Vulnerability Management permissions

Controls access to Vulnerability Management, which provides a centralized view of vulnerabilities across your organization to track, prioritize, and remediate discovered CVEs and exposures.

### Note

Requires a Cloud Posture Security, Cloud Runtime Security, Attack Surface Management (ASM), Exposure Management, or Cortex XSIAM Premium license. How users access and utilize these features depends on your license.

* Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium licenses: Go to **Posture Management** → **Vulnerability Management**. Grants access to Vulnerability Issues, Vulnerable Assets, Vulnerabilities by CVE, Vulnerability Intelligence, and Emerging Vulnerabilities.
* Exposure Management license: Go to **Exposure Management** → **Vulnerability Management**. Contact Customer Support to enable this feature.
* ASM license (without other licenses): Go to **Modules** → **Attak Surface.**. Grants access only to **Vulnerability Policies**.

For more information, see [Vulnerability Management](../../../detect-investigate-and-respond-to-threats/vulnerability-management).

| Permission | Description | Roles Example |
| ---------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| None | No access to Vulnerability Management pages, such as Vulnerability Issues, Findings, CVEs, and Vulnerability Policies. | |
| View | Read-only access to Vulnerability Management pages, such as Vulnerability Issues, Findings, CVEs, and Vulnerability Policies. | <ul><li>SOC Tier 1 and 2 Analysts: Needs visibility into vulnerabilities for initial triage; should not modify rules or policies.</li><li>Threat Hunter: Needs read access for threat research and correlation; typically does not modify rules or policies.</li></ul> |
| View/Edit | Full access to manage vulnerability issues (change status, assign, change severity), create/edit vulnerability policies (where relevant). | <ul><li>SOC Tier 3 Analyst: Senior analysts who can manage vulnerability issue lifecycle.</li><li>Security Engineer: Configures vulnerability remediation workflows.</li></ul> |

**Required and recommended permissions**

To effectively prioritize and respond to vulnerabilities, administrators and analysts require visibility into the underlying attack surface rules, active tests, and resulting security issues. Consider adding the following permissions.

| Permission | Permission Level | Reason |
| --------------------- | ----------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cases & Issues | View or View/Edit | <ul><li>View: Strongly recommended to view cases/issues linked to vulnerability issues.</li><li>View/Edit: Recommended to actively triage and respond to issues linked to exposure findings.</li></ul> |
| Attack Surface Rules | View | Strongly recommended to view the attack surface rules referenced in the vulnerability context. |
| Vulnerability Testing | View | Recommended to view vulnerability testing evidence in vulnerability issue details. |
| Exposure Management | View | Strongly Recommended for Security Controls view and broader Exposure Management navigation. Without this, users cannot see compensating controls or effectiveness data linked to vulnerability issues. View/Edit: Recommended for editing the Security Controls effectiveness rules. Only needed if the user should manage security controls, not just view vulnerability data. |
| Asset Inventory | View | Recommended. Provides necessary context regarding which specific assets are affected by the security control gaps. |