Lab 16: Vulnerability Management Program
Objectives
Step 1: VM Programme Architecture
┌─────────────────────────────────────────────────────────┐
│ VULNERABILITY MANAGEMENT CYCLE │
│ │
│ DISCOVER ASSESS PRIORITISE REMEDIATE │
│ ┌────────┐ ┌─────────┐ ┌──────────┐ ┌──────────┐ │
│ │Asset │ │Scan with│ │CVSS + │ │Patch │ │
│ │Inventory│→│Tenable/ │→│EPSS + │→│deploy │ │
│ │(CMDB) │ │Qualys/ │ │Asset │ │Config │ │
│ │ │ │Rapid7 │ │criticality│ │change │ │
│ └────────┘ └─────────┘ └──────────┘ └────┬─────┘ │
│ │ │
│ VERIFY REPORT │ │
│ ┌────────────────────────────┐ ┌────────────▼──────┐ │
│ │Rescan after patch/fix │ │KPIs, SLA tracking,│ │
│ │Validate remediation │ │board metrics │ │
│ └────────────────────────────┘ └───────────────────┘ │
└─────────────────────────────────────────────────────────┘Step 2: CVSS v3.1 Score Calculator + EPSS Prioritisation
Step 3: CVSS v3.1 Metrics Explained
Metric
Values
Description
Value
Score
Description
Score
Rating
Step 4: EPSS — Exploit Prediction Scoring System
CVSS Score
EPSS Score
Priority
SLA
Step 5: Asset Inventory and CMDB Integration
Step 6: SLA Tiers and Exception Management
Priority
CVSS Range
Typical EPSS
SLA
Owner
Step 7: VM Programme Metrics
KPI
Definition
Target
Step 8: Capstone — Enterprise VM Programme Design
Summary
Concept
Key Points
Last updated
