- Getting Started
- Dashboard Overview
- Asset Management
- Device Mapping
- Vulnerability Management
- Recall Management
- Reporting
- User Management
- Troubleshooting
-
Access the System
- Open your web browser
- Navigate to your DAVE URL (e.g.,
https://dave.yourorganization.com) - You'll see the login page
-
Login Process
- Enter your username (usually your email address)
- Enter your password
- If MFA is enabled, enter the 6-digit code from your authenticator app
- Click "Login"
-
Initial Setup
- Complete your profile information
- Set up notification preferences
- Review and accept the terms of service
The main dashboard provides a comprehensive overview of your organization's cybersecurity posture:
- Total Assets: Number of managed devices
- Active Vulnerabilities: Current security issues
- Open Recalls: FDA recalls affecting your devices
- Compliance Rate: Overall compliance percentage
- Dashboard: Main overview page
- Assets: Device and asset management
- Device Mapping: FDA device mapping
- Recalls: FDA recall monitoring
- Vulnerabilities: Security vulnerability management
- Reports: Report generation and analytics
- Navigate to Assets → Add Asset
- Fill in the required information:
- Basic Information
- Hostname/IP Address
- Asset Type
- Manufacturer
- Model Number
- Serial Number
- Network Information
- IP Address
- MAC Address
- Network Segment
- Organizational Data
- Department
- Location
- Business Unit
- Asset Owner
- Criticality & Compliance
- Criticality Level
- Compliance Status
- Security Classification
- Basic Information
- Click Save Asset
- Navigate to Assets → Upload Assets
- Prepare your CSV file with the following columns:
hostname,ip_address,manufacturer,model_number,serial_numberdepartment,location,status,criticality_level
- Click Choose File and select your CSV
- Review the preview and click Import Assets
- List View: Tabular format with sorting and filtering
- Grid View: Card-based layout for visual browsing
- Search: Use the search bar to find specific assets
- Filters: Filter by department, status, criticality, etc.
- Click on an asset from the list
- Click Edit button
- Modify the required fields
- Click Save Changes
- Active: Device is operational
- Inactive: Device is offline or decommissioned
- Maintenance: Device is under maintenance
- Retired: Device has been decommissioned
- Patient monitoring equipment
- Diagnostic devices
- Therapeutic devices
- Laboratory equipment
- Servers and workstations
- Network equipment
- Storage systems
- Security appliances
The system automatically maps your assets to FDA device records for enhanced compliance monitoring.
- MAC Address Lookup: System identifies manufacturer from MAC address
- FDA Database Query: Searches openFDA database for matching devices
- Confidence Scoring: Ranks potential matches by confidence level
- Manual Review: Review and confirm automatic matches
- Navigate to Device Mapping → Unmapped Assets
- Select an unmapped asset
- Search FDA database using device information
- Review potential matches
- Select the correct FDA device record
- Click Confirm Mapping
- Mapped: Asset successfully linked to FDA record
- Unmapped: No FDA record found or mapping pending
- Pending Review: Automatic mapping requires manual confirmation
- Mapping Failed: Unable to find suitable FDA match
- Device Name: Official FDA device name
- Manufacturer: Device manufacturer
- Product Code: FDA product classification code
- Device Class: FDA device class (I, II, or III)
- Regulation Number: FDA regulation reference
- FDA Registration: Device registration status
- Recall History: Past FDA recalls affecting this device
- Vulnerability Status: Known security vulnerabilities
- Compliance Score: Overall compliance rating
Software Bill of Materials (SBOM) files provide detailed information about software components in your devices.
- Navigate to Vulnerabilities → Upload SBOM
- Select the target device
- Choose your SBOM file (supports CycloneDX, SPDX, JSON, XML)
- Click Upload and Process
- CycloneDX: Industry-standard format
- SPDX: Software Package Data Exchange format
- JSON: Generic JSON format
- XML: XML-based format
- Component Extraction: Identifies all software components
- Vulnerability Matching: Matches components to known vulnerabilities
- Risk Assessment: Calculates risk scores for each component
- Remediation Planning: Suggests remediation actions
- Scheduled Scans: Weekly vulnerability scans
- Real-time Monitoring: Continuous vulnerability monitoring
- NVD Integration: National Vulnerability Database integration
- CVSS Scoring: Common Vulnerability Scoring System
- Navigate to Vulnerabilities → Scan Devices
- Select devices to scan
- Choose scan parameters
- Click Start Scan
- CVE ID: Common Vulnerabilities and Exposures identifier
- Description: Detailed vulnerability description
- Severity: Critical, High, Medium, Low, Info
- CVSS Score: Numerical risk score (0.0-10.0)
- Affected Components: Software components affected
- Remediation: Suggested fixes and patches
- Critical: Immediate attention required
- High: Priority remediation needed
- Medium: Address within reasonable timeframe
- Low: Monitor and address when possible
- Info: Informational only
- CVSS Score: Vulnerability severity
- Exploitability: Ease of exploitation
- Impact: Potential damage
- Asset Criticality: Importance of affected device
- Network Exposure: Network accessibility
The system automatically monitors FDA recalls and matches them to your devices.
