The Vulnerability Lifecycle: Managing vulnerabilities systematically through an end-to-end framework: discovery, triage, risk prioritization, remediation (repatching or mitigation), and post-remediation verification.
Vulnerability Scanning (Nessus, Qualys, Tenable): Performing network sweeps and target system analysis, contrasting non-destructive credentialed scans (which log in to examine the local patch level) with non-credentialed scans (which probe public network interfaces and service banners).
CVSS Scoring Framework: Quantifying the severity of security vulnerabilities using the Common Vulnerability Scoring System, calculating overall scores by weighing immutable base metrics with temporal and environmental conditions.
False Positives & Remediation SLA Management: Validating automated scanning results to eliminate false alarms, establishing formalized risk exception and acceptance workflows, and tracking remediation deadlines according to Service Level Agreements (SLAs).