Fussion_GRC domain 5 of 15
Vulnerability Management
Govern vulnerabilities from your existing scanners by business risk, SLA and ownership. Fussion_GRC does not scan; it decides what matters.
Fussion_GRC consumes data from your existing tools. It does not perform security scanning.
- Tenable / Qualys / Rapid7Every 4–24 hours
- CMDB / asset inventoryDaily
- Threat intelligence (CISA KEV, EPSS)Daily
The problem
What problem this domain solves
Vulnerability governance is the oversight layer above scanning: it decides which findings matter most to the business, who must fix them, by when, and proves that remediation happened. Fussion_GRC does not perform scanning or penetration testing.
For the CISO
Why this matters to the CISO
Scanners produce tens of thousands of findings. The CISO's real questions are: which critical issues on critical assets are beyond SLA, who owns them, and can we prove remediation to an auditor?
The number of critical, exploitable issues beyond SLA and the trend, by business unit.
How it works
How Fussion_GRC works in this domain
Fussion_GRC consumes data from your existing tools. It does not perform security scanning. It connects to the tools that already hold vulnerabilities data, then does the following:
- 01Combines severity, exploitability and asset criticality into a business priority.
- 02Applies SLA clocks by priority and flags findings that breach them.
- 03Creates and updates tickets in Jira or ServiceNow for the right owner.
- 04Confirms closure only when the next scan no longer sees the issue.
Data in
Exactly where the data comes from
| Source tool | Data received | Typical sync |
|---|---|---|
| Tenable / Qualys / Rapid7 | Findings, CVE, CVSS, asset, first seen, last seen | Every 4–24 hours |
| CMDB / asset inventory | Asset criticality, owner, environment, data class | Daily |
| Threat intelligence (CISA KEV, EPSS) | Known exploited and exploit probability | Daily |
| Jira / ServiceNow | Remediation ticket status | Every 15 minutes |
Typical frequencies; exact intervals depend on each tool's API limits and your configuration. Connector availability varies — see integrations.
Data flow
From your tools to the boardroom
- 1. Scanner findings
- 2. Fussion_GRC
- 3. Asset criticality
- 4. SLA
- 5. Jira / ServiceNow
- 6. Evidence
Automation
Automation and workflows
Workflows created
- Scanner → Fussion_GRC → asset criticality → business risk → SLA → Jira/ServiceNow → evidence → CISO dashboard → board report
- SLA breach → escalation to owner and manager
- Exception request → risk acceptance → expiry review
Actions for leaders
- Approve exception requests
- Escalate critical findings beyond SLA
- Review assets missing from scan coverage
Controls & evidence
Controls and evidence
Controls are defined once and mapped across frameworks. See supported frameworks.
Controls
- Vulnerability management policy with SLAs
- Scan coverage of all in-scope assets
- Remediation within SLA
- Risk acceptance for exceptions
Evidence generated
- Scan coverage report
- SLA compliance trend
- Verified remediation records
- Approved exceptions with expiry
AI assistance
How Fussion AI helps
Answers come from your own Fussion_GRC data, with sources. Learn about Fussion AI.
Questions you can ask
- "Which vulnerabilities have exceeded SLA on critical assets?"
- "Draft a remediation request for the infrastructure team."
- "Which known exploited vulnerabilities are still open?"
- Thousands of findings with no business context about which assets matter.
- SLAs defined in policy but not measured in practice.
- Tickets raised manually and closed without proof of the fix.
Every point links to its source record. Recommendation only — a named owner approves decisions.
Dashboard
Dashboard example
Roles
Who uses this domain
CISO
Scanners produce tens of thousands of findings. The CISO's real questions are: which critical issues on critical assets are beyond SLA, who owns them, and can we prove remediation to an auditor?
CIO
Sees how vulnerabilities affects IT services, investment priorities and the systems the business depends on.
Security Manager
Runs day-to-day vulnerabilities operations from one queue instead of separate tool consoles.
GRC Manager
Maps vulnerabilities controls to frameworks, tracks evidence freshness and prepares audits.
Control Owner
A prioritised list of findings on their assets, with SLA dates and linked tickets.
Auditor
Policy, scan coverage, SLA performance and verified remediation evidence.
Technical Owner
Receives specific, prioritised tasks in Jira or ServiceNow with the context needed to fix them.
Executive
The number of critical, exploitable issues beyond SLA and the trend, by business unit.
Integrations
Tools you can connect
- Tenable
- Qualys
- Rapid7
- Microsoft Defender
- Wiz
- Jira
- ServiceNow
Named tools show typical sources; availability may be planned, roadmap or custom connector. Confirm during a demo.
See all integrationsOutcomes
Business outcomes
Example
Example workflow
- 1System
New signal from Tenable / Qualys / Rapid7
- 2Fussion_GRC
Combines severity, exploitability and asset criticality into a business priority.
- 3Control owner
Scanner → Fussion_GRC → asset criticality → business risk → SLA → Jira/ServiceNow → evidence → CISO dashboard → board report
- 4GRC manager
Evidence attached: Scan coverage report
- 5CISO
Approve exception requests
FAQ
Frequently asked questions
Does Fussion_GRC scan our network?
No. Fussion_GRC never scans. It reads results from the scanners you already use and governs the response.
How is closure verified?
A finding is marked remediated only when the next scanner result no longer reports it, not just when a ticket is closed.
Does Fussion_GRC scan our environment?
Fussion_GRC consumes data from your existing tools. It does not perform security scanning.
