Vulnerability Management Operating Pack — Guide
- Version 1.0
- Updated
- Next review
Vulnerability Management Pack
Your scanner reports hundreds or thousands of issues. Nobody agrees which ones matter, who should fix them, or by when. This pack gives you ready-made documents to settle those three questions and keep them settled.
Is this for you?
This pack is for you if:
- you have been made responsible for vulnerabilities, but security is not your only job;
- findings keep piling up and old ones never seem to get fixed;
- an auditor, regulator or customer is about to ask how you handle vulnerabilities.
You will need some way of scanning your systems. If you have none yet, start there.
Start with these three
You do not need all ten documents. Most teams get the biggest improvement from three:
- Risk Rating & Deadline Model — decides which findings to fix first and how long each may stay open. It looks at whether a weakness is being exploited and whether the system faces the internet, not just the scanner’s severity label.
- Weekly Triage & Remediation Procedure — a 30-minute weekly routine: look at new urgent findings, give each one an owner, chase what is late.
- Remediation Tracker — one list of open findings with owner, deadline and status. A finding only counts as fixed when a new scan confirms it.
Not sure where you stand? Take the free 15-minute self-assessment first. It tells you which documents will help most.
A simple 90-day plan
| When | What to do | You’re done when |
|---|---|---|
| Month 1 | Agree priorities and deadlines with IT. Give every group of systems a named owner. | IT and security accept the deadlines. |
| Month 2 | Run the weekly routine. Check which systems your scanner is missing. | The weekly meeting has run four times. |
| Month 3 | Get the rules approved by management and send your first short report. | Management has made a decision based on it. |
Everything in the pack
| Document | What it does | Format |
|---|---|---|
| Vulnerability Management Standard | The rules management approves: what is scanned, how often, and the deadlines | Word |
| Weekly Triage & Remediation Procedure | The weekly routine, step by step | Word |
| Risk Rating & Deadline Model | How to decide what gets fixed first | Word |
| Scan Coverage Register | Shows which of your systems are not being scanned | Excel |
| Remediation Tracker | Tracks each finding until it is confirmed fixed | Excel |
| Scanner Set-up Checklist | Checks your scanner is giving you complete, trustworthy results | Excel |
| Metrics Workbook | Four numbers management can act on, calculated for you | Excel |
| Self-Assessment | Scores your current approach and suggests next steps | Online / Excel |
| Management Briefing Deck | Slides for your monthly or quarterly update | PowerPoint |
Adapting it
- Small team: the Standard asks for a weekly meeting, because the tightest deadline is 14 days and a finding that waits two weeks to be discussed is already late. If you have few new findings, you can meet every two weeks instead: change the Standard to say so, and keep giving urgent findings an owner as soon as they appear. You can skip the slide deck at first.
- IT run by an outside provider: put the deadlines into your agreement with them, and ask for scan results, not just “done” updates.
- Regulated firm (banking, investment, payments): keep the scan coverage register up to date, because supervisors will ask which critical systems are covered.
Not covered here
Installing patches (Patch Management pack), penetration testing, handling a live attack (Incident Management pack), and choosing a scanning product.