Vulnerability Management
Vulnerability management is the continuous process of finding weaknesses in the technology you use, deciding which ones matter most, treating them safely, and verifying the result. It turns scanner findings and security advisories into owned, risk-based work.
itDefensive security and security operations | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Vulnerability Management
Vulnerability management is the habit of turning a report that says “something might be wrong” into evidence that the risk changed. It exists because software arrives with flaws, environments change underneath it, and a dashboard with many red rows is not, by itself, a security program. Before this discipline, the usual plan was a mixture of vendor email, hurried patching, and the ancient administrative art of hoping the spreadsheet had the right owner.
The useful mental model has six stations: scope, discover, validate, prioritize, treat, and verify. Scope says what counts and who can decide. Discovery gathers clues from scans, inventories, advisories, and tests. Validation asks whether the clue fits the actual asset, version, enabled feature, and attacker path. This is the point at which a finding, meaning evidence that a weakness may apply, stops pretending it is already a fact.
Priority is where the numbers get their manners back. CVSS describes vulnerability characteristics and severity, which is helpful. It cannot know whether the affected system is an isolated test machine or an internet-facing identity service. Add exposure, exploitation evidence, asset privilege, business impact, and compensating controls before deciding what goes first. CISA KEV membership is a strong signal that exploitation is real; it is not a magic stamp proving that a particular asset has the vulnerable condition.
Treatment is more varied than “patch it immediately,” although patching is often a fine destination. You can upgrade, reconfigure, mitigate, remove, replace, isolate, or accept a defined residual risk for a limited period. The awkward detail is that a change can fix a weakness and damage the service. Testing, deployment rings, monitoring, backups, and rollback plans are therefore not ceremonial hats worn by change management. They are part of the risk decision.
The surprise is that a closed ticket proves only that a workflow moved. It does not prove that the vulnerable service is gone, the fixed version is installed everywhere, or the application still works. Verification is the technical evidence that the intended end state occurred: a follow-up scan, inventory check, configuration query, reachability test, and service health check, as the situation requires.
Read the intro for the full loop and its boundaries. Use the slides when the relationships need a quick map, and keep the cheatsheet nearby when a finding needs states, decision classes, or evidence labels. The practice reference turns the loop into a triage record; the exercise makes the uncertainty explicit before it has a chance to acquire a due date and a personality.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.cisecurity.org/controls/continuous-vulnerability-management
Supports
- Continuous assessment and tracking of vulnerabilities across enterprise assets
- Remediation to reduce the window of opportunity for attackers
- Monitoring public and private sources for changing threat and vulnerability information
- A documented vulnerability-management process and risk-based remediation
- https://csrc.nist.gov/pubs/sp/800/40/r4/final
Supports
- Enterprise patch management as preventive maintenance
- Identifying, prioritizing, acquiring, installing, and verifying patches, updates, and upgrades
- Enterprise strategy, risk reduction, and coordination between business and technology stakeholders
- Applicability across information technology, operational technology, cloud, mobile, firmware, and applications
- Operational and availability considerations when planning patching
- https://csrc.nist.gov/pubs/sp/1800/31/final
Supports
- Asset inventory and automated assessment as foundations for enterprise patching
- Routine and emergency patching processes
- Patch prioritization, testing, deployment, and policy targets
- Isolation and other emergency mitigations as alternatives when immediate patching is unavailable
- Verification and continuous monitoring of asset vulnerabilities
- https://nvd.nist.gov/vuln
Supports
- Vulnerability as a weakness whose exploitation can harm confidentiality, integrity, or availability
- CVE identifiers as shared references for unique vulnerabilities
- Distinction between a public vulnerability record and local asset applicability
- https://nvd.nist.gov/general/cve-process
Supports
- NVD enrichment of CVE records
- Reference tags, CVSS, CWE, and CPE applicability statements
- Product and version applicability as data for matching vulnerabilities to assets
- Record maintenance and change as new information arrives
- https://www.first.org/cvss/v4.0/specification-document
Supports
- CVSS as an open framework for communicating vulnerability characteristics and severity
- Base, Threat, Environmental, and Supplemental metric groups
- Base metrics as intrinsic vulnerability characteristics
- Threat metrics as time-sensitive characteristics and Environmental metrics as consumer-specific context
- Supplemental metrics as added insight that does not change the final score
- Severity as an input that can be refined with threat and environmental context
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Supports
- KEV as CISA's authoritative source for vulnerabilities exploited in the wild
- KEV as an input to vulnerability-management prioritization
- Known exploitation as threat evidence rather than proof of local product presence or exposure
- https://www.cisa.gov/sites/default/files/publications/cisa-ssvc-guide%20508c.pdf
Supports
- Stakeholder-Specific Vulnerability Categorization as a decision-tree model
- Prioritization based on exploitation and impact evidence
- Response outcomes that communicate required action
- Use of organizational impact when deciding vulnerability response
- https://github.com/sindresorhus/awesome
Supports
- Awesome Security as a listed security ecosystem collection
- https://github.com/sbilly/awesome-security
Supports
- OpenVAS as a vulnerability scanning and vulnerability-management solution
- Nmap as a network discovery and security-auditing tool
- Selection of OpenVAS and Nmap as relevant ecosystem projects
- https://greenbone.github.io/docs/latest/
Supports
- Greenbone Community Edition as the open-source Greenbone Vulnerability Management stack also known as OpenVAS
- Maintained documentation for the stable community edition
- Components for vulnerability scanning, management services, data, and user interaction
- https://nmap.org/book/man.html
Supports
- Nmap as an open-source network exploration and security-auditing tool
- Host, service, operating-system, and network observation capabilities
- Use in network inventory and security audits
- https://csrc.nist.gov/nist-cyber-history/automation-metrics/chapter
Supports
- ICAT development in 1999 and its change to a vulnerability index in 2000
- NIST launch of the National Vulnerability Database in 2005 to replace ICAT
- https://cwe.mitre.org/about/history.html
Supports
- MITRE launch of the CVE List in 1999
- Development of CWE in 2005 and its first release in 2006
- https://csrc.nist.gov/pubs/sp/800/40/r3/final
Supports
- Enterprise patch management as preventive maintenance
- Patch-management stages of identification, prioritization, acquisition, testing, deployment, and verification
- https://www.cisa.gov/sites/default/files/publications/Reducing_the_Significant_Risk_of_Known_Exploited_Vulnerabilities_20211103.pdf
Supports
- Creation of the KEV Catalog in November 2021
- Known exploitation as a distinct input to vulnerability prioritization
- https://www.tenable.com/products
Supports
- Tenable One Vulnerability Management as a Tenable product for vulnerability management and exposure management
- https://docs.qualys.com/en/vm/latest/about_qualys_vm_vmdr.htm
Supports
- Qualys VMDR discovery, assessment, prioritization, patch identification, and remediation context
- https://docs.rapid7.com/insightvm/
Supports
- InsightVM scanning, asset organization, risk identification, and remediation prioritization
- https://learn.microsoft.com/en-us/microsoft-365/security/defender-vulnerability-management/defender-vulnerability-management
Supports
- Microsoft Defender Vulnerability Management asset visibility, assessment, prioritization, remediation, and tracking
- https://www.servicenow.com/products/vulnerability-response.html
Supports
- ServiceNow Vulnerability Response support for vulnerability remediation workflow
