Continuous program to identify, assess, prioritize, remediate, and verify vulnerabilities across assets.
Definition
Includes asset inventory, scanning, risk scoring, remediation workflows, verification, and reporting. Often includes patch SLAs and exception handling.
In plain English
Continuous program to identify, assess, prioritize, remediate, and verify vulnerabilities across assets.
Why this matters
Why it matters: Reduces attack surface and helps protect systems processing personal data.
Example
Example: Maintain an asset inventory, set patch SLAs (e.g., critical within 7 days), verify fixes, and track mean time to remediate.
We use essential cookies so the site works (language, security). With your permission, we also collect anonymous usage statistics to improve the site. No ads, no third-party trackers.
Privacy policy.