Knowledge / vulnerability hardening acsc-glossary

Vulnerability management

Find, rank, fix, check. Known-exploited and exposure beat a 400-page scanner PDF.

VULNERABILITY MANAGEMENT LOOPDiscoverPrioritiseRemediateVerifyPrioritise with KEV, exposure, and asset value -- not CVSS alone.

Vulnerability management is the process of identifying weaknesses, putting them in a sensible order, and responding — patch, mitigate, or accept with an expiry. Assessment (design review, hands-on test, or scanning) feeds it. It is not the same as collecting CVEs like stamps.

Prioritise known-exploited, internet-facing, and crown-jewel systems. Include identity issues and misconfig. An open bucket does not wait for a CVSS before it is on the news.

Ownership, change windows, exceptions that die, and verification that the fix landed. That is the program.

Fact source: ASD's ACSC glossary. Wording is Cyberstack's.