enterprisesecuritymag

APRIL - 2021ENTERPRISE SECURITY| | 9repositories to determine if application code is leveraging vulnerable libraries or methodologies. Automation makes the bug hunting quicker and at scale. This has allowed businesses to determine what code requires an update even if developers are not currently working on the code, or worse yet, when the code becomes legacy and is not being maintained.Translating vulnerabilities into risks to help business execs prioritize While these advancements have allowed businesses to rapidly discover new vulnerabilities within new technologies as well as to discover vulnerabilities in new ways, the increased number of vulnerabilities found can make prioritization difficult. As a result, making a determination of the risk individual vulnerabilities have can be a cumbersome and difficult process. When combined with the continuous influx of new vulnerabilities types found in the wild, achieving acceptable vulnerability risk levels can be a constantly moving target, if not a seemingly insurmountable task. In order to address this challenge, most enterprises have adopted models where vulnerability management responsibilities and particularly remediation responsibilities are shared across multiple stakeholders. The vulnerability findings therefore are important to several stakeholders in the organization who have to make decisions or direct their teams to take action. Advancements in IT Service Management (ITSM) have helped bring businesses closer to the goal of having automated vulnerability management processes. As a result, ITSM vendors have incorporated features specifically targeted at assisting in the resolution of challenges associated with communication of tasks, and tracking of activity. The increased depth with which ITSM tools can support vulnerability management operations is evolving quickly. However, the ability to convert tasks into risk understanding is often still a difficult task for enterprises leveraging ITSM alone. As a result there have been several innovations that have increased the maturity of vulnerability prioritization tools which seek to unify risk understanding of individual vulnerabilities despite the method or technology layer with which vulnerabilities were found.Vulnerability prioritization technologies have made large leaps forward in interoperability, and in the universal scoring of vulnerabilities in order to assist businesses in understanding vulnerabilities within their individual context. These innovations assist businesses in honing their processes to address vulnerabilities in a manner that is meaningful to risk.Outlook on the FutureThe combination of innovations that assist businesses in discovering more vulnerabilities and advancements in technologies that assist businesses in addressing vulnerabilities offers hope in the attempt to manage vulnerability risk. The value in these innovations lies within how they are adopted. As news of the latest breaches push organizations to ask questions about whether they are vulnerable to similar attack vectors, these technologies could certainly assist in addressing their questions in an efficient manner. In tandem, however, businesses should determine how these technologies could be leveraged in a continuous manner. ESJoe Nocera
< Page 8 | Page 10 >