[{"data":1,"prerenderedAt":164},["ShallowReactive",2],{"wissen-en-vulnerability-management":3,"wissen-related-en-vulnerability-management":153},{"id":4,"title":5,"body":6,"description":132,"extension":133,"lang":134,"meta":135,"navigation":136,"path":137,"related":138,"seo":143,"short":144,"sitemap":145,"stem":146,"synonyms":147,"updated":151,"__hash__":152},"wissenEn\u002Fen\u002Fwissen\u002Fvulnerability-management.md","Vulnerability Management",{"type":7,"value":8,"toc":120},"minimark",[9,13,18,21,25,60,64,67,71,74,78,81,85,88,92],[10,11,12],"p",{},"Vulnerability management is the ongoing process of detecting vulnerabilities in servers, applications, network devices and cloud resources, prioritising them by risk, fixing them and evidencing the fix. The process is cyclical: new systems, new software versions and newly published vulnerabilities (CVEs) every day ensure it is never finished.",[14,15,17],"h2",{"id":16},"why-vulnerability-management-matters","Why vulnerability management matters",[10,19,20],{},"A large share of successful attacks exploits vulnerabilities for which a patch already existed at the time of the attack. The gap is rarely in knowing that a vulnerability exists but in deciding which of the hundreds or thousands of findings must be fixed first and who does it. Regulations such as NIS2 and DORA and standards such as ISO 27001 therefore explicitly require a documented process for handling vulnerabilities, not just an occasional scan.",[14,22,24],{"id":23},"how-vulnerability-management-works","How vulnerability management works",[26,27,28,36,42,48,54],"ol",{},[29,30,31,35],"li",{},[32,33,34],"strong",{},"Inventory",": Which systems and technologies are in use? Without a current inventory every scan remains incomplete.",[29,37,38,41],{},[32,39,40],{},"Detection",": Network and web scans, authenticated checks on hosts, configuration audits in the cloud and matching of the technology inventory against new CVEs.",[29,43,44,47],{},[32,45,46],{},"Prioritisation",": The CVSS score describes theoretical severity. For the order of remediation, additional questions count: is the vulnerability actually being exploited (EPSS, CISA KEV)? Is an exploit public? Is the system reachable from the internet? How critical is it for the business?",[29,49,50,53],{},[32,51,52],{},"Remediation",": Patch, change configuration, shut down the service or accept the risk with justification. Ownership must be clear, usually via tickets in Jira or ServiceNow.",[29,55,56,59],{},[32,57,58],{},"Evidence",": A retest confirms the fix; reports document the status for audit, management and insurers.",[14,61,63],{"id":62},"how-blacklensio-implements-vulnerability-management","How blacklens.io implements vulnerability management",[10,65,66],{},"blacklens.io brings external, internal (Sentry agent) and cloud findings together in one workflow. The vulnerability feed comprises more than 200,000 tests with daily updates. Every finding carries EPSS score and percentile, CISA KEV status with due date and ransomware flag, exploit and PoC availability, CVSS v3\u002Fv4 and the fixed version. The status workflow (opened, in progress, snoozed, risk accepted, closed) closes findings automatically after a successful re-scan; snoozed findings reopen after 30 days. New CVEs are checked in real time against the technology inventory and verified automatically in the Threat Center.",[14,68,70],{"id":69},"is-the-cvss-score-enough-for-prioritisation","Is the CVSS score enough for prioritisation?",[10,72,73],{},"No. CVSS rates severity assuming the worst case but says nothing about whether anyone is actually exploiting the vulnerability. Combining CVSS, EPSS, CISA KEV, exploit availability and reachability typically shrinks the list of urgent findings to a small fraction.",[14,75,77],{"id":76},"how-often-should-you-scan","How often should you scan?",[10,79,80],{},"Externally reachable systems continuously, internal systems at least weekly, complemented by a real-time match of the technology inventory against newly published CVEs. A quarterly scan gives attackers far too much time.",[14,82,84],{"id":83},"what-is-the-difference-between-vulnerability-management-and-a-pentest","What is the difference between vulnerability management and a pentest?",[10,86,87],{},"Vulnerability management is automated, broad and continuous. A penetration test is manual, deep and point-in-time: it finds logic flaws and chains vulnerabilities that no scanner detects. The two complement each other; PTaaS joins the results in one workflow.",[14,89,91],{"id":90},"related-terms","Related terms",[93,94,95,102,108,114],"ul",{},[29,96,97],{},[98,99,101],"a",{"href":100},"\u002Fen\u002Fwissen\u002Fepss","EPSS",[29,103,104],{},[98,105,107],{"href":106},"\u002Fen\u002Fwissen\u002Fcisa-kev","CISA KEV",[29,109,110],{},[98,111,113],{"href":112},"\u002Fen\u002Fwissen\u002Fcontinuous-threat-exposure-management","Continuous Threat Exposure Management (CTEM)",[29,115,116],{},[98,117,119],{"href":118},"\u002Fen\u002Fwissen\u002Fpenetration-testing-as-a-service","Penetration Testing as a Service (PTaaS)",{"title":121,"searchDepth":122,"depth":122,"links":123},"",3,[124,126,127,128,129,130,131],{"id":16,"depth":125,"text":17},2,{"id":23,"depth":125,"text":24},{"id":62,"depth":125,"text":63},{"id":69,"depth":125,"text":70},{"id":76,"depth":125,"text":77},{"id":83,"depth":125,"text":84},{"id":90,"depth":125,"text":91},"Vulnerability management explained: the cycle of detecting, prioritising, fixing and evidencing, why CVSS alone is not enough and how blacklens.io maps the process.","md","en",{},true,"\u002Fen\u002Fwissen\u002Fvulnerability-management",[139,140,141,142],"epss","cisa-kev","continuous-threat-exposure-management","penetration-testing-as-a-service",{"title":5,"description":132},"Vulnerability management is the ongoing process of detecting vulnerabilities in systems, prioritising them by risk, fixing them and evidencing the fix.",{"loc":137},"en\u002Fwissen\u002Fvulnerability-management",[148,149,150],"VM","Vulnerability management process","Vulnerability remediation","2026-09-14","MWNYwRHnXC1zq1R16EclX3NiFrSm6iffZyfoYXj2h5o",[154,157,159,162],{"path":106,"title":155,"short":156},"CISA KEV (Known Exploited Vulnerabilities)","The CISA KEV catalogue is a list maintained by the US agency CISA of vulnerabilities proven to be exploited in real attacks, each with a remediation due date.",{"path":112,"title":113,"short":158},"CTEM is a programme described by Gartner with five phases (scoping, discovery, prioritisation, validation, mobilisation) that reduces the attack surface continuously instead of at points in time.",{"path":100,"title":160,"short":161},"EPSS (Exploit Prediction Scoring System)","EPSS is a scoring system by FIRST that estimates for every CVE the probability that it will actually be exploited within the next 30 days, as a value between 0 and 1.",{"path":118,"title":119,"short":163},"PTaaS delivers manual penetration tests through a platform instead of a PDF: findings appear continuously, retests are built in, and tests repeat on a regular schedule.",1789638256034]