Monitor Risks
A Monitor risk originated from vulnerability monitoring — including risks ingested via xZETA or VicOne integrations, or created manually from a CVE or threat feed. The origin is a label and does not change how the risk is scored — all scoring is driven by evidence and controls via the evidence model.
Monitor risks are usually raised from a Beacon finding — either automatically (a flagged BOM country of origin) or by triaging an item in the VSEC Monitor tool (a matched external signal, raised as a new risk).
Evidence and Weakness State
Monitor risks accumulate Monitor evidence items. Each item carries:
| Field | Description |
|---|---|
| Source | Monitor |
| Summary | Description of the vulnerability or finding |
| CVSS score | Used to derive the Likelihood dial |
| Reference (CVE / report id) | External identifier (e.g. a CVE number or report id) — an identifier, not a link |
| Clause-8 weakness state | Event, Weakness, Vulnerability, or Not Applicable |
The Clause-8 weakness state records where the finding sits on the ISO/SAE 21434 Clause-8 triage path — from raw event to confirmed vulnerability. It can be advanced manually on the evidence item or via Suggested actions on the Context tab.
Controls
Link Control Library entries to the risk from the Risk tab to drive down the residual score.
Legacy Vulnerability Info Fields
Risks created before the evidence model migration may still carry flat Vulnerability Info fields — general description, recommended mitigation, vulnerability ID, threat intel link, event evaluation, vulnerability analysis, vulnerability management. These fields are preserved for back-compatibility, but they no longer appear on the Risk tab — they are visible only in revision-history snapshots (open an entry on the Activity tab). One exception feeds scoring: when no evidence item carries a CVSS score, the legacy Monitor CVSS score is used as a fallback.