From the course: CompTIA SecurityX (CAS-005) Cert Prep

Unlock this course with a free trial

Join today to access over 25,300 courses taught by industry experts.

Attack surface management and reduction

Attack surface management and reduction

From the course: CompTIA SecurityX (CAS-005) Cert Prep

Attack surface management and reduction

- The first element of managing and reducing the attack surface has to be vulnerability management. This is the process of identifying, evaluating, treating and reporting on security vulnerabilities in systems and software that it runs on. Vulnerability management is essential for maintaining the security and integrity of an organization's IT infrastructure. It involves continuous monitoring and updating to address new vulnerabilities as they are discovered. Vulnerability management activities include vulnerability assessment, risk-based mitigation, ongoing scanning and monitoring, and developing policies and procedures. Here's a sample vulnerability management lifecycle. Now, let me just say this. On the SecurityX exam, by no means will they ever ask you "What is phase three of a certain lifecycle?" Or, "What is step four of this lifecycle?" It's basically common sense, or just thinking about it logically. Now, yes, CompTIA describes a vulnerability management lifecycle as a…

Contents