From the course: Vulnerability Management: Assessing the Risks with CVSS, CISA KEV, EPSS, and SSVC
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
Assign vulnerablities for remediation
From the course: Vulnerability Management: Assessing the Risks with CVSS, CISA KEV, EPSS, and SSVC
Assign vulnerablities for remediation
- [Instructor] You've identified a big pile of vulnerabilities on lots of systems in your environment, and you've defined your risk approach so that you can prioritize them. Now, what do you do? Those critical and high-risk vulnerabilities aren't going to fix themselves. And as a security professional, you might not be the one to remediate them. That's why assigning vulnerabilities for remediation is a key component of a vulnerability management program. The first thing you need to know when assigning vulnerabilities for remediation is who to assign the work to. This may be easy in your environment. Server, workstation, and network vulnerabilities go to their respective teams. Or it could get really complex, especially in larger enterprises where you might have different teams responsible for specific software or types of systems, like Database, Middleware, Windows, and Linux. Once you know who to assign the vulnerability to, you need a method to provide the vulnerability information…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.