11. Configuring NESSviewer
The Options page has six tabs: Severity, Business Rules, Analysis, AI, Reference Data and Application. Everything saves itself as you change it — the page says so at the bottom: Settings are saved automatically. Nothing here requires a restart.
11.1 Severity
Section titled “11.1 Severity”These settings decide how NESSviewer rates a finding, which in turn drives the Dashboard counts, the report severities and the POA&M aging rules.
Which severity the counts use
Section titled “Which severity the counts use”| Setting | Default | What it does |
|---|---|---|
| Use DOD Severity for counts | Off | Off, counts use the severity Nessus assigned (Critical / High / Medium / Low). On, they use the DOD severity NESSviewer calculates. This is what renames the Dashboard tiles. |
How the DOD severity is worked out
Section titled “How the DOD severity is worked out”The section carries the on-screen explanation: How the calculated DOD Severity is derived from the Nessus severity, STIG severity, and CVSSv3 score.
| Setting | Default | What it does |
|---|---|---|
| Use CAT I / II / III labels | Off | On, the tiers are named Very High, CAT I, CAT II, CAT III, Information. Off, they are Very High, High, Moderate, Low, Information. Labels only — nothing is recalculated. |
| Treat Very High as High | Off | For organizations that do not recognise a Critical tier: a Critical finding becomes High (CAT I) instead of Very High. |
| STIG severity | Only when highest | Never ignores the STIG severity. Only when highest uses it when it outranks the Nessus or CVSS rating. Always lets it override, even over a Critical. |
| Use CVSSv3 score instead of Nessus severity | Off | Bases the severity on the CVSSv3 band — 9.0–10.0 Critical, 7.0–8.9 High, 4.0–6.9 Medium, 0.1–3.9 Low — instead of the rating in the scan. Findings with no CVSSv3 score fall back to the Nessus severity. |
11.2 Business Rules
Section titled “11.2 Business Rules”Business rules are the standards your scans have to meet. A scan that fails one is flagged Issues on the Files page and in the Dashboard’s Scan Information tab, and is counted in the Policy violations tile. The section explains itself on screen: Flag loaded scans that don’t meet policy… Changes apply immediately.
| Rule | Default | Flags a scan when |
|---|---|---|
| Require all ports | Off | The scan policy did not cover the full port range — anything other than All, 0-65535 or 1-65535. Turn this on if your policy requires full-range scanning. |
| Maximum scan age | Off, 90 days | The scan is older than the number of days you set. The number box is greyed out until you switch the rule on. |
| Scan / plugin date gap | Off, 5 days | The scan date and the plugin feed date differ by more than the number of days you set — the scanner was running on stale plugins. |
| Require credentialed scans | On | Any host in the file was scanned without working credentials. |
| Require successful scan status | On | Any host did not scan Good (see section 5.3). |
| Require plugin attributes | On | The file contains no Description, Synopsis or Solution anywhere — the signature of an export made with XML Plugin Attributes switched off in Security Center. The findings are all there, but nothing explains them. |
| POA&M aging | On | Used slightly differently: it drives the POA&M Required column on the Analyze page rather than flagging the scan file. |
POA&M aging thresholds
Section titled “POA&M aging thresholds”While POA&M aging is on, four small boxes appear beneath it — Very High, High, Moderate and Low — followed by days since publication. Each defaults to 30. A finding older than the threshold for its severity gets POA&M Required = Yes; one still inside the window gets No.
A number you type is only accepted once it is a valid whole number. A half-typed or empty box is ignored and the previous value stays in force; there is no error message.
11.3 Analysis
Section titled “11.3 Analysis”Grouped cells
Section titled “Grouped cells”| Setting | Default | What it does |
|---|---|---|
| Group separator | , (comma and space) | What goes between values in multi-value cells on the grouped Software and Ports views. Clearing it puts the default back. |
| Append newline after each separator | Off | Adds a line break after each separator. Makes long host lists far easier to read in an exported spreadsheet. |
Hostnames
Section titled “Hostnames”Shorten fully-qualified hostnames (default off) trims resolved names to the part before the first dot: web01.corp.example.mil becomes web01.
The problem it solves is described in section 6.6 — the same machine resolving short in one scan and qualified in another, and so failing to match itself in the baseline and the POA&M. The setting applies live, and turning it off restores exactly what the scan reported rather than a re-derived guess.
Baseline
Section titled “Baseline”Fill blank hostnames from Baseline and Fill blank host descriptions from Baseline, both off by default, are the same two switches described in section 4.3. Changing them here or there is the same thing.
11.4 AI
Section titled “11.4 AI”The AI tab holds the language-model connection settings and the prompt library, including which prompt each POA&M field’s fill button uses. It is built the first time you open the tab.
11.5 Reference Data
Section titled “11.5 Reference Data”NESSviewer ships with offline copies of two public datasets and uses them to enrich your findings on the Analyze page’s Risk tab. You can update either one without waiting for a new release. The section explains: To update, download the raw file from the source and drop it in here — no pre-processing needed. Applies to scans loaded after the update.
| Dataset | What it adds | Where to get it | File |
|---|---|---|---|
| CWE (MITRE) | Weakness names, consequences and mitigations behind each finding — the CWE and CWE Details columns. | cwe.mitre.org | The CWEC XML, .xml or .xml.zip |
| CISA KEV | Whether a CVE is known to be exploited in the wild, its BOD 22-01 due date, and whether it has been used in ransomware. | cisa.gov | known_exploited_vulnerabilities.json |
Each row shows a status line — either a summary such as MITRE CWE v4.20 · 2026-04-30 · 969 entries, or Loaded (bundled) or Not loaded — and an Update… button. Reset to bundled puts both datasets back to the versions that shipped with the application.
| Message | Meaning |
|---|---|
| Importing CWE… / Importing CISA KEV… | The import is running. |
| CWE updated — applies to scans loaded after this. | Success. Reload your scans to see the new data. |
| CISA KEV updated — applies to scans loaded after this. | Success. Reload your scans to see the new data. |
| CWE update failed: {message} / CISA KEV update failed: {message} | The file could not be read. Check you downloaded the raw file from the source in the format listed above. |
| Reverted to the bundled reference data. | Both datasets are back to the shipped versions. |
| Reset failed: {message} | The reset did not complete. |
The tab ends with the required attribution for both datasets: CWE is a trademark of The MITRE Corporation, and the CISA KEV catalog is public domain.
11.6 Application
Section titled “11.6 Application”| Setting | Default | What it does |
|---|---|---|
| Default export location | Your Documents folder | The folder suggested for exports. Browse… picks one. |
| Show debug information | Off | Surfaces additional diagnostic detail. |
| eMASS URL | empty | The base address of your eMASS instance — for example https://your-instance.emass.apps.mil. Setting it enables the Open in eMASS links on POA&M items, in the Analyze details panel and on the eMASS POA&M tab. While it is empty those links do not appear at all. |
11.7 Where your settings are kept
Section titled “11.7 Where your settings are kept”Settings are stored in your Windows user profile, so they follow your account and do not affect anyone else on the same machine. As well as the Options page settings, NESSviewer remembers your theme and menu mode, your column layouts, your Analyze views and coverage checks, your recent-file lists, which fields you have hidden in the details panels, and your Dashboard counting mode.
There is no global “reset everything” action. Reset to bundled on the Reference Data tab is the only reset, and it affects only the CWE and CISA KEV datasets.