>Question: Should I be concerned about a finding that has a low severity >rating but the risk factor is high? Why isn't a finding that has a high >risk factor rated with a high severity rating? I have seen lots of findings >like this that have a low severity rating but a high risk factor. Just does >not make sense to me. What is the logic behind Nessus doing this?
Your CIO has the right idea - you can't fix 10,000 problems in a week, but you might be able to handle the top 10. Anyway, it's up to *you* to decide what your top 10 are. Things like SNMP don't bug me as much, because my domain is internal security. I'd much rather spend time fixing the problems on our few externally available servers with a "low" severity than most of the "high" severity problems on the internal machines, simply because of exposure. Just look at where the risks come from - if it takes a highly sophisticated attack from the inside, it's probably more worth your time to secure access from the outside to machines on the inside, as most users wouldn't be able to do it themselves.
