TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

Tenable.io

Estimated reading: 3 minutes 2431 views

Set up Tenable.io for automated tests with TrustCloud

Purpose

Once you set up your compliance program, TrustCloud TrustOps works to ensure that your systems remain compliant with your adopted controls. To do so, TrustCloud runs automated tests against systems in your product and business stack, and verifies that they are properly configured.
This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your Tenable.io account, so that TrustOps can validate and generate evidence for your compliance program.

Instructions to grant TrustCloud limited access to Tenable.io

  1. Log in to your organization Tenable.io account to generate API tokens.
  2. Click the User profile icon from the upper right corner. Navigate to the My Account page from the user account menu options.
  3. Navigate to the API Keys page by selecting API Keys from My Account page.
  4. Within the API Keys tab, click Select. This will bring up the Generate API Keys window with a warning.
    Caution: Any existing API keys are replaced when you click the Generate button. You must update the applications where the previous API keys were used.
  5. Review the warning and click Generate. Tenable.io will then generate a new set of access and secret keys which will be displayed in the Custom API Keys  section of the page.
  6. Copy the new Access Key and Secret Key & provide it to TrustOps.

For additional details, you can refer to the Tenable.io documentation to generate API keys.

Data feeds

Types of control testing that TrustCloud enables with EntraID:

  1. Vulnerability Scanning

To automate the continuous monitoring of these controls, TrustCloud pulls the following sample of data feeds from Tenable:

  1. Assets
  2. AssetList
  3. Vulnerabilities
  4. VulnList

A sample of read-only data elements we pulled from these data feeds.

Read only: Assets
   - record
   - Application
   - CIID
   - name
   - ipv4s
   - hostnames
   - last_seen
   - last_scan_time
   - operating_system
   - last_authenticated_scan_date
   - Last_licensed_scan_date

Read only: AssetList
   - asset_uuid
   - hostname
   - ip_address
   - OS
   - last_seen
   - Last_authenticate_scan_date
   - plugin_version
   - scanner_id
   - policy_id
   - schedule_frequency
   - schedule_interval
   - schedule_starttime
   - schedule_timezone
   - plugin_update_date

Read Only: Vulnerabilities
   - record
   - application
   - CIID
   - host
   - name
   - ipv4s
   - first_found
   - pluginName
   - pluginSynopsys

Read only: VulnList
   - vuln_id
   - asset_uuid
   - plugin_id
   - Plugin_name
   - cve-id
   - severity
   - severity
   - status
   - first found
   - last found

Join the conversation

You might also be interested in

Duo

This document outlines the steps you can take to grant TrustCloud access to only...

Google Cloud Platform

This document outlines the steps you can take to grant TrustCloud access to only...

Bitbucket

Instructions to grant TrustCloud read-only access to your Bitbucket organization...

Hybrid Data Fabric

The Hybrid Data Fabric is a built-in connector between your TrustCloud and an external...

Okta

Set up Okta for automated tests with TrustCloud! This document outlines the steps you...

ServiceNow

Set up ServiceNow for Ticket as Evidence with TrustCloud! This document outlines the steps...

Jira Cloud

Set up Jira Cloud for Jira Ticket as Evidence with TrustCloud! This document outlines...

AWS

This document outlines the steps you can take to grant TrustCloud access to only...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue