GLOSSARY logo

GLOSSARY

THE TECHNICAL LANGUAGE OF DIGITAL B2B INFRASTRUCTURE

PRACTICE
CYBERSECURITY

Vulnerability Management

The continuous practice of identifying, assessing, prioritising, remediating, and verifying weaknesses across systems, software, devices, and services.


BUSINESS RELEVANCE

Effective vulnerability management reduces exploitable exposure, focuses scarce remediation capacity on material risk, supports assurance obligations, and provides leadership with measurable security debt.


IMPLEMENTATION EXAMPLE

An organisation combines authenticated scanning, cloud inventory, threat intelligence, and service criticality to prioritise an internet-facing exploited flaw, patch it under an emergency change, and rescan to verify closure.


LIMITATIONS

Scanner severity alone is not business risk, and complete elimination is unrealistic. Unknown assets, false positives, unsafe patches, weak ownership, and unverified remediation leave material exposure.


TECHNICAL EXPLANATION

A programme maintains asset context, discovers vulnerabilities and misconfigurations, enriches findings with exploitability and business impact, assigns treatment, deploys patches or compensating controls, validates remediation, manages exceptions, and monitors coverage and ageing.


Secondary Topics

Systems Architecture

Sources

NIST CSRC — Vulnerability Management glossary — https://csrc.nist.gov/glossary/term/vulnerability_management; NIST SP 800-40 Rev. 4 — Guide to Enterprise Patch Management Planning — https://csrc.nist.gov/pubs/sp/800/40/r4/final