Appendix C. Data Value Reference
The exact values you will see in the fields that carry a fixed set of possibilities.
C.1 Severity
Section titled “C.1 Severity”| Field | Possible values |
|---|---|
| Nessus Severity | Critical, High, Medium, Low, Information |
| DOD Severity — words | Very High, High, Moderate, Low, Information |
| DOD Severity — CAT labels | Very High, CAT I, CAT II, CAT III, Information |
| STIG Severity | I, II, III, or blank |
C.2 Risk flags
Section titled “C.2 Risk flags”| Field | Possible values |
|---|---|
| Exploit Available | true or false |
| Unsupported by Vendor | Yes, or blank |
| CISA KEV | Yes, or blank |
| KEV Ransomware | Known, or blank |
C.3 POA&M and remediation
Section titled “C.3 POA&M and remediation”| Field | Possible values |
|---|---|
| POA&M Status (eMASS) | No POA&M Loaded before a POA&M is loaded; Not on POA&M when no item matches; On POA&M when the matched item has no status text; otherwise the item’s own status. Where several items match, their statuses are joined with semicolons and Ongoing is listed first. |
| POA&M Required | Yes, No, or blank |
| Remediation columns | No Remediation Plan Loaded until a plan is loaded |
| Exception types | Documented, False Positive, Misleading |
C.4 Scan status
Section titled “C.4 Scan status”| Value | Verdict |
|---|---|
| Good, Local Checks Enabled | Complete results — the scan authenticated and ran local checks. |
| Good, Local Checks Support Not Available or Unsupported OS | Fine, but expect thinner results — no local checks exist for this platform. |
| Good, Local Checks Support Not Available or Identification Issues Reported | Fine, but the platform was hard to identify. |
| Good, Local Checks Not Attempted Against Fragile Device | Deliberately not probed. |
| Error, Local Checks Enabled and Issues Reported | Authenticated, but something went wrong during the checks. |
| Bad, Local Checks Failed to be Enabled Due to an Error; No Fragile Devices | Authentication failed. Do not trust a low finding count. |
| Bad, Authentication Capable or Credentials Not Provided | No credentials were supplied. Fix the scan configuration. |
| Suspect, Authentication Protocols Not Available or Endpoint Became Unresponsive | The host stopped responding or offered no usable authentication. |
| Unable to determine scan status | No verdict is possible. |
C.5 Baseline and coverage
Section titled “C.5 Baseline and coverage”| Field | Possible values |
|---|---|
| In Testplan? | No Testplan Loaded when no baseline is open; Yes when the host matched by name; Yes-Matched on MAC Address when it matched by hardware address; No when it did not match. |
| Coverage Status | Present, Missing, Unverifiable |
| Coverage Credentialed | Yes, No, or blank |
| Coverage Identified By Plugin | Plugin numbers, and Host CPE where the match came from the scanner’s host inventory |
| Compliance | OK, Issues, or blank |