Vulnerability management
Find, rank, fix, check. Known-exploited and exposure beat a 400-page scanner PDF.
Vulnerability management is the process of identifying weaknesses, putting them in a sensible order, and responding — patch, mitigate, or accept with an expiry. Assessment (design review, hands-on test, or scanning) feeds it. It is not the same as collecting CVEs like stamps.
Prioritise known-exploited, internet-facing, and crown-jewel systems. Include identity issues and misconfig. An open bucket does not wait for a CVSS before it is on the news.
Ownership, change windows, exceptions that die, and verification that the fix landed. That is the program.
Fact source: ASD's ACSC glossary. Wording is Cyberstack's.
