Skip to content

VTI-Module

The VTI Module (Vulnerability & Threat Intelligence) of the fuentis Suite 4 is a central component for the systematic identification, assessment, and management of threats and vulnerabilities within the ISMS framework. It forms the foundation for a well-founded risk analysis according to ISO 27001 and BSI IT-Grundschutz by enabling organizations to detect potential threats early and address them proactively.

Note: You can access this module as an automatic function in Asset Management. To do so, either click on an asset and then on the “Vulnerabilities (CVE)” tab, or click on the settings icon (gear wheel). Here you can now click on “Vulnerabilities (CVE)”.

Schwachstellen Tab Assets

In the digital landscape, organizations are exposed to a multitude of cyber threats. The VTI module supports through:

  • Proactive Security: Early detection of vulnerabilities before they are exploited
  • Compliance Fulfillment: Demonstrable fulfillment of regulatory requirements (ISO 27001, BSI Standard 200-3)
  • Risk Minimization: Systematic reduction of the attack surface through structured vulnerability management
  • Resource Optimization: Prioritization of critical vulnerabilities based on actual risk

Attention: Unfortunately, our VTI cannot yet automatically identify patches and thus already closed vulnerabilities for assets. This feature is still on the roadmap.

A threat is a potential circumstance or event that can compromise the confidentiality, integrity, or availability of information. In the VTI context, we distinguish:

  • Elementary Threats: Basic threat scenarios from BSI catalogs (e.g., G 0.28 “Software vulnerabilities or errors”)
  • Specific Threats: Threats tailored to the organization
  • Emerging Threats: Newly emerging threats from current threat intelligence sources

A vulnerability is a weakness in a system, process, or control that can be exploited by a threat. Important aspects:

  • CVE-based Vulnerabilities: Common Vulnerabilities and Exposures from public databases
  • Configuration Weaknesses: Faulty system settings or processes
  • Organizational Vulnerabilities: Gaps in policies or procedures

Practice Tip: A threat only becomes a concrete danger when an exploitable vulnerability exists. Without a vulnerability, no risk can arise.

A damage scenario describes the concrete impacts when a threat successfully exploits a vulnerability:

  • Primary Damages: Direct impacts (e.g., data loss, system failure)
  • Consequential Damages: Indirect consequences (e.g., reputation loss, legal consequences)
  • Cascade Effects: Impacts on dependent systems and processes

Note: You can also use the Catalog Manager to access additional functions here, such as reusability.

Schadensszenario Risikoanalyse

Practical Implementation with the fuentis Suite

Section titled “Practical Implementation with the fuentis Suite”

The VTI module is closely linked with Asset Management:

  1. Asset-based Vulnerability Assignment

    • Direct linking of CVEs with affected IT systems
    • Automatic identification of vulnerable assets based on software inventory
    • Prioritization according to asset protection requirements
  2. Target Object Group Linkage

    • Threats are assigned to target object groups
    • Inheritance of vulnerabilities along the asset hierarchy
    • Aggregated risk assessment at process level

Data Source Integration

  • Fuentis CVE Source: Curated vulnerability database with verified entries
  • NIST NVD Integration: Automatic import of current CVE data
  • MITRE ATT&CK Framework: Mapping of threats to attack techniques

Automated Processes

1. Daily import of new CVEs from configured sources
2. Matching against asset inventory (software, versions, configurations)
3. Automatic risk assessment based on CVSS scores
4. Generation of action recommendations and tasks

CVE

Vulnerability Lifecycle

  1. Identification: Automatic detection or manual import
  2. Assessment: CVSS scoring and context evaluation
  3. Prioritization: Risk-Based Vulnerability Management (RBVM)
  4. Remediation: Measure planning and implementation
  5. Verification: Verification of effectiveness
  6. Documentation: Audit-compliant evidence documentation

The VTI module feeds directly into risk analysis:

Risk Identification

  • Threats and vulnerabilities are linked in risk objects
  • Automatic suggestions based on asset type and configuration
  • Context-related threat selection from catalogs

Risk Assessment

  • Probability of occurrence based on:
    • CVSS Exploitability Score
    • Threat Intelligence indicators
    • Historical incident data
  • Damage impact derived from:
    • Asset protection requirements
    • Business Impact Analysis
    • Dependency analysis
  1. Catalog Setup

    • Import relevant threat catalogs (BSI, ISO, industry-specific)
    • Create organization-specific threats for unique risks
    • Maintain vulnerability templates for recurring vulnerability types
  2. Asset Preparation

    • Complete software inventory (name, version, patch level)
    • Documentation of system dependencies
    • Classification by criticality and protection requirements
  3. Process Establishment

    • Define clear responsibilities (Threat Owner, Vulnerability Manager)
    • Establish regular review cycles
    • Implement escalation paths for critical findings

Practice Tip: Use the dashboard module of the fuentis Suite to visualize these KPIs. Create separate views for management and operational teams.

ISMS Module

  • Direct input for risk register
  • Basis for measure derivation
  • Evidence documentation for ISO 27001 audits

Task Management

  • Automatic task generation for critical vulnerabilities
  • Workflow-based remediation processes
  • SLA tracking and escalation

Reporting

  • Vulnerability Assessment Reports
  • Threat Landscape overviews
  • Compliance evidence for auditors

Catalog Manager

  • Management of own threat catalogs
  • Import of external threat databases
  • Maintenance of vulnerability categories

Scenario: Monthly Microsoft Patch Tuesday

  1. Automatic import of new CVEs via VTI service
  2. Matching against Windows assets in Asset Management
  3. Risk assessment based on asset criticality
  4. Task generation for IT operations with prioritization
  5. Tracking and reporting of patch compliance

Scenario: Critical zero-day vulnerability (e.g., Log4Shell)

  1. Immediate manual import of CVE
  2. Automatic identification of affected systems
  3. Impact assessment via dependency analysis
  4. Emergency tasks with highest priority
  5. Management reporting and communication

Scenario: ISO 27001 recertification

  1. Export of all addressed vulnerabilities from the last 12 months
  2. Evidence of systematic threat monitoring
  3. Documentation of risk treatment decisions
  4. KPI dashboard for auditor presentation

Holistic Approach: VTI integrates threat intelligence and vulnerability management in a coherent system that seamlessly integrates with asset management and risk analysis.

Automation as Key: Through automated CVE import, asset matching, and task generation, manual effort is significantly reduced while simultaneously improving response time.

Risk-Based Prioritization: Not every vulnerability is equally critical - context evaluation based on asset criticality and business impact enables focused resource allocation.

Continuous Improvement: Through metrics and KPIs, the effectiveness of vulnerability management becomes measurable and can be systematically optimized.