The Global Overview Metrics view will display high-level data, including the total number of companies and assets, percentage breakdown of vulnerabilities by severity, and total risk score across all companies.
Global Metrics - Table of Contents
Global Metrics - Overview
The Global Metrics view will display data like Severity, Risk Score, Asset(s), and Companies. in the top or header section of the view.
Total vulnerabilities by severity (Critical, High, Medium, Low) across all companies and assets
Average Risk Score across all assets for all companies
Total count of Assets across all companies
Total count of Companies
The second half of the view contains the Company Overview data, which includes:
You can click down to see the underlying data for any of the values listed in the Company Overview.
Global Metrics - Details
Company Overview Details
Company Name = displays the company's name as listed in ConnectSecure
Asset Count = total count of all assets for the company
Asset Risk Score = MAX weightage achieved * 100 as a percentage (Asset Type = Discovered)
Vulnerability Risk Score = MAX weightage achieved * 100 as a percentage
AD Risk Score =MAX weightage achieved * 100 as a percentage
PII Risk Score = pending details
External Scan Risk Score = MAX weightage achieved * 100 as a percentage (Asset Type = External)
Average Risk Score = pending details
CIS Score = Non Compliant controls count multiplied by the number of Assets
PCI-DSS Score = Non Compliant controls count multiplied by the number of Assets
HIPAA Score = Non Compliant controls count multiplied by the number of Assets
NIST-50083 Score = Non Compliant controls count multiplied by the number of Assets
Cyber Essentials Score = Non Compliant controls count multiplied by the number of Assets
ID = displays the Agent ID from the ConnectSecure database; not configurable
NOTE: Click on the column editor icon to add/remove and rearrange the column headers.
Once you have your columns the way you like them, tap the Save Settings icon to keep these moving forward.
Global Metrics - Action Toolbar Overview
The Action toolbar provides a set of actions you can take to change the system's global settings. This toolbar should be docked on the right and always visible. It includes system-built-in actions.
Companies - this includes the following functions:
New Company - Create local or PSA-connected companies in the v4 portal.
Delete Companies - select a company for deletion from the v4 portal (all data is removed).
Companies - view a list of all your companies in the portal; click through to access company info
Integrations - access the list of supported API integrations.
Application Baseline - access the application baseline rules configurations.
Tags - tap manage the global level tag rules; add, edit, and delete
Global Settings - tap to view a listing of all the global settings affecting all companies.
Users - this includes the following functions:
Profile redirects to the user management front end (ZITADEL Console), where you can manage user accounts, passwords and security, identity providers, authorizations, memberships, metadata, and more.
User Management - redirects to the user management front end (ZITADEL Console), where you can manage user accounts, passwords and security, identity providers, authorizations, memberships, metadata, and more.
Plan - displays the Current Plan for your deployment, pricing, and a breakdown by Company/Asset and Accrued Cost.
Search - tap to use the global CVE search.
Alerts - displays the System Event (alerts) in a timeline-style format.
Alerts - tap to view the System Events in a timeline style for all companies.
Info - tap to see the ConnectSecure Getting Started Info.
Help-Link - tap to view the corresponding documentation page.
Action Toolbar Details
You can change your UI look and feel using the settings menu in the corner:
THEME- you can toggle between the different color palettes displayed in the v4 portal by clicking
SCHEME - you can toggle between DARK and LIGHT mode by clicking
LAYOUT - you can toggle between the different UI options and where the v4 portal is laying out the top/side navigation toolbar options by clicking
Align Dynamic Settings - choose either left or right to display the content toolbars
Companies
New Company
You can create a new company for the v4 portal here. Under the Choose Mode, you can select 'Local' or 'PSA Companies' to create a new option.
NOTE: Using a supported PSA, you can choose your system and import/map companies one or multiple at a time.
Click the Save button once you have completed all required and optional fields.
