Implementing and Supporting Patch and Vulnerability Management
Vulnerability management is the process of identifying, assessing, and addressing vulnerabilities within a defined environment. Vulnerabilities typically result in a risk to an organization, and if not managed, the risk may result in the compromise of information and operational assets. Consequently, such a compromise may lead to financial losses, reputational damage, or legal ramifications.
The vulnerability management framework consists of five phases, of which a number are performed by the security function:
- Identifying the vulnerability
- Assessing and prioritizing the risk
- Stakeholder engagement
- Remediation
- Monitoring and reporting
These are discussed in detail in the sub-sections that follow.
Identifying the Vulnerability
Vulnerabilities are identified through a number of security processes, which may include (but are not necessarily limited to) vulnerability scanning, external...