Guidance
Vulnerability management
Advice, guidance and other resources for managing vulnerabilities.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Advice, guidance and other resources for managing vulnerabilities.
Page 7 of 12
There may sometimes be legitimate reasons not to update. The decision not to is a senior-level risk decision, and should be considered in the wider context of organisational risk management policy and practice.
You will probably find more issues than you have resources available to fix them. The decision not to fix an issue is, at root, a senior-level business risk decision, not an IT problem, and every organisation has its own risk appetite. There are many legitimate factors to consider here including cost, resources, complexity and other operational risks. The aim should still be to update by default and to minimise the need to make decisions on a case-by-case basis. The organisation’s risk management structures and staff need to be aware of the risk the organisation has chosen to tolerate at the present time.
Once a decision is made, record the reasons behind it, and ensure any remaining risk is considered in your organisation's overall risk management framework. This may be a risk register where you can group all the same risks such as ‘High: Unpatched externally exposed vulnerabilities allows initial compromise’. It's important that the business owns the risk, not the security team, and that it is visible to senior leaders.
The NCSC has separate guidance about Risk management.


