# What is Vulnerability Management?

> Vulnerability management is the ongoing, risk-informed process of finding, recording, evaluating, prioritizing, treating, and verifying vulnerabilities across technology and its lifecycle.

- Canonical URL: https://yellowcube.eu/glossary/vulnerability-management/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It connects technical evidence with asset and service context, threat information, ownership, remediation or mitigation decisions, exceptions, and measurement. The practice is broader than running scanners or installing patches, and it continues as systems and evidence change.

A useful program establishes repeatable workflows from intake through closure, including reassessment after a fix or compensating control. Priorities should reflect likely exposure and organizational consequence, not a scanner label or numerical severity score alone.

### Key points

- **Operating cycle:** Maintain scope and ownership, collect findings from multiple sources, validate and deduplicate them, prioritize treatment, track decisions, and verify that the intended risk reduction occurred.
- **Treatment options:** Remediation may include updating, reconfiguring, redesigning, removing, or replacing an affected component; mitigation and documented risk acceptance are distinct outcomes that still require review.
- **Prioritization inputs:** Consider affected assets, business criticality, attack paths, threat activity, exploit evidence, technical severity, exposure duration, control coverage, and the cost and risk of treatment.
- **Important limitation:** Vulnerability management cannot guarantee that every weakness will be discovered or corrected, and closing a ticket, passing a rescan, or meeting a service target does not by itself demonstrate acceptable risk.

### Related terms

[Vulnerability](<https://yellowcube.eu/glossary/vulnerability/>) · [Vulnerability assessment](<https://yellowcube.eu/glossary/vulnerability-assessment/>) · [Vulnerability scanning](<https://yellowcube.eu/glossary/vulnerability-scanning/>) · [Continuous threat exposure management (CTEM)](<https://yellowcube.eu/glossary/continuous-threat-exposure-management/>) · [Virtual patching](<https://yellowcube.eu/glossary/virtual-patching/>) · [Patch management](<https://yellowcube.eu/glossary/patch-management/>)

### Sources

[NIST Cybersecurity Framework 2.0](https://www.nist.gov/cyberframework) · [NIST SP 800-53 Rev. 5](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) · [CISA: Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

