Skip to content

Vulnerability Management

What is Vulnerability Management?

The ongoing practice of identifying, evaluating, treating, and reporting on security vulnerabilities in systems and software. Vulnerability management programmes include regular scanning, risk-based prioritisation, and timely remediation.

Information Security

Each of these is named in at least one of the same controls as vulnerability management. The number is how many controls name both.

What the standards actually require on vulnerability management

Requirements naming vulnerability management across 6 standards, quoted from the control text.

Define, monitor and report vulnerability identification and remediation metrics at set intervals.

CCM-TVM-10 · Vulnerability Management Metrics
CIS Controls v82 controls

Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.

CIS-7.1 · Establish and Maintain a Vulnerability Management Process
ISO/SAE 214342 controls

Technical vulnerability management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.

ISO21434-25 · Technical vulnerability management
NIST SP 800-1902 controls

Cloud vulnerability management. Control from NIST SP 800-190 framework, domain: NIST SP 800-190: Cloud Operations & Monitoring.

NIST190-23 · Cloud vulnerability management

Operating systems, applications, and firmware must be patched within timescales appropriate to the severity of vulnerabilities and the Risk Profile of the contract.

DEFSTAN-PATCH · Patch and Vulnerability Management
AICPA SOC 31 control

Identify, prioritize, and remediate vulnerabilities through scanning, patching, and threat intelligence.

SOC3-VULN-MGT · Vulnerability Management

Questions people ask about vulnerability management

What is Vulnerability Management?
The ongoing practice of identifying, evaluating, treating, and reporting on security vulnerabilities in systems and software. Vulnerability management programmes include regular scanning, risk-based prioritisation, and timely remediation.
Why is Vulnerability Management important for compliance?
Vulnerability Management is a key concept in Information Security. Understanding vulnerability management helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Vulnerability Management?
Vulnerability Management appears in the requirement text of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, CIS Controls v8, ISO/SAE 21434, NIST SP 800-190, UK Defence Standard 05-138 - Cyber Security for Defence Suppliers. Across these standards we have identified 13 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Vulnerability Management?
Explore our compliance framework pages to see how vulnerability management applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Vulnerability Management applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.