

Tenable One
By Tenable, Inc.
The typical implementation process for Tenable One software involves the following steps:
Initial Consultation: Assess client needs and discuss integration requirements.
System Setup: Configure the Tenable One platform for the organization’s environment. This includes integration with existing security tools and IT infrastructure.
Data Integration: Integrate data sources, including vulnerabilities, cloud services, assets, and external attack surfaces.
Custom Configuration: Customize the platform’s settings to align with specific business goals, compliance needs, and reporting preferences.
Testing & Validation: Conduct tests to ensure all integrations are functional and data is properly captured.
Training: Provide training to key staff members on how to use the platform effectively for ongoing monitoring and vulnerability management.
Go-Live: Launch the platform and begin real-time monitoring and reporting.
Tenable One can be customized to fit specific business needs. Here are key aspects of its customization capabilities:
Custom Dashboards and Reporting:
Tenable One allows users to create custom dashboards to visualize security data in ways that best fit organizational requirements.
Reports can be tailored to specific risk assessments, compliance standards, and key performance indicators (KPIs).
Integration with Third-Party Tools:
Tenable One can integrate with a wide range of existing security tools and platforms, including SIEMs, vulnerability scanners, and cloud services (e.g., AWS, Azure). This helps tailor the platform to the existing security infrastructure of an organization.
Custom connectors are available for integrations with proprietary or niche tools.
Vulnerability Management and Asset Classification:
Users can define custom asset groups, classification schemes, and risk levels, allowing for granular control over how assets are managed and monitored.
Custom vulnerability scoring models can be implemented to prioritize threats based on business risk.
Cloud and On-Premises Customization:
Tenable One is adaptable for both cloud and on-premises environments. Users can customize their monitoring scope to focus on specific cloud regions, on-premise assets, or hybrid infrastructures.
Organizations can also choose to monitor specific network segments, applications, or operational technologies based on their unique infrastructure.
Security Policies and Alerts:
Custom security policies can be configured to meet industry-specific compliance standards (e.g., GDPR, HIPAA, PCI DSS).
Alerts and notifications can be fine-tuned to trigger based on custom thresholds, risk levels, or incidents relevant to business operations.
Scalability:
The platform is scalable, meaning that it can grow with the business. It supports customization for organizations of different sizes, from small businesses to large enterprises.
Organizations can adjust the scope of what is being monitored as business needs evolve. This includes adding new assets, networks, or geographical regions.
Role-Based Access Control (RBAC):
Tenable One allows organizations to implement role-based access control to ensure that only authorized personnel have access to sensitive data, reports, or configurations. This can be tailored to the roles and responsibilities within an organization.
API Access for Further Customization:
For advanced users, Tenable One provides API access, which allows businesses to build additional integrations or automate processes within the platform. This can be used to tailor the platform further to specific operational workflows.
Compliance & Regulatory Needs:
Tenable One offers a comprehensive range of training and support to ensure new users can efficiently utilize the platform. Here's a breakdown of the available options:
Tenable University:
Tenable provides access to Tenable University, an online platform offering free training courses, certifications, and learning paths. Users can access structured courses on vulnerability management, risk-based security, and the usage of Tenable products.
Topics range from basic introductory content to more advanced use cases, ensuring both beginners and experienced professionals can find relevant material.
Product Documentation:
Tenable One users have access to comprehensive and detailed product documentation that covers all aspects of the platform, from installation and setup to advanced configurations and troubleshooting.
The documentation is regularly updated to include the latest features and best practices.
Webinars and Tutorials:
Tenable hosts webinars and live training sessions led by experts, where users can learn directly from Tenable professionals. These sessions are often focused on specific features, use cases, or industry trends.
On-demand webinars are also available for those who cannot attend live sessions.
Guided Demos:
Tenable offers guided demos for new users to walk through the platform's capabilities and understand how to use it in their environments. These demos are typically led by Tenable representatives.
User Training Sessions:
Personalized training can be arranged, where Tenable provides customized instruction tailored to the user’s specific needs and the organization's requirements.
Customer Support Portal:
Tenable provides access to a customer support portal, where users can log support tickets, track issues, and get help from Tenable’s expert support team.
The portal also contains a knowledge base with articles and troubleshooting guides that users can reference for quick self-service support.
Technical Support:
Tenable offers 24/7 technical support to its customers, ensuring that users have access to assistance at any time, especially in critical situations.
Support is available via multiple channels, including phone, email, and live chat, depending on the support plan.
Community and Forums:
Tenable has a robust community forum where users can discuss issues, share tips, and ask questions. It's a valuable resource for peer-to-peer support and learning from others’ experiences with Tenable One.
Active users and Tenable staff often engage in discussions, offering solutions or insights.
Knowledge Base:
The Tenable Knowledge Base contains articles, how-to guides, and troubleshooting steps for common problems, helping users to resolve issues on their own without needing to contact support.
Product Updates and Notifications:
Tenable One users are kept informed about product updates, new features, security patches, and system enhancements through release notes and notifications. This ensures they are always aware of the latest improvements.
Premium Support Options:
Here’s a shorter version of the security measures Tenable One implements to protect data:
Data Encryption:
In-Transit: TLS encryption.
At-Rest: AES-256 encryption.
Identity & Access Management:
Role-based access control RBAC and multi-factor authentication MFA.
Secure Data Hosting:
Hosted on secure cloud providers with certifications like ISO 27001 and SOC 2.
Continuous Monitoring:
Real-time monitoring and behavioral analysis for threat detection.
Auditing and Logging:
Comprehensive logs and audit trails for transparency.
Patching & Vulnerability Management:
Regular security patches and automated vulnerability scanning.
Compliance:
Supports GDPR, HIPAA, and PCI DSS compliance.
Data Loss Prevention DLP:
Measures to prevent unauthorized data access and leakage.
Penetration Testing & Security Audits:
Regular third-party testing and audits.
Incident Response:
Tenable One's policies on data ownership and portability are outlined in their Privacy Policy and Subscription Agreement. Key points include:
Data Ownership: Customer Data: You retain ownership of all data you input into Tenable One. Tenable acts as a data processor, handling your data solely to provide the services.
Tenable One's contract renewal and cancellation terms are detailed in the Tenable Subscription Agreement. Key points include:
Contract Renewal:
Auto-Renewal: Tenable One subscription's may automatically renew at the end of the initial term. Customers can manage this setting through their account portal.
Renewal Period: A warning appears in the user interface 30 days before your license expires, prompting you to work with your Tenable representative to add or remove products or change your license count.
Contract Cancellation:
Customer-Initiated Termination: You may terminate the agreement at any time by stopping use of the services and providing written notice to Tenable. However, this does not relieve you of any payment obligations incurred up to the date of termination.
Tenable One complies with several key industry standards to ensure data protection and security. These include:
ISO 27001: Certification for information security management systems (ISMS), ensuring secure management of sensitive data.
SOC 2 Type II: Focuses on controls related to security, availability, processing integrity, confidentiality, and privacy.
SOC 3: A public version of the SOC 2 report, providing transparency about the security measures in place.
General Data Protection Regulation (GDPR): Ensures compliance with EU data protection laws, focusing on the privacy and security of personal data.
Health Insurance Portability and Accountability Act (HIPAA): For users in the healthcare sector, ensuring the protection of health-related information.