The job to be done
Choose which exposure to reduce next, then verify that the risk changed.
What goes in
- Asset inventory and ownership
- Scanner and configuration findings
- Threat, exploitation, and exposure context
What should come out
- Prioritized remediation work
- Exceptions with owners and expiry
- Evidence of verification and residual risk
Questions worth asking
- How do we measure assets that were not successfully assessed?
- Can findings be linked to an owner and validated after remediation?
- How does known exploitation affect the queue?
A useful evaluation exercise
Compare an internet-facing exploited weakness with a high-severity issue on an isolated test system. Explain which uncertainty you would resolve first.