Threat

Vulnerability Management

Vulnerability management is the ongoing process of finding weaknesses, assessing them by risk, and verifying their remediation.

Vulnerability management is the ongoing process of finding weaknesses, assessing them, remediating them, and verifying their remediation. It is a continuous cycle, not a one-time project.

How it works

Scanners regularly check servers, workstations, network devices, and cloud resources for known vulnerabilities. The results are then assessed based on severity, exploitability, and system criticality. Remediation tasks, such as applying a patch or changing a configuration, are assigned to the responsible teams. A subsequent scan confirms that the vulnerability is closed. Key metrics can show the average time to remediation.

For example, a scan might identify 4,000 vulnerabilities. The team first filters for actively exploited weaknesses on internet-facing systems. This might leave 30 findings. These are then remediated within seven days. The remainder are addressed according to fixed deadlines based on severity.

What to look out for

  • Prioritise based on the real risk to your organisation. The CVSS score alone is not enough.
  • Set deadlines for each severity level and measure compliance.
  • Assign each vulnerability to a responsible team.
  • Include all systems, such as cloud, containers, and network devices.
  • Document exceptions where a patch is not possible and plan compensating controls.

Switzerland and regulation

FINMA expects financial institutions to have effective vulnerability management. ISO 27001 includes a specific control for this topic. For critical infrastructure operators, it is a basic measure according to the Swiss federal ICT minimum standard.

Relevance for the SOC

The SOC uses information about vulnerabilities to classify Alerts. An attack attempt on a vulnerable system is more urgent than on a patched one. Conversely, the SOC reports any weaknesses discovered during incident response.

Typical mistakes

A common issue is creating long reports that lead to no action. Another mistake is performing scans without system credentials, which overlooks many weaknesses. Missing responsibilities can also delay remediation more than technical hurdles.

How we implement it

We offer Vulnerability Management as a Security Service. The results feed into the assessment of Alerts in our SOC.

How ANOMAL implements this