It connects technical evidence with asset and service context, threat information, ownership, remediation or mitigation decisions, exceptions, and measurement. The practice is broader than running scanners or installing patches, and it continues as systems and evidence change.
A useful program establishes repeatable workflows from intake through closure, including reassessment after a fix or compensating control. Priorities should reflect likely exposure and organizational consequence, not a scanner label or numerical severity score alone.
Key points
Operating cycleMaintain scope and ownership, collect findings from multiple sources, validate and deduplicate them, prioritize treatment, track decisions, and verify that the intended risk reduction occurred.
Treatment optionsRemediation may include updating, reconfiguring, redesigning, removing, or replacing an affected component; mitigation and documented risk acceptance are distinct outcomes that still require review.
Prioritization inputsConsider affected assets, business criticality, attack paths, threat activity, exploit evidence, technical severity, exposure duration, control coverage, and the cost and risk of treatment.
Important limitationVulnerability management cannot guarantee that every weakness will be discovered or corrected, and closing a ticket, passing a rescan, or meeting a service target does not by itself demonstrate acceptable risk.