Question: Does the organization perform regular vulnerability assessments and remediate identified issues within defined timelines?
-
Objective — Why This Matters
Routine vulnerability scanning reveals weak points before attackers do. Closing findings promptly reduces exposure and strengthens compliance posture. -
Maturity Levels (0 – 5)
No vulnerability scanning.
Occasional manual scans without remediation tracking.
Quarterly internal scans; remediation recorded in spreadsheets.
Automated scanning; risk-based prioritization; SLAs applied.
Feeds to ticketing and SIEM; verification of fixes.
Continuous scanning and threat-intel correlation.
- How to Level Up
| From → To | Actions |
|---|---|
| 0 → 2 | Select internal/external scanners; run quarterly scans. |
| 2 → 3 | Automate scheduling; assign owners and SLAs. |
| 3 → 4 | Link to ticketing (Jira, GitHub Issues); verify closure. |
| 4 → 5 | Add continuous scanning and feed results to SIEM. |
-
People / Process / Technology Enablers
People – Security Ops Analyst, Infra Admin.
Process – Vulnerability remediation workflow with SLA tracking.
Technology – OpenVAS, Nessus Essentials, Wazuh, Grafana. -
Evidence Required
Latest scan reports, ticket logs, remediation evidence. -
Metrics / KPIs
• percentage of critical findings closed within SLA
• average time to remediate high vulnerabilities
• number of recurring findings across scans -
Low-Cost / Open-Source Options (MSME)
| Purpose | Tool | Notes |
|---|---|---|
| Scanning | OpenVAS / Nmap + Vulners | Automated discovery and assessment. |
| Reporting | Faraday Community | Aggregate results and assign owners. |
| Metrics | Wazuh / Grafana | Visualize trend closure rates. |
-
Common Pitfalls
Scanning without closure tracking; accepting false positives as excuses to ignore critical issues. -
Compliance Mapping
| Standard | Clauses / Notes |
|---|---|
| ISO 27001 | A.8.8 (Vulnerability management). |
| NIST CSF 2.0 | DE.CM-8 / PR.IP-12. |
| CERT-In 2022 | Quarterly VA/PT expectation. |
| NIRMATA Scoring | IS-Q03 ≥ Level 4 requires ticket-linked remediation verification. |