Vulnerability Management
The continuous process of identifying, evaluating, prioritising, remediating and verifying security vulnerabilities across an organisation's systems and software, and of reporting on the resulting risk.
Vulnerability management runs as a cycle. It starts with an accurate asset inventory, followed by discovery through authenticated and unauthenticated scanning, software composition analysis, penetration tests and vendor advisories. Findings are assessed for severity and exposure, prioritised, then remediated by patching, configuration changes or upgrades, or mitigated with compensating controls when no fix is possible. Rescanning verifies the outcome, and metrics show progress over time.
Unpatched known vulnerabilities are a common entry point for ransomware and other attacks, so the discipline is a core control in frameworks such as ISO/IEC 27001, the NIST Cybersecurity Framework and the CIS Critical Security Controls. It spans servers, endpoints, network devices, cloud resources, containers and applications, and, with additional care, industrial systems, where patching must respect availability requirements and vendor qualification.
Effective programmes prioritise by combining CVSS severity with exploitation evidence, asset criticality and exposure, rather than attempting to fix everything at once. Common measures include mean time to remediate by severity, the proportion of assets scanned and the number of overdue critical findings. Exceptions should be formally risk-accepted with an expiry date. In OT environments, vendor guidance and site change-management procedures govern patching decisions.
Key points
- A continuous cycle: discover, assess, prioritise, remediate and verify.
- Depends on a complete and current asset inventory.
- Prioritisation combines severity, exploitation evidence and asset value.
- Mean time to remediate is a common performance measure.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- Common Vulnerabilities and Exposures (CVE)Cybersecurity & Compliance
- Common Vulnerability Scoring System (CVSS)Cybersecurity & Compliance
- Vulnerability Assessment and Penetration Testing (VAPT)Cybersecurity & Compliance
- Software Composition Analysis (SCA)Cybersecurity & Compliance
- Threat IntelligenceCybersecurity & Compliance
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
Terms that refer to Vulnerability Management
- Cyber Resilience Act (CRA)Cybersecurity & Compliance
- Payment Card Industry Data Security Standard (PCI DSS)Cybersecurity & Compliance
- Penetration TestingCybersecurity & Compliance
- RansomwareCybersecurity & Compliance
- Security MisconfigurationCybersecurity & Compliance
- SOC 2Cybersecurity & Compliance
- Software Bill of Materials (SBOM)Cybersecurity & Compliance
- Zero-Day VulnerabilityCybersecurity & Compliance