Glossary

Vulnerability management

Vulnerability management is the continuous process of identifying security weaknesses, ranking them by real risk, fixing them and verifying the fix.

Short answer

What is vulnerability management?

Vulnerability management is the continuous process of identifying security weaknesses, ranking them by real risk, fixing them and verifying the fix.

Explained two ways

Plain and technical

In plain terms

Scanning finds problems. Vulnerability management is the work of deciding which ones matter most, getting them to the right people, and confirming they were actually fixed.

Technically

Effective vulnerability management deduplicates findings across scanners and across services sharing base layers, ranks by environmental exposure rather than severity score alone, assigns ownership from a live service inventory, tracks remediation against targets set by exposure class, and verifies closure by rescanning the rebuilt artifact rather than accepting a status change.

Example

What it looks like in practice

A raw scan returns 12,000 findings. Deduplication reduces it to 900 distinct vulnerabilities. Exposure ranking moves the internet-facing ones to the top, and rebuilding three shared base images closes most of the list.
Keep going

More definitions

See these concepts in a running system

A 30-minute walkthrough against your own infrastructure rather than a slide about the theory.