Risk Score Overview

The Axonius Risk Score page offers a robust solution to assess threat levels and prioritize remediation efforts. Use this page to create multiple Risk Scores for different assets and scenarios, and to manage and edit them as needed.

The Risk Score calculation process takes into account risk, business impact, and exploitability considerations, and incorporates custom conditions and data normalization rules to allow for an accurate, transparent calculation process.

A major capability of the Risk Score module it is to calculate Risk Score across assets and vulnerabilities, namely, to calculate the Risk Score of a specific vulnerability in the context of a specific asset ("per vulnerability per asset"). For example, you can compare the risk level of specific CVEs on a laptop with the risk level of the same CVEs on a desktop or a mobile device.

From the Vulnerability Instances page, click Risk Score to navigate to the Risk Score settings page.

RiskScoreButton

Required Permissions

To create, edit and run Risk Scores, and edit Risk Score settings, the following Enforcement Center Permissions are required:

PermissionUI PageUI componentBehavior (when permission is disabled)
View Enforcement CenterRisk ScorePageCannot access page
Add Enforcement CenterRisk ScoreAdd Asset button on the left side panelCan change risk score details but cannot save
Add Enforcement CenterRisk ScoreQuick Add (+) button next to an asset item on the left side panelCan change risk score details but cannot save
Add Enforcement CenterRisk ScoreCreate a new Risk ScoreCan change risk score details but cannot save
Add & Run Enforcement CenterRisk ScoreSave and Run buttonCan change risk score details but cannot save and run
Edit Enforcement CenterRisk ScoreEdit a Risk ScoreCan change risk score details but cannot save
Edit & Run - Enforcement CenterRisk ScoreSave and Run buttonCan change risk score details but cannot save
Delete Enforcement CenterRisk ScoreDelete Risk Score option in the Risk Score Menu of each Risk Score itemCan change risk score details but cannot save
Edit - Enforcement CenterRisk Score SettingsSave button at the bottom rightCan change risk score details but cannot save

The following pages walk you through the Risk Score configuration process:

Creating a Risk Score

Viewing Risk Score Results

Previewing the Risk Score

Editing Enforcement Actions in a Risk Score