inSight Vulnerability Management
CJIS-Aligned Vulnerability Assessment, Remediation Tracking and Oversight
Municipal police departments cannot afford to discover critical vulnerabilities only after an incident or CJIS audit. Without complete asset visibility, recurring assessments and documented remediation, outdated systems and exposed services can remain unnoticed for months.
inSight Vulnerability Management delivers a repeatable program for identifying, prioritizing and tracking security weaknesses across municipal technology environments, including:
Authenticated internal vulnerability scanning of servers, workstations and supported infrastructure
Network-based assessment of firewalls, switches, applications and other connected systems
External assessment of publicly accessible systems and services
Risk-based validation and prioritization of discovered vulnerabilities
Documented remediation assignments, target dates, exceptions and compensating controls
Rescanning to verify that vulnerabilities were successfully corrected
Audit-ready reporting and evidence aligned with CJIS Security Policy requirements
Day-to-day and audit support from our trusted US-based technical team
CJIS Security Policy 6.1 requires agencies to establish an ongoing vulnerability monitoring, scanning and remediation process—not simply conduct a one-time assessment. inSight Vulnerability Management helps municipalities build, operate and demonstrate that process.
ACT NOW. Identify and address security weaknesses before they become incidents or audit findings.
Service Features
Internal Vulnerability Assessment
inSight Vulnerability Management assesses authorized systems from within the customer’s trusted network environment using an encrypted site-to-site VPN or an optional on-site scan engine.
Internal assessment can include:
Windows and Linux servers
Domain controllers and directory services
User workstations and administrative systems
Firewalls, switches and wireless infrastructure
VMware and other virtualization platforms
Storage, backup and application servers
Printers, cameras and other supported network devices
Systems supporting CJIS and public-safety workflows
Authenticated scanning uses authorized credentials where appropriate to inspect installed software, missing updates, security configurations and other conditions that cannot reliably be identified through an unauthenticated network scan.
This supports CJIS vulnerability monitoring, privileged scanning and system-component inventory requirements, including RA-5, RA-5(5), CM-8 and CA-7.
External Attack-Surface Assessment
Internal scanning identifies risks reachable from trusted networks. External assessment identifies what a potential attacker can reach from the public Internet.
inSight Vulnerability Management assesses authorized public-facing assets for conditions such as:
Exposed network services
Outdated or vulnerable software
Weak encryption protocols and certificates
Insecure remote-access services
Unexpected administrative interfaces
Misconfigured web applications and services
Changes to the municipality’s external attack surface
Internal and external assessments provide complementary views of risk. Neither should be treated as a substitute for the other.
Complete Asset Visibility
A vulnerability management program is only effective when the agency knows which systems should be assessed.
Trestle reconciles scan results against available authoritative sources, which may include:
Active Directory
inSight Monitoring
Endpoint security platforms
VMware and virtualization inventory
DHCP, ARP and switch forwarding information
Firewall objects and network documentation
Existing municipal asset records
This process helps identify:
Systems missing from the formal inventory
Devices that could not be reached during a scan
Unsupported or obsolete operating systems
Unmanaged endpoints
Unknown network devices
Retired assets that remain connected
Discrepancies between operational and documented inventory
This strengthens the relationship between vulnerability management and CJIS system-component inventory requirements under CM-8.
Risk-Based Prioritization
Automated scanners can produce hundreds or thousands of findings. They cannot independently determine which vulnerabilities create the greatest operational risk to a police department.
Trestle reviews and prioritizes findings using factors such as:
Technical severity and CVSS score
Evidence of active exploitation
Internet exposure
Access to Criminal Justice Information
System criticality
Availability of patches or mitigations
Existing security controls
Operational impact of remediation
Age of the vulnerability
Whether the finding has been validated
This allows municipalities to focus limited technical resources on the vulnerabilities most likely to affect public safety, security or CJIS compliance.
Remediation Tracking and Verification
Vulnerability management does not end when a scan report is delivered.
inSight Vulnerability Management maintains a structured remediation process that documents:
Affected system and vulnerability
Technical severity and operational risk
Recommended corrective action
Assigned responsible party
Target remediation date
Current remediation status
Technical or operational dependencies
Approved exceptions
Compensating controls
Rescan results and closure evidence
Remediated findings are rescanned whenever practical to verify that the vulnerability is no longer present.
