Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Vulnerability Management Operating Pack — Guide

Vulnerability Management Pack

Your scanner reports hundreds or thousands of issues. Nobody agrees which ones matter, who should fix them, or by when. This pack gives you ready-made documents to settle those three questions and keep them settled.

Is this for you?

This pack is for you if:

  • you have been made responsible for vulnerabilities, but security is not your only job;
  • findings keep piling up and old ones never seem to get fixed;
  • an auditor, regulator or customer is about to ask how you handle vulnerabilities.

You will need some way of scanning your systems. If you have none yet, start there.

Start with these three

You do not need all ten documents. Most teams get the biggest improvement from three:

  1. Risk Rating & Deadline Model — decides which findings to fix first and how long each may stay open. It looks at whether a weakness is being exploited and whether the system faces the internet, not just the scanner’s severity label.
  2. Weekly Triage & Remediation Procedure — a 30-minute weekly routine: look at new urgent findings, give each one an owner, chase what is late.
  3. Remediation Tracker — one list of open findings with owner, deadline and status. A finding only counts as fixed when a new scan confirms it.

Not sure where you stand? Take the free 15-minute self-assessment first. It tells you which documents will help most.

A simple 90-day plan

WhenWhat to doYou’re done when
Month 1Agree priorities and deadlines with IT. Give every group of systems a named owner.IT and security accept the deadlines.
Month 2Run the weekly routine. Check which systems your scanner is missing.The weekly meeting has run four times.
Month 3Get the rules approved by management and send your first short report.Management has made a decision based on it.

Everything in the pack

DocumentWhat it doesFormat
Vulnerability Management StandardThe rules management approves: what is scanned, how often, and the deadlinesWord
Weekly Triage & Remediation ProcedureThe weekly routine, step by stepWord
Risk Rating & Deadline ModelHow to decide what gets fixed firstWord
Scan Coverage RegisterShows which of your systems are not being scannedExcel
Remediation TrackerTracks each finding until it is confirmed fixedExcel
Scanner Set-up ChecklistChecks your scanner is giving you complete, trustworthy resultsExcel
Metrics WorkbookFour numbers management can act on, calculated for youExcel
Self-AssessmentScores your current approach and suggests next stepsOnline / Excel
Management Briefing DeckSlides for your monthly or quarterly updatePowerPoint

Adapting it

  • Small team: the Standard asks for a weekly meeting, because the tightest deadline is 14 days and a finding that waits two weeks to be discussed is already late. If you have few new findings, you can meet every two weeks instead: change the Standard to say so, and keep giving urgent findings an owner as soon as they appear. You can skip the slide deck at first.
  • IT run by an outside provider: put the deadlines into your agreement with them, and ask for scan results, not just “done” updates.
  • Regulated firm (banking, investment, payments): keep the scan coverage register up to date, because supervisors will ask which critical systems are covered.

Not covered here

Installing patches (Patch Management pack), penetration testing, handling a live attack (Incident Management pack), and choosing a scanning product.