JUNE 2022ENTERPRISE SECURITY| | 9Which vulnerabilities should be fixed first?Whereas IT teams often use risk values from a report to determine which vulnerabilities have the highest level of risk and should be addressed first, remediation should prioritize items that are being actively exploited in the wild, not just items that receive a high CVSS score. Many popular scanners will even help identify which vulnerabilities have publicly available exploits. Then, once these are addressed, remediation teams can begin addressing vulnerabilities according to their overall risk score, from highest to lowest, as time permits.Which vulnerabilities need to be addressed for compliance reasons?Although many vulnerabilities are addressed because of "true risk," some are addressed because of the risk perceived by regulations and audits. For example, having TLS v1.1 enabled on an internal web server hosting general data might not be considered a true risk by the organization's security team, but an auditor might see it as a reportable item that needs to be addressed. Thus, it is important to be familiar with and understand any compliance regulations applicable to the organization as well as any additional requirements by auditors in order to adjust remediation strategies accordingly.3. RemediateThe third step in vulnerability management is to fix the vulnerabilities before an attacker can exploit them (or an auditor can find them). Are vulnerabilities fixed within a reasonable timeframe?Most organizations scan for vulnerabilities and do their best to remediate discovered issues, but it is just as important to address these issues in a timely manner. Tracking how long it takes to address an issue once it has been discovered helps the security team understand how effectively and quickly they are lowering the organization's overall level of risk.4. VerifyFor the fourth step, after a vulnerability is believed to have been remediated, a new vulnerability scan should be run to confirm the issue was indeed addressed.THE BEST WAY FOR COMPANIES TO PREVENT A CYBER ATTACKER FROM FINDING AND EXPLOITING VULNERABILITIES IS TO FIND THEIR VULNERABILITIES FIRST, AND TO REMEDIATE ANY WEAKNESSES--BEFORE AN ATTACKER DOESAre vulnerabilities remediated on the first attempt?Especially when starting a new vulnerability management Program, remediation teams can struggle to fix issues correctly on the first try. Tracking this information helps the remediation teams become more effective over time while continuing to lower overall risk. 5. MonitorFinally, organizations must continually monitor for the announcement of new vulnerabilities which could affect their company. Would the security team know when action needs to be taken for a new vulnerability that is announced?This is an area where many organizations can struggle if they are not organized. Using a central platform to track a complete inventory of the company's hardware and software implementations helps ensure that when a new vulnerability is announced, the security team can more quickly determine if the organization is impacted. ES
<
Page 8 |
Page 10 >