Zones, subnets, URLs, and tags
This is where you define what the CyberOptix CTEM Platform scans. Nothing internal is touched until something here says it should be.
Four pieces, and they do different jobs:
| Answers | |
|---|---|
| Subnets and URLs | What could be scanned |
| Zones | What actually is, by whom, and when |
| Tags | How you find it afterwards |
Subnets and URLs
The raw inventory of things you own. Subnets are network ranges in CIDR; URLs are web applications.
Adding them here makes them available, not scanned. Scanning happens when a zone includes them - which is what lets you record your estate without committing to scan all of it.
Zones
A zone is a scanning scope. It brings together what to scan, who scans it, and when:
SCREENSHOT: the zone configuration form.
| Component | Purpose |
|---|---|
| Subnets and URLs | What is in scope |
| Scanner group | Which scanners do the work |
| Scan schedules | How often each scan type runs |
| Nmap parameters | How aggressively to probe |
| Excluded hosts | Addresses inside the range that must not be touched |
| Blackout windows | When not to scan |
The scanner group is assigned to the zone, not to the assets. That indirection is what lets you replace a scanner without editing scope, and lets one group serve several zones. See Scanner groups and tasks.
Model zones on reachability
A zone should answer "what can a scanner in this position actually reach?" - because that is the constraint it exists to express. Splitting by network position (DMZ, internal, management) works. Splitting by ownership does not: that is a business unit, and a scanner cannot see a team.
Excluded hosts
Addresses that must not be scanned even though they sit inside an included range.
Use this for anything that reacts badly to being probed - fragile industrial equipment, medical devices, a legacy appliance that falls over on a port scan. It is a safety control, and it is easier to add before an incident than to explain afterwards.
Blackout windows
Periods when scanning must not run: a trading window, a month-end batch, a maintenance weekend. One-off windows and recurring ones are configured separately, so a nightly batch job does not need re-entering every day.
Excluded hosts and blackout windows are the two settings people configure in response to something going wrong. Both take a minute in advance.
Scan schedules
Each scan type runs on its own cadence, because their costs differ enormously. A common starting point:
| Scan type | Cadence | Why |
|---|---|---|
| Discovery | Daily or weekly | Cheap, and new hosts are what you most want to catch |
| Port scan | Daily or weekly | Cheap, catches service changes |
| Vulnerability scan | Weekly or monthly | Expensive, results change slowly |
| Web application scan | Weekly or monthly | Expensive, and noisy against production |
Discovery frequently and assessment less often is usually right: it is cheap to notice a new host and expensive to deeply test every host every night.
Nmap parameters
How aggressively scanners probe - a trade between speed, thoroughness, and how much load is put on the target. Fragile networks want gentler parameters; a lab can take more. Custom parameter sets are configured under Administration if the supplied ones do not fit.
Tags
Free-form labels, and the highest-return thing on this page for the least effort.
Zones and business units are structural and deliberately rigid. Tags are for everything
else you will want to filter by later: production, pci-scope, owner:platform-team,
decommission-q3.
Tag as assets are discovered, not later. The first pass through a new inventory is the only time anyone has the context fresh, and every subsequent triage is faster for it. "Critical findings on production assets in PCI scope" is a one-line filter if you tagged, and an afternoon if you did not.
Getting to a first scan
- Add the subnets and URLs you own.
- Create a scanner group and deploy a scanner into it.
- Create a zone: include the subnets, assign the group, set schedules.
- Add excluded hosts and blackout windows before anything runs.
- Let discovery run, then tag what comes back.
API
The endpoints behind this section are in the API reference.
Next
- Scanner profiles - credentialed scanning
- Scanner groups and tasks - who does the scanning
- Organizations, business units, and zones - how zones differ from business units