Skip to content

Vulnerability management

Vulnerability management is the continuous process of discovering, prioritizing, remediating, and verifying weaknesses across the fleet. It’s not “run a scanner once”: it’s a cycle that, done well, closes doors before an attacker finds them.

1. INVENTORY you can't protect what you don't know you have (assets, software, services)
2. DISCOVER authenticated/unauthenticated scanning + sources (CMDB, SBOM, cloud)
3. PRIORITIZE by real risk, not by volume (see below)
4. REMEDIATE patch (def-patch), mitigate, or accept with justification
5. VERIFY re-scan/validate that the remediation worked
6. REPEAT continuous process; track trends (not just a point-in-time snapshot)
CVSS base technical severity (0-10) -> NOT priority on its own
EPSS probability of exploitation in practice (key data for prioritizing)
CISA KEV catalog of actively EXPLOITED vulnerabilities -> top priority
Context critical asset? Internet-exposed? compensated by another control?
-> priority = severity x exploitability (EPSS/KEV) x exposure x asset criticality

Prioritizing by CVSS alone wastes effort: a 9.8 on an internal, unexposed host matters less than a 7.5 on an exposed KEV.

Nessus / Tenable, Qualys, Rapid7 reference vulnerability scanners
OpenVAS/Greenbone open-source
Nuclei (see tool-nuclei) template-based detection, fast for web exposure
Authenticated scanning > unauthenticated: sees real patches/config, not just banners
Cloud/containers: Trivy, Grype (see dso-containers) and CSPM posture (see cloud)
- "vulnerability fatigue": thousands of findings with no prioritization -> nothing gets fixed
- scanner false positives -> validate before opening a thousand tickets
- uninventoried assets (shadow IT) -> blind spots the attacker does see
- a patch that doesn't deploy or breaks production -> change management (def-patch)
  • Start from a reliable inventory (see System hardening) and regular authenticated scanning.
  • Prioritize with EPSS + CISA KEV + business context, not just CVSS.
  • Agree remediation SLAs by severity/exposure and measure compliance and trend.
  • Close the loop: verify remediation; integrate with patching (Patch management) and risk (Risk management).
  • Equifax (2017): an unpatched Apache Struts (CVE-2017-5638) for months → a 147M-person breach.
  • Log4Shell (CVE-2021-44228): the inventory/SBOM decided who could respond fast.
  • The CISA KEV catalog exists precisely to prioritize what’s actually being exploited.
  • Reliable asset/software inventory (incl. cloud and containers)
  • Authenticated and regular scanning (not just the perimeter)
  • Prioritization by EPSS + CISA KEV + context, not just CVSS
  • Remediation SLAs by severity/exposure
  • False-positive validation before opening tickets
  • Post-remediation verification (re-scan)
  • Trend and coverage metrics; integration with def-patch