| ACAS |
Assured Compliance Assessment Solution — the DOD’s deployment of Tenable scanning tools. An ACAS scan and a Nessus scan produce the same .nessus file. |
| Anchor plugin |
In a coverage check, a plugin used to prove the scan could actually see the kind of thing being checked for on a host. Anchoring makes a “missing” result trustworthy. |
| Baseline / test plan |
The authoritative list of hosts and what each must be tested with, held in a .tpln file. In NESSviewer it also stores your tracked lists and POA&M exceptions. |
| CAT I / II / III |
DOD severity categories. CAT I is the most severe. NESSviewer can label its severity tiers this way (section 11.1). |
| CISA KEV |
The Known Exploited Vulnerabilities catalog published by the US Cybersecurity and Infrastructure Security Agency: vulnerabilities confirmed to be exploited in the wild. Entries carry a remediation deadline under Binding Operational Directive 22-01. |
| CPE |
Common Platform Enumeration — a standard way of naming a product and version, used to identify software consistently. |
| Credentialed scan |
A scan that logged in to the host. It can see installed patches, software and settings. A non-credentialed scan sees only what is exposed to the network, so a clean result from one proves very little. |
| CVE |
Common Vulnerabilities and Exposures — the public identifier for a specific vulnerability, such as CVE-2024-3094. |
| CVSS |
Common Vulnerability Scoring System — a 0 to 10 score for severity. Version 3 is the current one; NESSviewer shows both v2 and v3 where the scan carries them. |
| CWE |
Common Weakness Enumeration — a classification of the kind of flaw, such as CWE-79 for cross-site scripting. A CVE is one specific instance; a CWE is the category it belongs to. |
| DVL |
Detailed Vulnerability List — a standard deliverable listing every finding with its detail. NESSviewer produces one from the Reports page. |
| eMASS |
Enterprise Mission Assurance Support Service — the DOD system of record for authorisation packages, including POA&Ms. |
| Finding |
One plugin firing on one host on one port. The same vulnerability on forty machines is forty findings. |
| IAVA / IAVB / IAVT |
Information Assurance Vulnerability Alert, Bulletin and Technical Advisory — DOD advisories that carry compliance reporting obligations. |
| Nessus |
The vulnerability scanner from Tenable. Its export format is .nessus. |
| Plugin |
One check the scanner performs, identified by a number. A finding is a plugin that fired on a host. |
| Plugin feed |
The set of plugins the scanner had at the time it ran. A feed much older than the scan date means the scan could not have detected recent vulnerabilities. |
| POA&M |
Plan of Action and Milestones — the formal record of a known weakness, what will be done about it, by whom and by when. |
| Remediation plan |
A working document mapping plugins to planned actions, owners and target dates. NESSviewer can read and edit it. |
| Security Center |
Tenable’s management console, from which scans are commonly exported. The XML Plugin Attributes setting there controls whether descriptions and solutions are included in the export. |
| STIG |
Security Technical Implementation Guide — DISA’s configuration standard for a product. Some Nessus plugins carry a STIG severity. |
| Unsupported / end-of-life |
A product the vendor no longer patches. These findings cannot be remediated by patching; they need replacement, isolation or a documented acceptance of risk. |