Vulnerability Management
What is Vulnerability Management?
The ongoing practice of identifying, evaluating, treating, and reporting on security vulnerabilities in systems and software. Vulnerability management programmes include regular scanning, risk-based prioritisation, and timely remediation.
Terms that appear alongside vulnerability management
Each of these is named in at least one of the same controls as vulnerability management. The number is how many controls name both.
- encryption 21 shared controls
- nist 19 shared controls
- incident response 19 shared controls
- penetration testing 18 shared controls
- audit 18 shared controls
- cybersecurity 17 shared controls
- remediation 16 shared controls
- authentication 15 shared controls
Frameworks that govern vulnerability management
What the standards actually require on vulnerability management
Requirements naming vulnerability management across 6 standards, quoted from the control text.
Define, monitor and report vulnerability identification and remediation metrics at set intervals.
CCM-TVM-10 · Vulnerability Management Metrics →Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
CIS-7.1 · Establish and Maintain a Vulnerability Management Process →Technical vulnerability management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.
ISO21434-25 · Technical vulnerability management →Cloud vulnerability management. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Operations & Monitoring.
NIST190-23 · Cloud vulnerability management →Operating systems, applications, and firmware must be patched within timescales appropriate to the severity of vulnerabilities and the Risk Profile of the contract.
DEFSTAN-PATCH · Patch and Vulnerability Management →Identify, prioritize, and remediate vulnerabilities through scanning, patching, and threat intelligence.
SOC3-VULN-MGT · Vulnerability Management →Questions people ask about vulnerability management
What is Vulnerability Management?
Why is Vulnerability Management important for compliance?
Which compliance frameworks address Vulnerability Management?
Where can I learn more about Vulnerability Management?
See how Vulnerability Management applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.