Feb 14, 2022

Top Five Vulnerability Management Failures and Best Practices

This is an easy to follow webinar fro David Hazar that talks about the top-5 failures and best practices in vulnerability management.



Top Five Failures in Vulnerability Management:

  1. We don't understand our asset management.
  2. We focus too much on prioritization.
  3. We only present facts and data.
  4. We accept too much risk on behalf of the organization
  5. We are not consistent.

 Notes:

  • Use API access to create inventory, and supplement/validate to ITAM.
  • Balance prioritization with root cause analysis.
  • Focus on the solutions with different solution groups and solution types.
  • Only Driver and Guardian are interested in facts/data (but not Pioneer and Integrator). 
  • Storytelling - build the story for leadership.
  • Uses owner-based, role-based, and team-based reporting.
  • Tracking invisible risks: exclusion.
  • Apply standardization, integration and automation
  • Use aging report for those who do nothing.

Best Practices:

  1.  Automate the reconciliation of inventory and process for obtaining contextual data.
  2. Don't just prioritize. Focus on the bigger picture.
  3. Learn to communicate more than just facts and data.
  4. Track risk and technical debt, and communicate it in the right way to the right people.
  5. Standardize, integrate, and automate your way to increased consistency.
  6. Automate everything (that can be automated).