4. Reference Files: Baseline, POA&M and Remediation Plan
Scans tell you what is wrong. Your reference files tell you what was supposed to be there, what you have already documented, and what you have promised to fix. Loading them turns a list of findings into a picture of where you stand against your own paperwork.
All three are optional. Load whichever ones you have.
4.1 What each reference file adds
Section titled “4.1 What each reference file adds”| Reference file | What it adds to your findings |
|---|---|
| Baseline (.tpln) | The In Testplan? answer for every scanned host — whether the machine you scanned is one you were supposed to scan. It can also fill in hostnames and host descriptions the scan could not resolve, and it can hold your tracked ports and software lists and your POA&M exceptions. |
| eMASS POA&M (.xlsx) | For every finding: whether it is already on the POA&M, what its status is, its item ID, the devices listed against it, and a link that opens the item directly in eMASS. |
| Remediation plan (.xml) | For every finding: the planned action, its category, the estimated completion date, the point of contact, the details and any mitigation. You can also create and edit plan entries from inside NESSviewer. |
All three are matched to your findings by plugin ID. That is worth remembering: a POA&M item is linked to a finding because its Security Checks field names that plugin, not because the hostnames happen to match.
4.2 Loading a reference file
Section titled “4.2 Loading a reference file”There are two equivalent places to do this, and they stay in step with each other.
From the Reference Files panel
Section titled “From the Reference Files panel”At the bottom of the Files page’s Files tab is a panel headed Reference Files with one row for each type — Baseline, eMASS POA&M and Remediation Plan. Each row has a Browse… button and a dropdown of files you have used recently.
From the tabs
Section titled “From the tabs”The Files page’s other three tabs — Baseline, eMASS POA&M and Remediation Plan — each open a full editor for that file type. Loading a file on a tab is the same as loading it from the panel; both show the same file.
4.3 The Baseline tab
Section titled “4.3 The Baseline tab”The Baseline tab holds the baseline editor, and above it a panel of options headed:
Use this baseline to fill gaps in scan data
There are two switches:
| Switch | On-screen explanation | What it does |
|---|---|---|
| Fill blank hostnames | When a scan couldn’t resolve a hostname, use this baseline’s host name — matched by MAC address, then IP. | Where a finding has no hostname, NESSviewer looks the machine up in the baseline and borrows its name. |
| Fill blank host descriptions | Use the baseline host’s Target Comment where a scan has no host description. Hosts with no MAC or IP are never matched; turning either option off restores the blanks. | Same idea for the host description, taken from the baseline’s Target Comment field. |
Both switches are off by default and take effect immediately across Analyze and Reports — there is no reload or restart. The same two switches also appear on the Options page under Analysis → Baseline; changing one changes the other.
How the matching works
Section titled “How the matching works”For each row that is missing a value, NESSviewer looks for the machine in the baseline by MAC address first, then by IP address. Only genuinely blank cells are ever filled, so nothing the scan reported is overwritten. Hosts with neither a MAC nor an IP can never be matched.
Because NESSviewer remembers which cells it filled, turning a switch back off restores the blanks exactly.
4.4 The eMASS POA&M tab
Section titled “4.4 The eMASS POA&M tab”The eMASS POA&M tab shows your loaded POA&M export and lets you work with it directly. Once a POA&M is loaded, every finding in the Analyze grid gains its POA&M columns:
| Column | What it tells you |
|---|---|
| POA&M Status (eMASS) | The status of the matching POA&M item. Where a plugin matches more than one item the statuses are joined together, with Ongoing listed first. An item that has no status text is shown as On POA&M. |
| POA&M Raw Severity | The raw severity recorded on the POA&M item. |
| POA&M Devices Affected | The hosts listed on the matching item or items, de-duplicated. |
| POA&M Item ID | The visible item identifier. |
| POA&M eMASS Link ID | The internal record ID, which drives the Open in eMASS button. |
Before a POA&M is loaded these columns read No POA&M Loaded. Once one is loaded, findings whose plugin is not on it read Not on POA&M — which is exactly the list you want when you are working out what still needs documenting.
4.5 The Remediation Plan tab
Section titled “4.5 The Remediation Plan tab”The Remediation Plan tab opens the plan editor. Unlike the baseline and the POA&M, you can have several plan files open at once — loading another adds it rather than replacing what is there.
Once a plan is loaded, these columns are filled in on every matching finding: Remediation Action, Remediation Category, Remediation ECD, Remediation POC, Remediation Details and Mitigation. Before a plan is loaded they read No Remediation Plan Loaded.
You do not have to work in this tab to maintain the plan. The Analyze page’s details panel has a Remediation tab where you can create and edit the entry for whichever finding you are looking at, and those edits are written straight back into the plan file. Section 6.3 covers it.
4.6 How reference data reaches your findings
Section titled “4.6 How reference data reaches your findings”You do not have to do anything to make the joins happen. Whenever scans or reference files change, NESSviewer re-matches everything automatically. The practical consequences are worth knowing:
-
Order does not matter. Load the POA&M before or after the scans; the result is the same.
-
Unloading a reference file undoes its columns. Close the last remediation plan and those columns go back to No Remediation Plan Loaded.
-
Matching is by plugin ID only. If a POA&M item’s Security Checks field does not name the plugin, the finding will read Not on POA&M no matter how clearly the two describe the same problem.
-
One plugin can match several POA&M items, and one POA&M item can cover several plugins. NESSviewer handles both and joins the values together.