Home/Glossary/Vulnerability Management

Vulnerability Management

The continuous process of identifying, prioritizing, and remediating security weaknesses in systems and applications.

Security OperationsAlso called: "vuln management"

Effective vulnerability management balances scan coverage with pragmatic prioritization so teams fix the issues that matter most.

Lifecycle steps

  • Discover assets and the software they run.
  • Assess vulnerabilities via scanning, penetration testing, and threat intelligence.
  • Prioritize based on exploitability, business impact, and exposure.
  • Remediate through patching, configuration changes, or compensating controls.

Modern practices

  • Align findings with frameworks like CVSS, KEV, and exploit intelligence.
  • Integrate with ticketing systems to assign clear owners.
  • Measure patch latency for critical systems.