After successfully saving, you'll receive a confirmation message in the top-right corner. You will then be automatically redirected to the newly created company's 'Overview.'
Delete Companies
You can delete an existing company from the v4 portal from here.
Select the target company from the drop-down and then click the Delete button.
You will be prompted one final time before the record is removed from the v4 portal.
A confirmation message will appear to confirm a successful delete
If you encounter any errors during this process, please take screenshots of any error messages and send them to our ConnectSecure Support Team by emailing support@cybercns.com.
Companies
Tap here to view all the companies in your portal. This includes the Company Name, ID, and Create On Date.
Click on the Company Name to be redirected to the selected companies data.
Integrations
Access the API integrations menu. Tap on a tile to configure/manage the settings. Each integration has its own unique set of credentials and configuration options. Please refer to the integration-specific guide for a step-by-step explanation.
Integration Guides by Category
Check out our dedicated page here for supported API Integrations:
App Baseline
Tap here to Add, Edit, or Delete the Tag Rules across all companies.
Tags
Tag Rules enable the user to input search criteria, which scan all assets and apply tags based on the criteria.
Field | Description |
---|---|
Name | Give the tag rule a name of your choice |
Risk Score | Enter a risk score if you want to modify the risk score of any asset where this rule matches. If you do not want to change the risk score, enter zero (0). |
Collection | Select the Collection which organizes the tags by Assets, Ports, and Problems |
Description | Give the tag rule a description of your choice |
Rules | Used to build a search query with specific search criteria; the rule will check all assets for a match and apply the specified tag(s) |
Tags: Name | Give the tag a name of your choice |
Tags: Value | Give the tag a value of your choice (string or integer) |
Example!
Add New Tag Rule
Tap the Add button to create a new tag rule.
Complete all the required fields which include Name, Risk Score, Collection, Description, and the Name/Value for the actual tag. You will also need to specify the Rules section which includes a boolean for AND/OR with different field selections.
Edit or Delete Tag Rules
You will see any of the existing tag rules in the table view, where you can use the three-dot action menu to Edit or Delete.
Tag rules would be applied within a few minutes and can be verified under assets information.
Global Settings
Here, you will find general global-level settings.
They can be accessed from the Global Overview or Global Metrics page.
Timezone Settings
Set your timezone by selecting from the drop-down and tapping the save button.
Custom Date Format
Set your date format by selecting from the drop-down menu and tapping the save button.
Session Timeout
Set the time (in minutes) for the session timeout to occur. This includes the Idle, Wait, and Logout intervals.
Ports Policy
Specify Insecure, Denied, Excluded, and/or Allowed Ports.
Allowed ports, denied ports, and insecure ports are used for flagging the information on the report card. When you add the port number, this will still scan the ports for vulnerabilities. You can use the exclude port option to exclude the ports from scanning.
Deprecation Days
Set asset and/or Agent deprecation days as well as your Suppress Vulnerabilities days
White Label Settings
Set the logos to be used for both dark and light modes. You can also edit the display name of the application the browser tab, along with the footer content.
EDR Application
The Global EDR applications contain the list of antivirus applications shown in the security report card for the respective assets. Any application not listed as antivirus under Global EDR applications can be added here. Please run a scan after adding it to reflect the application name in the security report card of the respective asset. To Exclude any application from the Global EDR applications list, please click on the 'X' for the selected application.
Backup Software
The Global Backup Software contains the list of Backup Software shown in the security report card for the respective assets and also reflects as compliant for the asset under the Essential Eight Backup Software Compliance rule.
Any Backup Software that is not already listed under Global Backup Software can be added here. Please run a scan after adding it here to reflect the software name in the security report card for the respective asset.
To Exclude any of the Backup Software from the Global Backup Software list, please click on the 'X' for the selected software.
Compliance Scan
Set the Compliance types to be scanned here. Only the selected options will be activated when running compliance scans. This will reduce the time it takes to complete and the load on the scan agents.
