Vulnerability management

Identifying vulnerabilities

The methods: vulnerability scanning (Nessus and OpenVAS probing against a known-vuln database), application security (static, dynamic, package monitoring), penetration testing, and system and process audits.

The cycle: plan, test, implement, audit.

Threat intelligence feeds

Continuous streams of malware signatures, IoCs, and malicious IPs and URLs.

The sources: OSINT (free public sources like AlienVault OTX and SANS ISC), proprietary third-party feeds (subscription, refined: FireEye, McAfee, Symantec), information-sharing orgs (ISACs and ISAOs by industry), and the dark web.

Threats have shifted over time from server-side to client-side to mobile and cloud.

Responsible disclosure

The researcher privately notifies the org, they agree on a disclosure timeframe, then the researcher goes public after the fix.

Bug bounty programs (HackerOne, Bugcrowd, Synack) pay for validated findings: external scrutiny at low cost, but they need clear scope, communication channels, and legal safeguards.

Analyzing vulnerabilities

Prioritize with CVSS (Common Vulnerability Scoring System) by ease of exploitation, damage, and system importance. Classify by type (software flaw, config error, policy gap). CVE (Common Vulnerabilities and Exposures) uniquely identifies known vulnerabilities.

The Exposure Factor (EF) estimates the percentage of asset damage, and risk tolerance sets how fast you must remediate.

Response and remediation

Patching applies vendor updates. The other options: cyber insurance (covers breach and recovery costs), network segmentation (isolate to stop spread), and compensating controls (alternative measures when a standard control can’t be applied).

An exception is a temporary bypass for a business need with known risk. An exemption is a permanent waiver, often for legacy systems.

Validating remediation

Rescan devices after remediation (replicating the initial scan conditions), audit configurations and patches, then verify by testing (pen tests included) and user verification that services still work.

Confirm both that the vulnerability is gone and that the system is stable.

Reporting

Clear, concise, and confidential: a vulnerability report is a map for attackers.

Internal reporting is the first line; external reporting coordinates with vendors and shares non-sensitive details to CVE. Encrypt reports, store them securely, share on need-to-know, and give non-technical stakeholders an executive summary.