Vulnerability Assessment
Datenmodelle
Finding- und Remediation-Schema mit allen Feldern, Typen und Pflichtangaben.
Hinweis: Diese Seite ist eine Umsetzungshilfe und ersetzt keine Rechtsberatung oder verbindliche aufsichtsrechtliche Auslegung.
| Tabelle
| Feld | Typ | Pflichtfeld |
|---|---|---|
| finding_id | string | Ja |
| title | string | Ja |
| source | enum : scanner, ai_assessment, pentest, manual, sbom, code_review | Nein |
| asset_type | enum : web_app, api, cloud, infrastructure, dependency, identity, mobile | Nein |
| environment | enum : dev, staging, production | Nein |
| publicly_exposed | boolean | Nein |
| cvss_score | float | Nein |
| exploitability_status | enum : not_tested, not_exploitable, exploitable_non_destructive | Nein |
| data_class | enum : public, internal, confidential, pii, payment, auth_secret | Nein |
| resilience_priority | enum : critical, high, medium, low | Nein |
| status | enum : open, triaged, remediation_planned, fixed, retest_pending, closed, risk_accepted | Nein |
| remediation_owner | string | Nein |
| due_date | date | Nein |
| Feld | Typ | Pflichtfeld |
|---|---|---|
| remediation_id | string | Ja |
| finding_id | string | Ja |
| fix_type | enum : code_change, config_change, patch, dependency_upgrade, policy_change, compensating_control | Nein |
| fix_description | string | Nein |
| testing_required | boolean | Nein |
| status | enum : draft, approved, implemented, verified, rejected | Nein |
Beispiel-Findings
CVSS
Quelle
Asset-Typ
Umgebung
Status
Keine Findings gefunden.
Detail-Tabelle
| ID | Titel | CVSS | Quelle | Asset-Typ | Umgebung | Priorität | Status |
|---|---|---|---|---|---|---|---|
Sicherheitshinweis: Exploit-Nachweise niemals öffentlich. Request/Response nur redigiert speichern. Tokens, Session-Cookies, personenbezogene Daten maskieren.