- Daily Checks: Automated daily recall monitoring
- Real-time Alerts: Immediate notifications for new recalls
- Device Matching: Automatic matching to affected devices
- User Notifications: Email alerts to relevant users
- FDA Recall Number: Official FDA recall identifier
- Recall Date: Date recall was issued
- Product Description: Detailed product information
- Reason for Recall: Why the recall was issued
- Manufacturer: Device manufacturer
- Classification: Class I, II, or III recall
- Affected Devices: Your devices affected by the recall
- Detection: System identifies new recall
- Matching: Matches recall to your devices
- Notification: Alerts relevant users
- Assessment: Review impact and required actions
- Remediation: Implement corrective actions
- Tracking: Monitor remediation progress
- Closure: Document resolution
- Open: Recall requires action
- In Progress: Remediation actions underway
- Resolved: Recall has been addressed
- Closed: No further action required
- Device Replacement: Replace affected devices
- Firmware Update: Update device firmware
- Configuration Change: Modify device settings
- Isolation: Remove device from network
- Monitoring: Enhanced monitoring of affected devices
- Remediation Plan: Detailed action plan
- Progress Updates: Regular status updates
- Evidence Collection: Documentation of actions taken
- Verification: Confirmation of successful remediation
- Asset Summary: Comprehensive asset overview
- Vulnerability Report: Security vulnerability analysis
- Recall Report: FDA recall status and impact
- Compliance Report: Compliance status and issues
- Device Mapping: Mapping status and gaps
- Security Dashboard: Overall security posture
- Navigate to Reports → Generate Report
- Select report type
- Choose export format (PDF, Excel, CSV)
- Set date range and filters
- Click Generate Report
- PDF: Professional formatted reports
- Excel: Spreadsheet format for analysis
- CSV: Comma-separated values for data import
- JSON: Machine-readable format
- Asset Statistics: Total, active, and new assets
- Vulnerability Trends: Security issue trends over time
- Recall Impact: Devices affected by recalls
- Compliance Rates: Department compliance percentages
- Asset Distribution: Assets by department
- Risk Assessment: Department risk levels
- Compliance Status: Department compliance rates
- Vulnerability Summary: Security issues by department
- Historical Data: Trends over time
- Seasonal Patterns: Recurring patterns
- Risk Indicators: Early warning signs
- Performance Metrics: System performance indicators
- Navigate to Reports → Scheduled Reports
- Click Create Schedule
- Configure report parameters
- Set delivery schedule
- Add email recipients
- Click Save Schedule
- Daily: Daily report delivery
- Weekly: Weekly summary reports
- Monthly: Monthly comprehensive reports
- Custom: Custom schedule configuration
- Full system access
- User management
- System configuration
- Background service management
- Security management
- API key management
- Risk matrix configuration
- Asset management
- Device mapping
- Vulnerability monitoring
- Report generation
- Dashboard access
- Read-only system access
- Personal Details: Name, email, phone
- Department: Organizational department
- Role: User role and permissions
- Preferences: Notification and display preferences
- Email Notifications: Email alert preferences
- Dashboard Alerts: Dashboard notification settings
- Report Delivery: Scheduled report preferences
- Security Alerts: Security notification settings
- Minimum 8 characters
- Must contain uppercase and lowercase letters
- Must contain numbers
- Must contain special characters
- Cannot reuse last 5 passwords
- Click Forgot Password on login page
- Enter your email address
- Check email for reset link
- Click reset link and enter new password
- Login with new password
- Forgot Password: Use password reset function
- Account Locked: Contact administrator
- MFA Issues: Check authenticator app time sync
- Browser Issues: Clear browser cache and cookies
- Upload Failures: Check file format and size
- Missing Data: Verify required fields are filled
- Permission Errors: Contact administrator for access
- Search Issues: Try different search terms
- Scan Failures: Check device connectivity
- Missing Vulnerabilities: Verify SBOM upload
- False Positives: Review vulnerability details
- Update Issues: Check for system updates
- Report Failures: Check date ranges and filters
- Missing Data: Verify data availability
- Format Issues: Try different export formats
- Download Problems: Check browser settings
- User Guide: This comprehensive guide
- FAQ: Frequently asked questions
- Video Tutorials: Step-by-step video guides
- Knowledge Base: Searchable help articles
- Email Support: support@yourorganization.com
- Phone Support: (555) 123-4567
- Ticket System: Submit support tickets
- Live Chat: Real-time support during business hours
- User Training: Scheduled training sessions
- Documentation: Comprehensive documentation
- Best Practices: Recommended procedures
- Updates: System update notifications
Last Updated: January 2024
Version: 1.0.0
For Technical Support: Contact your system administrator