官术网_书友最值得收藏!

Vulnerability management

It is very important to note that many of the things that cause an all-hands-on-deck situation relate to how an enterprise information system is managed. If an enterprise information system is not regularly patched, then this leads to an all-hands-on-deck situation.

Vulnerability management is the process of:

  • Identifying vulnerabilities that are applicable to your information system:
    • Vulnerabilities can be identified through the use of enterprise vulnerability management tools such as Nessus
    • Additionally, the information security professional should be reading information security blogs and should be subscribed to the security sites for the vendors that they use
  • Triaging vulnerabilities that are applicable to your information system:
    • The information security professional must determine the risk that a given vulnerability presents to the organization and communicate that risk effectively
    • It must be clearly represented whether this is an all-hands-on-deck or a planned approach to the vulnerability mitigation exercise
  • Researching, planning, and deploying mitigations to applicable vulnerabilities:
    • There may be multiple tasks that makeup vulnerability mitigation. The information security professional must fully understand these steps, effectively communicate these steps to stakeholders, and completely deploy the appropriate countermeasure to adequately mitigate the vulnerability.
  • Monitoring the information systems to ensure that the vulnerabilities have been fully mitigated:
    • You must ensure that vulnerabilities have been fully mitigated within an information system
    • Utilizing a vulnerability assessment tool for this stage will allow you to continuously assess your information system during vulnerability mitigation to assess your progress and understand when you have met your goal
主站蜘蛛池模板: 龙江县| 广灵县| 项城市| 连城县| 武平县| 阜新| 开远市| 嵊泗县| 班戈县| 苏州市| 昌黎县| 芮城县| 融水| 康定县| 兴和县| 蕲春县| 宁强县| 卫辉市| 永寿县| 文成县| 合山市| 射阳县| 平度市| 合阳县| 托里县| 浑源县| 丰都县| 鸡泽县| 天台县| 承德市| 平果县| 余庆县| 皮山县| 前郭尔| 临潭县| 天柱县| 曲松县| 海丰县| 和平县| 灌云县| 喀喇沁旗|