account:

  • Read Compliance

  • Write Compliance

Use the ASV Vulnerability Scanning add-on product to meet compliance requirements and review potential issues discovered by the scans.  

You can order the following the following add-on products:

  • Navis

    HIPAA Vulnerability Scans

  • Navis

    PCI Vulnerability Scans

  • Navis

    PCI + HIPAA Vulnerability

    Scans 

    Scans

After you order the the ASV Vulnerability Scanning add-on product, you can use the ASV Vulnerability Scanning Scanning screen in the Armor Management Portal (AMP) to:

  • View the status of the vulnerability scan

  • Upgrade or downgrade your service

  • Access the

    Navis

    CoalfireOne portal to schedule a scan


Anchor
Order-Vulnerability-Scanning-for-Compliance
Order-Vulnerability-Scanning-for-Compliance
Order ASV Vulnerability

...

Scanning

...

  1. In the Armor Management Portal (AMP), in the left-side navigation,

...

  1. click Marketplace.

...

  1. Locate and

...

  1. select Coalfire Vulnerability Scanning.

  2. Locate the desired add-on product, and then

...

  1. select Choose This.

...

...

  1. Click Purchase.

...

  1. A ticket will be automatically created and sent to Armor Support. To see the status of this ticket, in the left-side navigation,

...

  1. click Support, and then

...

  1. click Tickets

...

  1. . Armor will use this ticket to communicate with you about the status of your order and to inquire about your specific configuration requests.

...

    • When the product has been fully provisioned, you can view the

...

    • Vulnerability Scanning screen in AMP for detailed information.

...


Anchor
Upgrade,-downgrade,-or

...

-cancel-a-vulnerability-scanning-option
Upgrade,-downgrade,-or

...

-cancel-a-vulnerability-scanning-option
Upgrade,

...

Downgrade, or

...

Cancel A Vulnerability Scanning Option

...

Note

When you downgrade or delete cancel a vulnerability scanning option, the changes will take place at the end of the billing cycle.  

When you upgrade, the changes will take place immediately.  Your Your next bill will be pro-rated to reflect this upgrade.

CoalfireOne portal access will revert to read-only after cancelling Vulnerability Scanning for Compliance. Read-only access will allow users to download past reports. It is recommended that users download past reports immediately, as the data is not retained indefinitely.

Prior to cancelling, it is recommended that users cancel scheduled scans. Canceling scans prevents users from getting unnecessary notifications.

  1. In the Armor Management Portal (AMP), in the left-side navigation,

...

  1. click Security.

  2. Click Vulnerability Scanning.

...

  • To remove an option, select Remove Service

...

  1. Click Compliance.

    • If you do not have the vulnerability scanning add-on product, then click Order in the Marketplace.

  2. Click the gear icon, and then select the desired option:

    1. To upgrade or downgrade, select the Change Service icon, click Choose This, and then click Purchase.

    2. To delete, select the Remove Service icon, and then click Remove Vulnerability Scanning.


Anchor
Access-Coalfires-Navis-Portal-and-Schedule-a-Scan
Access-Coalfires-Navis-Portal-and-Schedule-a-Scan
Access CoalfireOne Portal and Schedule A Scan

...

You must use the CoalfireOne portal to schedule a scan.

...

  1. After you purchase an add-on product, you will receive an email with login information for Coalfire. Open the email, and then copy the login information. You will need this information to enter the Navis Portal.

  2. In the Armor Management Portal (AMP), in the left-side navigation,

...

  1. click Security.

...

  1. Click Vulnerability Scanning.

...

  1. Click Compliance.

  2. Click

...

  1. Log into Navis Portal.

  2. Use the login information from the email to access the Navis Portal.

...

  1. Under Projects, click the applicable project name (you will have three different projects, and some/all will be active depending on which offering you are subscribed to).

  2. In the selected project, click the Setup menu item.

  3. Above the list of previously-scheduled scans, click the Add button.

  4. Under the Scan Details tab, complete the empty fields, including Name and Frequency.

  5. Click the Targets tab.

  6. Above the list of previously-added targets, click the Add Existing Target button.

  7. Mark the desired IP addresses, and then

...

  1. click Add.

...

...

  1. Click the Save button.


Anchor
Resyncing-Scan-Targets-Between-AMP-and-Coalfire
Resyncing-Scan-Targets-Between-AMP-and-Coalfire
Resyncing Scan Targets Between AMP and Coalfire

...

As you assign or unassign IP addresses to your virtual machines, those which remain assigned are made available within the Coalfire Navis portal as potential scan targets. Normally, such changes are immediately available within Coalfire, but this can occasionally fail. In the event you are missing scan targets, you can attempt to remediate this by performing a manual synchronization between AMP and Coalfire:

  • In the Armor Management Portal (AMP), in the left-side navigation, click Security.

  • Click Vulnerability Scanning.

  • Click Compliance.

  • Click the gear icon, and then select Resync Targets (this option is only displayed if there is at least one unsynced scan target)

If you attempt the above steps yet still have issues with scan targets appearing missing within Coalfire, please create a ticket with Armor Support for additional assistance.


Learn More About CoalfireOne

...

The CoalfireOne platform is Coalfire's newest offering, which incorporates several improvements to their current scanning & assessment experience. To learn more about how to use those new functions, please watch the training videos available on our CoalfireOne Portal Training page.


Related Documentation

Armor Marketplace

Vulnerability Scanning

Vulnerability Scanning Exclusions