Threat and Vulnerability Management
What is Threat and Vulnerability Management?
An ongoing programme for identifying, evaluating, and addressing threats and vulnerabilities in an organisation's IT environment. Combines threat intelligence, vulnerability scanning, risk prioritisation, and remediation tracking.
Frameworks that govern threat and vulnerability management
What the standards actually require on threat and vulnerability management
Requirements naming threat and vulnerability management across 2 standards, quoted from the control text.
Keep approved policies and procedures for identifying, reporting and prioritising vulnerability remediation so systems are not left open to exploitation, and review them at least annually.
CCM-TVM-01 · Threat and Vulnerability Management Policy and Procedures →The software vendor must establish a threat and vulnerability management process that identifies, assesses, prioritizes, and remediates threats and vulnerabilities across the software lifecycle.
SSS-6.1 · Threat and Vulnerability Management →Questions people ask about threat and vulnerability management
What is Threat and Vulnerability Management?
Why is Threat and Vulnerability Management important for compliance?
Which compliance frameworks address Threat and Vulnerability Management?
Where can I learn more about Threat and Vulnerability Management?
See how Threat and Vulnerability Management applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.