Skip to content

Appendix D. Glossary

Term Meaning
ACAS Assured Compliance Assessment Solution — the DOD’s deployment of Tenable scanning tools. An ACAS scan and a Nessus scan produce the same .nessus file.
Anchor plugin In a coverage check, a plugin used to prove the scan could actually see the kind of thing being checked for on a host. Anchoring makes a “missing” result trustworthy.
Baseline / test plan The authoritative list of hosts and what each must be tested with, held in a .tpln file. In NESSviewer it also stores your tracked lists and POA&M exceptions.
CAT I / II / III DOD severity categories. CAT I is the most severe. NESSviewer can label its severity tiers this way (section 11.1).
CISA KEV The Known Exploited Vulnerabilities catalog published by the US Cybersecurity and Infrastructure Security Agency: vulnerabilities confirmed to be exploited in the wild. Entries carry a remediation deadline under Binding Operational Directive 22-01.
CPE Common Platform Enumeration — a standard way of naming a product and version, used to identify software consistently.
Credentialed scan A scan that logged in to the host. It can see installed patches, software and settings. A non-credentialed scan sees only what is exposed to the network, so a clean result from one proves very little.
CVE Common Vulnerabilities and Exposures — the public identifier for a specific vulnerability, such as CVE-2024-3094.
CVSS Common Vulnerability Scoring System — a 0 to 10 score for severity. Version 3 is the current one; NESSviewer shows both v2 and v3 where the scan carries them.
CWE Common Weakness Enumeration — a classification of the kind of flaw, such as CWE-79 for cross-site scripting. A CVE is one specific instance; a CWE is the category it belongs to.
DVL Detailed Vulnerability List — a standard deliverable listing every finding with its detail. NESSviewer produces one from the Reports page.
eMASS Enterprise Mission Assurance Support Service — the DOD system of record for authorisation packages, including POA&Ms.
Finding One plugin firing on one host on one port. The same vulnerability on forty machines is forty findings.
IAVA / IAVB / IAVT Information Assurance Vulnerability Alert, Bulletin and Technical Advisory — DOD advisories that carry compliance reporting obligations.
Nessus The vulnerability scanner from Tenable. Its export format is .nessus.
Plugin One check the scanner performs, identified by a number. A finding is a plugin that fired on a host.
Plugin feed The set of plugins the scanner had at the time it ran. A feed much older than the scan date means the scan could not have detected recent vulnerabilities.
POA&M Plan of Action and Milestones — the formal record of a known weakness, what will be done about it, by whom and by when.
Remediation plan A working document mapping plugins to planned actions, owners and target dates. NESSviewer can read and edit it.
Security Center Tenable’s management console, from which scans are commonly exported. The XML Plugin Attributes setting there controls whether descriptions and solutions are included in the export.
STIG Security Technical Implementation Guide — DISA’s configuration standard for a product. Some Nessus plugins carry a STIG severity.
Unsupported / end-of-life A product the vendor no longer patches. These findings cannot be remediated by patching; they need replacement, isolation or a documented acceptance of risk.