Vulnerability Management

Vulnerability management is the continuing practice of identifying, classifying, remediating, and mitigating vulnerabilities to an organization’s host systems. Many IS compliance, audit and risk management frameworks require organizations to have a vulnerability management system in place. There are four general core competencies involved in vulnerability management—discovery, reporting, prioritization and response. Discovery is the process of finding and categorizing network assets. Reporting captures the vulnerabilities for each network asset. Prioritization helps the organization to rank the risks of the vulnerabilities that are captured in the reporting, and response is the approach an organization takes to address known risks.

