- Vulnerability scanners, industry alerts, and penetration tests are revealing more and more vulnerabilities, and it is unclear how to manage them.
- Organizations are struggling to prioritize the vulnerabilities for remediation, as there are many factors to consider, including the threat of the vulnerability and the potential remediation option itself.
Our Advice
Critical Insight
- Patches are often seen as the only answer to vulnerabilities, but these are not always the most suitable solution.
- Vulnerability management does not equal patch management. It includes identifying and assessing the risk of the vulnerability, and then selecting a remediation option which goes beyond just patching alone.
- There is more than one way to tackle the problem. Leverage your existing security controls in order to protect the organization.
Impact and Result
- At the conclusion of this blueprint, you will have created a full vulnerability management program that will allow you to take a risk-based approach to vulnerability remediation.
- Assessing a vulnerability’s risk will enable you to properly determine the true urgency of a vulnerability within the context of your organization; this ensures you are not just blindly following what the tool is reporting.
- The risk-based approach will allow you prioritize your discovered vulnerabilities and take immediate action on critical and high vulnerabilities, while allowing your standard remediation cycle to address the medium to low vulnerabilities.
- With your program defined and developed, you now need to configure your vulnerability scanning tool, or acquire one if you don’t already have a tool in place.
- Lastly, while vulnerability management will help address your systems and applications, how do you know if you are secure from external malicious actors? Penetration testing will offer visibility, allowing you to plug those holes and attain an environment with a smaller risk surface.
Member Testimonials
After each Info-Tech experience, we ask our members to quantify the real-time savings, monetary impact, and project improvements our research helped them achieve. See our top member experiences for this blueprint and what our clients have to say.
9.8/10
Overall Impact
$39,229
Average $ Saved
19
Average Days Saved
Client
Experience
Impact
$ Saved
Days Saved
City of Birmingham
Guided Implementation
10/10
N/A
N/A
Best-advice from an experienced professional Worst- the issues with the current environment. Bob is always great!
University of Ottawa
Guided Implementation
10/10
N/A
5
Advices and discussions with the advisor.
Chapman University
Guided Implementation
10/10
$68,500
10
The best part was the expertise and professionalism brought to the project by Petar. Now only did he provide guidance and knowledge to the project,... Read More
Open Technology Solutions LLC
Guided Implementation
10/10
$68,500
10
Jon came in with great experience and advice based on his time working at the enterprise level in financial services.
Peel Regional Police
Guided Implementation
9/10
$5,000
10
Yolo County
Guided Implementation
9/10
$19,865
18
City of Atlanta / Atlanta Information Management (AIM)
Guided Implementation
10/10
N/A
20
Girl Guides of Canada
Guided Implementation
10/10
N/A
10
Noramco, LLC
Guided Implementation
10/10
$34,281
60
the experience was absolutely great. Mr Sooknanan experience and approaches are exceptional.
California Natural Resources Agency
Guided Implementation
10/10
N/A
32
Shastri proves to be a valuable asset to any conversation I've been apart of with him. He is knowledgeable and provides useful insights and recomme... Read More