The cycle
Know what you have through an asset inventory. Find weaknesses through vulnerability scanning, attack surface management, penetration tests, code analysis and vendor advisories. Prioritise them. Remediate by patching, changing configurations or applying compensating controls. Verify that the fix worked. Report progress and repeat on a regular schedule.
Prioritising by real risk
Most organisations have far more findings than they can fix at once, and a CVSS score alone is not enough to decide. Better prioritisation combines severity with whether the vulnerability is being actively exploited, for example if it appears in the CISA Known Exploited Vulnerabilities catalogue, the probability of exploitation, whether the system is exposed to the internet and how critical the asset is.
Making it work
Define remediation deadlines by severity, assign an owner to each system, track exceptions with a documented risk acceptance, and measure the time to remediate and the number of overdue findings. Patch management handles most fixes, but configuration issues and custom code need their own processes.
Where it shows up in compliance
ISO 27001 requires information about technical vulnerabilities to be obtained, exposure to be evaluated and appropriate measures to be taken (Annex A 8.8). NIS2 lists vulnerability handling and disclosure among its minimum measures, and the ENS, SOC 2, PCI DSS and cyber insurers all ask how vulnerabilities are managed.




