Once a vulnerability compensating control has been created, it must be added to a vulnerability to have an effect. Vulnerability compensating controls can be added from a vulnerability's Vulnerability Compensating Controls tab by a user with the Threats and Vulnerabilities View and Update permissions.
To add a vulnerability compensating control to a vulnerability:
Open the Vulnerabilities menu.
- Click any page, such as My Vulnerabilities, Vulnerabilities from Scanners or Users, or Inferred Vulnerabilities.
- Click a vulnerability.
- Click Comp Controls to open the Vulnerability Compensating Controls tab.
- Click Add.
- In the left window, click + next to each category you wish to open and click the checkbox next to each vulnerability compensating control you wish to add to the vulnerability.
- Click >> to add the selected vulnerability compensating controls to the right window.
- Click Next.
- Enter the initial Detection % and Protection % for each of the vulnerability compensating controls. These values can be changed later. The sum of a single vulnerability compensating control's fields cannot exceed 100%. However, the total sum of all compensating controls may exceed 100%.
- Click Finish.