Vulnerability analysis
A risk manager must dedicate sufficient time and resources to ensure the vulnerabilities identified using threat modeling are actioned. The first step that must be performed after identifying these vulnerabilities is to ensure that vulnerabilities are categorized per their severity. Analysis must also be performed on the implemented controls.
Organizations may choose to adopt a nomenclature to define the severity of the vulnerability. As an industry practice, vulnerabilities are quantified as Critical, High, Medium, Low, and Informational. Organizations and vulnerability assessment tools use the Common Vulnerability Scoring System (CVSS) to quantify vulnerabilities. A risk manager must prioritize the Critical and High vulnerabilities to be remediated as soon as practical and analyze the implemented controls periodically.