Frequently Asked Questions
What this playlist answers
5 questions this playlist covers — skim
them for a quick takeaway, or dive into the videos above for the full picture.
Vulnerability management is the continuous process of identifying, assessing, prioritizing, and remediating security weaknesses in systems, applications, and infrastructure to reduce exposure to cyberattacks.
CVE (Common Vulnerabilities and Exposures) is a publicly available catalog of known security vulnerabilities, each assigned a unique identifier. Security teams use CVEs to track and communicate about specific vulnerabilities.
CVSS (Common Vulnerability Scoring System) provides a numerical score from 0 to 10 indicating the severity of a vulnerability. Organizations use CVSS scores to prioritize which vulnerabilities require immediate remediation.
Vulnerability management identifies, assesses, and prioritizes security weaknesses across systems. Patch management focuses specifically on applying software updates that fix known vulnerabilities.
Common tools include vulnerability scanners, SIEM platforms, asset discovery tools, penetration testing frameworks, and threat intelligence feeds that help identify, prioritize, and track remediation of security weaknesses.