Vulnerability management program
Identifying vulnerabilities in itself will not make the organization secure but prioritizing and remediating those vulnerabilities per their severity will. A risk manager’s primary job related to vulnerabilities is to ensure that the vulnerabilities are prioritized, tracked, and fixed as a part of the vulnerability management program (VMP).
Organizations may choose to implement a tool to input all the vulnerabilities from the sources mentioned in this chapter or manage them manually in a project management tool. An important aspect to note for a VMP is coordinating with other teams. Remediating a vulnerability may come across as additional work on top of an engineer’s day-to-day; however, it is important to carve out some time and ensure that these vulnerabilities are remediated in an agreed-upon timeline.