SecBytes (S2E4) : Create a custom CISA Table for Vulnerability Response
[Music] hey everyone chris walker your security doctor back again with a quick tool tip on creating a custom table and importing a catalog of known vulnerabilities from sisa.gov now i've had a couple of colleagues and some customers ask me about this like how can i demonstrate it well it's pretty easy to import and generate a visual report which can be actually added to performance analytics so let's go ahead and get after it alright so today's objective is to create a custom table import the data and then visually represent where these vulnerabilities live and breathe as it pertains to the products the vulnerability name cve id and some other areas that cesa.gov is going to provide us within that known vulnerability catalog so for today's discussion we're going to be focusing on vulnerability response from a performance analytics perspective creating that custom sisa table and then visually representing that in a simple pie chart so let's go ahead and get right into my instance so as you can see here i'm in my instance san diego release let's go we are excited to be here but first and foremost let's go ahead and break this down into five simple steps yes five steps will get you exactly what you need first and foremost step one we're gonna head over to the application navigator and we're to type in tables specifically we're looking at the tables under system definition so let's click on the tables option now the second step is to enter the appropriate fields on the form now you'll see we have a list of different tables we need to now go ahead and create a new custom table that's going to represent the imported data from sisa.gov so i'm going to go ahead and name this csa known vulnerabilities and notice because i'm in a scoped application it automatically adds the priests prefix of sn vul if i was in a global application scope then it would be represented differently but make sure because we're trying to harden those security controls make sure you're in the right scoped application so this table is accessible for those users and for those roles so now that we have that done everything else is ready to rock and roll here we can go ahead and hit submit and what's going to happen now is when we hit submit it's now going to show us a couple of different columns that have been pre-populated for us to start gathering this information that we're going to be importing now what that looks like is a little something like this here i have my known sisa vulnerabilities table and i have actually already populated some of the different column labels that are going to be required in order for me to match that excel workbook spreadsheet that i'm going to be importing so if you'll see here again we're doing this step by step step three is to navigate to your import source here we can download this information from the catalog so you see here i can download the csv version then when i go back to my table i can actually import this information now one caveat which i'll pop up over here is that we are not able to actually import the csv here in this particular instance we can only import an xls or xlsx workbook so make sure you convert that and save as the excel workbook but once that is done i'm gonna go over to show the list of records which in this case there are no records because step four is to do the actual import so let's go ahead and do that i'm excited so we're going to right click on the first column we're going to click on import and then you have a series of options we're not going to create an excel template because we already have the data we're simply going to choose the file and you'll see here it is in my downloads as an xlsx excel workbook i'm gonna open it and with a matter of seconds here we're gonna have all this relevant information imported into our known vulnerabilities table so five seconds a little long let's go ahead and preview the imported data we can see all of those records have been represented and captured we're going to scroll to the bottom to complete step 4 which was completing the import the last step step 5 is to right click on this particular table in this case we're going to click on the top column and we're going to select the pie chart because again we want to create that visual representation for our cio or our cso so here we can see our pi in the sky it's got a lot of different um vulnerabilities and cves being represented in this table i actually want this to be represented in a couple different ways so we're going to group by not only the cve id but we're also going to look at products if there's a required action vendor project and the actual name of the vulnerability so we'll move that up to the top here and then i'm going to click ok now i'm also going to change the name of this because that is way too long so let's call this the sisa known vulnerabilities and now i'm going to go ahead and hit save now notice what's going to happen is it's going to now go ahead and give me a group by drop down option so now if i wanted to see this by product i can see all the products that are impacted by those vulnerabilities or if i wanted to see this based on vulnerability name i can simply see that diced out through a pie chart by vulnerability names so now that i have this saved i'm going to save it again because i love to save we're now going to go ahead and add this to our performance analytics dashboard so when i click on the sharing button i have the ability to share schedule but here i'm going to add this to an existing dashboard so i'm going to go ahead and add this to my vulnerability management or cso dashboard it's really entirely up to you on where you want to represent it i'm going to put this on the cso dashboard and i'm going to put this under the overview page now when i click add it is now going to add that to the overview page and it's actually going to now populate that specific dashboard to show me the actual dashboard in question so now here i can see all of the information visually represented in a mere matter of just a few minutes and a few clicks i now have the information i need to be successful as a vulnerability analyst as always thank you so much for allowing me to do what i do and as always stay safe
https://www.youtube.com/watch?v=csvD02c0qzE