LW Agent Scan Interval
Configure the scan interval for the lightweight agent(s). Choose from 15, 30, 60, 90, or 120 minutes.
Patching Status
Enabling patching status is required to enable the patching engine and configure options.
Custom Domain
Requires a DNS (A-Record) for Domain Name with IP Address 65.20.101.254
Provide your desired Domain Name and upload your SSL Certificate and SSL Private Key files. Optionally, you can include any Allowed IPs.
You can tap on our ‘how to links’ for the various SSL providers.
SSL Provider | Link |
---|---|
AWS | |
Bluehost | |
Cloudflare | |
Go Daddy | |
Google Domains | |
Namecheap | |
Network Solutions |
Exclude Component(s) from Security Report Card
Select your options for excluding the options showing on your security report card.
Security Report Card shows up in the Dashboard, Standard Reports, and Agent views.
Custom Report Cover Page
Upload your own custom DOCX file to use with any of the Company Standard Reports.
Select a company option. You can select All Companies or specific(s) from the list.
Tap the Choose File button to upload your DOCX file.
We can only customize Report Name {{reportName}} and Company Name {{companyName}}
Once the DOCX file is uploaded successfully, you can run any standard report, and the cover page will display.
Anti Ransomware
The Global Anti-Ransomware contains the list of antivirus applications shown in the security report card for the respective assets. Any application not listed as Global Anti-Ransomware can be added here. Please run a scan after adding it to reflect the application name in the security report card of the respective asset. To Exclude any application from the Global Anti-Ransomware list, please click on the '->' for the selected application.
Global Table Setting
Set the default font size and items per page globally.
Firewall
The Global Firewall contains the list of firewall options shown in the security report card for the respective assets. Any application that is not already listed as antivirus under Global Firewall can be added here.
Please run a scan after adding to reflect the application name in the security report card of the respective asset.
To Exclude any application from the Global Firewall list, please click on the '->' for the selected application.
Users
Profile
It redirects you to the external auth site where you can manage your user profile settings in Zitadel.
https://authprod.myconnectsecure.com
User Management
Manage the users within your v4 portal. You can Add new users, Edit existing ones, and Delete users from here. Our standard search, refresh, filter, tag, column chooser, download, and save buttons are at the top of the Users panel.
Add New User
Tap the Add button to create a new user for the v4 portal. When selecting the Role for the User, there is an option to Allow or Deny a user access to specified Companies. This option will only appear if the Role is something other than Admin. By default, Admin will have access to All Companies, which can not be changed.
Security Roles Matrix
We have a dedicated page for users and security found here:
Here are the default Roles with their default Permissions.
In the previous version of ConnectSecure, we had a role called ‘ITADMIN’, which is no longer available.
To grant ITADMIN access similarly in V4, you should assign the following roles:
ASSETWRITER
VULNERABILITYWRITER
COMPLIANCEWRITER
ACTIVEDIRECTORYWRITER
Edit Existing User
Tap the three-dot Action menu next to any existing user to edit them and change their security Role.
Select the new Role and tap Update; otherwise, click Cancel to back out.
Delete Existing User
Tap the three-dot Action menu next to any existing user to Delete the User.
Click the red Delete button to confirm deletion; otherwise, click Cancel to back out.
Plan
View a detailed breakdown of your agent deployment's current plan, including pricing and costs accrued by company/asset.
Search
This is a CVE search that allows you to search a specific CVE through the system.
Alerts
To view the changes and updates in the System Events, you can use the timeline style.
Info
Tap here to view your V4 Getting Started Info.
https://cybercns.atlassian.net/wiki/x/MIDKfw
Help Link
Tap to view the corresponding documentation page; this link works across all screens.
Need Support?
Contact our support team by sending an email to support@connectsecure.com or by visiting our Partner Portal, where you can create, view, and manage your tickets.
https://cybercns.freshdesk.com/en/support/login