You can't fix what you can't see. Vulnerability management is the continuous process of finding and reducing weaknesses before attackers exploit them.
Vulnerability Management
The continuous cycle of finding and fixing weaknesses.
Tap or hover a part to learn more.
Inventory & scan.
Know your assets, then scan them regularly (authenticated and unauthenticated) to discover vulnerabilities. You can't fix what you can't see.
Check your understanding
1. What does a CVSS score describe?
2. How does a vulnerability scan differ from a pen test?
The lifecycle
- Identify — asset inventory and regular scanning (authenticated and unauthenticated).
- Assess & prioritise — CVEs describe known flaws; CVSS scores severity, but true priority weighs exploitability, exposure and business impact.
- Remediate — patch, configure or apply compensating controls; verify with a re-scan.
- Report — track metrics and trends over time.
Distinct from a penetration test (a point-in-time simulated attack). Patching connects to Malware & Endpoint Security and Security+.
