Overview
You can manage POA&M information for one or more findings with Nucleus using the user interface.
Single instance updates
A single finding can be updated from the Instances tab on the vulnerability summary page. Select Instances > Click to select an instance checkbox > POA&M Tracking..png)
The click path is shown in the previous screen shot denoted by red boxes. To update one or more fields, select the appropriate drop down for the field you want to change and click Save. You can also update the Service Names field using a text box. Planned Milestones can be updated but existing saved milestones cannot be removed. The Display ID field can be updated for a particular instance as well.
Note that if multiple Display ID fields have the same value, they will be grouped together on the same row when the POAM Continuous Monitoring Report is generated. Grouping logic is further defined in the section entitled Generate ConMon (Continuous Monitoring) Report
Multi-instance Updates
Multiple findings can be updated from the Instances tab on the vulnerability summary page. Select Instances > Click to select one or more instances > Set POA&M Fields. Note that the checkbox at the top of the column can be used to select all findings if desired.
.png)
The click path is shown in the previous screen shot denoted by red boxes. To update one or more fields for the selected findings click Set POA&M Fields which opens a drawer menu as shown in the following screen shot:
Set POA&M Fields Drawer Menu
.png)
Use the drop-down menus or text fields to update the selected findings with new POA&M values. Note that updates to Planned Milestones will be appended. Click Save to complete the updates. When the update has successfully completed you should see a toast message as follows:.png)
Note that a maximum of 500 findings can be updated at once using the Set POA&M Fields menu.
To group multiple POA&Ms together in the exported spreadsheet you can use the Display ID field and enter an ID of your choice. POA&Ms with the same Display ID will appear as a single row in the exported POAM Continuous Monitoring Report. Grouping logic is further defined in the section entitled Generate ConMon (Continuous Monitoring) Report