Product segment / VM

Vulnerability & exposure management

Find weaknesses, establish their context, and track useful remediation rather than chasing a single severity score.

The job to be done

Choose which exposure to reduce next, then verify that the risk changed.

What goes in

  • Asset inventory and ownership
  • Scanner and configuration findings
  • Threat, exploitation, and exposure context

What should come out

  • Prioritized remediation work
  • Exceptions with owners and expiry
  • Evidence of verification and residual risk

Questions worth asking

  1. How do we measure assets that were not successfully assessed?
  2. Can findings be linked to an owner and validated after remediation?
  3. How does known exploitation affect the queue?

A useful evaluation exercise

Compare an internet-facing exploited weakness with a high-severity issue on an isolated test system. Explain which uncertainty you would resolve first.

Find your next idea.

Tip: press / to open search. Escape closes this window.