Take advantage of our economies of scale and visibility into billions of attacks to help protect your organization from cyber threats. Utilize the intelligence of our Big Data Analytics Platform, Data Scientists, and our 24×7 Security Operations Center Analysts to implement a security strategy that fits your enterprise.
Vulnerability Management is widely described as the practice of identifying, classifying, remediating and mitigating vulnerabilities. It is also described as the discovery, reporting, prioritization, and response to vulnerabilities in your network.
Vulnerability management is no longer an option for organizations, in fact, it is becoming required by multiple compliance, audit and risk management frameworks. SANS Security Controls lists continuous vulnerability assessment and remediation as number four on their most recent framework citing that it needs to “Continuously acquire, assess, and take action on new information in order to identify vulnerabilities, and to remediate and minimize the window of opportunity for attackers.”
You can’t stop what you can’t see. That’s why vulnerability management should be the foundation of your security program because you have to know what is on your network in order to monitor and protect it. A good vulnerability management program can help you proactively understand the risks to ever asset in order to keep it safe.
Four Stages of Vulnerability Management
Build a list of every computing asset you have on your network and then build a database that vulnerability management solutions can use. This list will be constantly changing so it will need to be constantly refreshed. However, make sure all assets are found, categorized and assessed.
This will include all data from your network assets in their current state. Typically, this is done with a vulnerability scanner which will produce a report of all known vulnerabilities on any assets in your network.
Depending on the size of your organization or the age of your assets, the list of known vulnerabilities can be pages long. In this step, the vulnerabilities will be ranked from highest to lowest risk depending on multiple factors. Your vulnerability management solution should prioritize these by the MITRE Common Vulnerabilities and Exposure (CVE) Score and by the unique risk they pose to your organization.
The goal of discovering, reporting and prioritizing your vulnerabilities is so that your team can focus its remediation to the largest risks in your network. Once you remediate or patch these vulnerabilities, you should conduct a penetration test to ensure that the patch is valid and that you no longer have an issue before moving on to the next vulnerability.