inSight Vulnerability Management

CJIS-Aligned Vulnerability Assessment, Remediation Tracking and Oversight

Municipal police departments cannot afford to discover critical vulnerabilities only after an incident or CJIS audit. Without complete asset visibility, recurring assessments and documented remediation, outdated systems and exposed services can remain unnoticed for months.

inSight Vulnerability Management delivers a repeatable program for identifying, prioritizing and tracking security weaknesses across municipal technology environments, including:

  • Authenticated internal vulnerability scanning of servers, workstations and supported infrastructure

  • Network-based assessment of firewalls, switches, applications and other connected systems

  • External assessment of publicly accessible systems and services

  • Risk-based validation and prioritization of discovered vulnerabilities

  • Documented remediation assignments, target dates, exceptions and compensating controls

  • Rescanning to verify that vulnerabilities were successfully corrected

  • Audit-ready reporting and evidence aligned with CJIS Security Policy requirements

  • Day-to-day and audit support from our trusted US-based technical team

CJIS Security Policy 6.1 requires agencies to establish an ongoing vulnerability monitoring, scanning and remediation process—not simply conduct a one-time assessment. inSight Vulnerability Management helps municipalities build, operate and demonstrate that process.

ACT NOW. Identify and address security weaknesses before they become incidents or audit findings.


Service Features

Internal Vulnerability Assessment

inSight Vulnerability Management assesses authorized systems from within the customer’s trusted network environment using an encrypted site-to-site VPN or an optional on-site scan engine.

Internal assessment can include:

  • Windows and Linux servers

  • Domain controllers and directory services

  • User workstations and administrative systems

  • Firewalls, switches and wireless infrastructure

  • VMware and other virtualization platforms

  • Storage, backup and application servers

  • Printers, cameras and other supported network devices

  • Systems supporting CJIS and public-safety workflows

Authenticated scanning uses authorized credentials where appropriate to inspect installed software, missing updates, security configurations and other conditions that cannot reliably be identified through an unauthenticated network scan.

This supports CJIS vulnerability monitoring, privileged scanning and system-component inventory requirements, including RA-5, RA-5(5), CM-8 and CA-7.

External Attack-Surface Assessment

Internal scanning identifies risks reachable from trusted networks. External assessment identifies what a potential attacker can reach from the public Internet.

inSight Vulnerability Management assesses authorized public-facing assets for conditions such as:

  • Exposed network services

  • Outdated or vulnerable software

  • Weak encryption protocols and certificates

  • Insecure remote-access services

  • Unexpected administrative interfaces

  • Misconfigured web applications and services

  • Changes to the municipality’s external attack surface

Internal and external assessments provide complementary views of risk. Neither should be treated as a substitute for the other.

Complete Asset Visibility

A vulnerability management program is only effective when the agency knows which systems should be assessed.

Trestle reconciles scan results against available authoritative sources, which may include:

  • Active Directory

  • inSight Monitoring

  • Endpoint security platforms

  • VMware and virtualization inventory

  • DHCP, ARP and switch forwarding information

  • Firewall objects and network documentation

  • Existing municipal asset records

This process helps identify:

  • Systems missing from the formal inventory

  • Devices that could not be reached during a scan

  • Unsupported or obsolete operating systems

  • Unmanaged endpoints

  • Unknown network devices

  • Retired assets that remain connected

  • Discrepancies between operational and documented inventory

This strengthens the relationship between vulnerability management and CJIS system-component inventory requirements under CM-8.

Risk-Based Prioritization

Automated scanners can produce hundreds or thousands of findings. They cannot independently determine which vulnerabilities create the greatest operational risk to a police department.

Trestle reviews and prioritizes findings using factors such as:

  • Technical severity and CVSS score

  • Evidence of active exploitation

  • Internet exposure

  • Access to Criminal Justice Information

  • System criticality

  • Availability of patches or mitigations

  • Existing security controls

  • Operational impact of remediation

  • Age of the vulnerability

  • Whether the finding has been validated

This allows municipalities to focus limited technical resources on the vulnerabilities most likely to affect public safety, security or CJIS compliance.

Remediation Tracking and Verification

Vulnerability management does not end when a scan report is delivered.

inSight Vulnerability Management maintains a structured remediation process that documents:

  • Affected system and vulnerability

  • Technical severity and operational risk

  • Recommended corrective action

  • Assigned responsible party

  • Target remediation date

  • Current remediation status

  • Technical or operational dependencies

  • Approved exceptions

  • Compensating controls

  • Rescan results and closure evidence

Remediated findings are rescanned whenever practical to verify that the vulnerability is no longer present.