Findings that cannot be immediately corrected remain visible until resolved, mitigated or formally accepted. This supports CJIS RA-5 vulnerability monitoring and SI-2 flaw-remediation tracking.
Current Vulnerability Intelligence
The vulnerabilities affecting municipal systems continually change as researchers, vendors and government agencies disclose new security weaknesses.
Trestle maintains current scanning content and adjusts the assessment program when:
New critical vulnerabilities are announced
A vulnerability is known to be actively exploited
Significant new systems are deployed
Major operating-system or application changes occur
New attack techniques affect existing infrastructure
Security advisories identify potentially vulnerable products
Where appropriate, Trestle can perform targeted out-of-cycle assessments to determine whether a newly disclosed vulnerability affects the customer environment.
This supports RA-5(2), which requires agencies to update the vulnerabilities being assessed as new vulnerabilities are identified.
Vulnerability Reporting You Can Act On
inSight Vulnerability Management reports are designed for action and oversight—not simply to reproduce raw scanner output.
Recurring reports may include:
Executive summary of current risk
Asset and scan-coverage statistics
Critical and high-priority vulnerabilities
Newly discovered findings
Outstanding findings by age
Remediation progress
Overdue corrective actions
Accepted risks and compensating controls
Systems that could not be authenticated or reached
Verification-scan results
Trends across reporting periods
CJIS control alignment
Technical details remain available for administrators, while concise management reporting helps police leadership and municipal officials understand exposure, progress and required decisions.
Audit-Ready Evidence
CJIS readiness requires agencies to demonstrate that vulnerabilities are identified, reviewed and addressed through an established process.
inSight Vulnerability Management helps maintain repeatable evidence such as:
Approved scan scope
Asset and network coverage records
Scan schedules and completion history
Authenticated-scan status
Vulnerability reports
Review and prioritization records
Remediation tickets
Exception and risk-acceptance documentation
Rescan and closure evidence
Periodic management reports
This is the difference between “we ran a scan” and “we operate a vulnerability management program.”
The Real Risks of Unmanaged Vulnerabilities
Exploitation of Known Security Weaknesses
Attackers frequently exploit vulnerabilities for which updates or mitigations already exist.
Unmanaged vulnerabilities can expose agencies to:
Ransomware
Credential theft
Unauthorized remote access
Lateral movement between systems
Data loss or disclosure
Disruption of public-safety operations
Compromise of privileged accounts
A recurring vulnerability management program reduces the window between vulnerability disclosure, detection and remediation.
Incomplete System Inventory
Unknown or unmanaged systems cannot be reliably secured.
Inventory gaps may include:
Old servers that remain connected
Unmanaged workstations
Vendor-installed appliances
Forgotten remote-access services
Test systems placed into production
Devices operating on unexpected network segments
Systems missing endpoint security or monitoring agents
Vulnerability discovery helps identify these gaps and strengthen the municipality’s authoritative system inventory.
Unsupported and Obsolete Technology
Older operating systems, applications and network devices may no longer receive security updates.
Without recurring assessment, agencies may not recognize that critical infrastructure has become:
Unsupported by the manufacturer
Unable to receive security patches
Dependent on obsolete encryption
Incompatible with current security requirements
Increasingly difficult to insure or defend
Early identification allows municipalities to budget and plan replacements before an emergency occurs.
Audit Findings and Corrective Action Plans
Agencies that cannot demonstrate an ongoing vulnerability management process may face:
CJIS audit findings
Required corrective action plans
Accelerated follow-up reviews
Unplanned remediation projects
Increased scrutiny from municipal leadership
Difficulty demonstrating due diligence after an incident
A documented, repeatable program reduces last-minute audit preparation and provides durable evidence of security oversight.
Operational Disruption
Uncoordinated vulnerability remediation can itself create risk.
Updates to police, dispatch, video, access-control and other public-safety systems must account for:
Vendor support requirements
Maintenance windows
System dependencies
High-availability design
Backup and recovery readiness
Public-safety continuity
Trestle helps prioritize remediation while respecting operational requirements.