Vulnerability management
Vulnerability management is the continuous process of identifying security weaknesses, ranking them by real risk, fixing them and verifying the fix.
What is vulnerability management?
Vulnerability management is the continuous process of identifying security weaknesses, ranking them by real risk, fixing them and verifying the fix.
Plain and technical
Scanning finds problems. Vulnerability management is the work of deciding which ones matter most, getting them to the right people, and confirming they were actually fixed.
Effective vulnerability management deduplicates findings across scanners and across services sharing base layers, ranks by environmental exposure rather than severity score alone, assigns ownership from a live service inventory, tracks remediation against targets set by exposure class, and verifies closure by rescanning the rebuilt artifact rather than accepting a status change.
What it looks like in practice
Nearby vocabulary
DevSecOps
DevSecOps is the practice of integrating security verification into the software delivery process rather than applying it as a separate review at the end.
Software bill of materials
A software bill of materials is a machine-readable inventory of every component and dependency contained in a piece of software, including versions.
How DevOpsArk handles vulnerability management
Articles on this subject
Vulnerability management: turning a report into a work queue
How to make a twelve-thousand-row vulnerability report actionable: deduplication, exposure-based ranking, ownership and verified closure.
What is DevSecOps? Beyond "shift left"
What DevSecOps means in practice, why shifting left fails when the feedback is not actionable, and the practices that actually change security outcomes.
More definitions
See these concepts in a running system
A 30-minute walkthrough against your own infrastructure rather than a slide about the theory.