Findings that cannot be immediately corrected remain visible until resolved, mitigated or formally accepted. This supports CJIS RA-5 vulnerability monitoring and SI-2 flaw-remediation tracking.

Current Vulnerability Intelligence

The vulnerabilities affecting municipal systems continually change as researchers, vendors and government agencies disclose new security weaknesses.

Trestle maintains current scanning content and adjusts the assessment program when:

  • New critical vulnerabilities are announced

  • A vulnerability is known to be actively exploited

  • Significant new systems are deployed

  • Major operating-system or application changes occur

  • New attack techniques affect existing infrastructure

  • Security advisories identify potentially vulnerable products

Where appropriate, Trestle can perform targeted out-of-cycle assessments to determine whether a newly disclosed vulnerability affects the customer environment.

This supports RA-5(2), which requires agencies to update the vulnerabilities being assessed as new vulnerabilities are identified.

Vulnerability Reporting You Can Act On

inSight Vulnerability Management reports are designed for action and oversight—not simply to reproduce raw scanner output.

Recurring reports may include:

  • Executive summary of current risk

  • Asset and scan-coverage statistics

  • Critical and high-priority vulnerabilities

  • Newly discovered findings

  • Outstanding findings by age

  • Remediation progress

  • Overdue corrective actions

  • Accepted risks and compensating controls

  • Systems that could not be authenticated or reached

  • Verification-scan results

  • Trends across reporting periods

  • CJIS control alignment

Technical details remain available for administrators, while concise management reporting helps police leadership and municipal officials understand exposure, progress and required decisions.

Audit-Ready Evidence

CJIS readiness requires agencies to demonstrate that vulnerabilities are identified, reviewed and addressed through an established process.

inSight Vulnerability Management helps maintain repeatable evidence such as:

  • Approved scan scope

  • Asset and network coverage records

  • Scan schedules and completion history

  • Authenticated-scan status

  • Vulnerability reports

  • Review and prioritization records

  • Remediation tickets

  • Exception and risk-acceptance documentation

  • Rescan and closure evidence

  • Periodic management reports

This is the difference between “we ran a scan” and “we operate a vulnerability management program.”


The Real Risks of Unmanaged Vulnerabilities

Exploitation of Known Security Weaknesses

Attackers frequently exploit vulnerabilities for which updates or mitigations already exist.

Unmanaged vulnerabilities can expose agencies to:

  • Ransomware

  • Credential theft

  • Unauthorized remote access

  • Lateral movement between systems

  • Data loss or disclosure

  • Disruption of public-safety operations

  • Compromise of privileged accounts

A recurring vulnerability management program reduces the window between vulnerability disclosure, detection and remediation.

Incomplete System Inventory

Unknown or unmanaged systems cannot be reliably secured.

Inventory gaps may include:

  • Old servers that remain connected

  • Unmanaged workstations

  • Vendor-installed appliances

  • Forgotten remote-access services

  • Test systems placed into production

  • Devices operating on unexpected network segments

  • Systems missing endpoint security or monitoring agents

Vulnerability discovery helps identify these gaps and strengthen the municipality’s authoritative system inventory.

Unsupported and Obsolete Technology

Older operating systems, applications and network devices may no longer receive security updates.

Without recurring assessment, agencies may not recognize that critical infrastructure has become:

  • Unsupported by the manufacturer

  • Unable to receive security patches

  • Dependent on obsolete encryption

  • Incompatible with current security requirements

  • Increasingly difficult to insure or defend

Early identification allows municipalities to budget and plan replacements before an emergency occurs.

Audit Findings and Corrective Action Plans

Agencies that cannot demonstrate an ongoing vulnerability management process may face:

  • CJIS audit findings

  • Required corrective action plans

  • Accelerated follow-up reviews

  • Unplanned remediation projects

  • Increased scrutiny from municipal leadership

  • Difficulty demonstrating due diligence after an incident

A documented, repeatable program reduces last-minute audit preparation and provides durable evidence of security oversight.

Operational Disruption

Uncoordinated vulnerability remediation can itself create risk.

Updates to police, dispatch, video, access-control and other public-safety systems must account for:

  • Vendor support requirements

  • Maintenance windows

  • System dependencies

  • High-availability design

  • Backup and recovery readiness

  • Public-safety continuity

Trestle helps prioritize remediation while respecting operational requirements.