Vulnerability management
Advice, guidance and other resources for managing vulnerabilities.
Pages
Page 2 of 12
Vulnerability management guidance

Principles to help organisations establish an effective vulnerability management process.
Implementing this guidance
This guidance intends to help organisations direct their efforts when it comes to vulnerability management and provides goals to aim for.
When you first start implementing a vulnerability management process, it’s easy to become overwhelmed by the number and nature of the issues you discover, so it's important to prioritise actions and activity. It's often best to start in a small or focused way and then grow the process to scale, for example by focussing only on vulnerabilities in critical systems.
Wider organisational relevance
A vulnerability management process shouldn’t exist in isolation. It is a cross-cutting effort and involves not just those working in IT operations, but also security and risk teams. Time, budget and risks should all be added to your organisation’s risk register, and you may need to involve your senior leaders, particularly if different teams report to different board members.
The NCSC’s Cyber Security Toolkit for Boards provides resources to help boards govern cyber risk more effectively.
Vulnerability management principles
This guidance lays out five principles intended to help organisations establish an effective vulnerability management process:
- 1. Put in place a policy to update by default
Apply updates as soon as possible, and ideally automatically, in line with our best-practice timescales.
- 3. Identify your assets
Understanding what systems and software you have on your technical estate, who is responsible for what, and which vulnerabilities are present.
- 4. Carry out assessments by triaging and prioritising
If updating to the latest version of the affected software doesn’t fix the reported vulnerability or misconfiguration, or there isn’t an update to address the issue yet, you will need a process to triage and prioritise.
- 5. The organisation must own the risks of not updating
There may sometimes be legitimate reasons not to update. The decision not to is a senior-level risk decision, and should be considered in the wider context of organisational risk management policy and practice.
- 6. Verify and regularly review your vulnerability management process
Your vulnerability management process should always be evolving to keep pace with changes in your organisation’s estate, new threats or new vulnerabilities.