Guidance
Vulnerability management
Advice, guidance and other resources for managing vulnerabilities.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Advice, guidance and other resources for managing vulnerabilities.
Page 8 of 12
Your vulnerability management process should always be evolving to keep pace with changes in your organisation’s estate, new threats or new vulnerabilities.
Your vulnerability management process should be actively verified and always evolving. You should put in place a feedback loop to help with this. Improvements could include reducing the update timescales, or ensuring asset discovery and management scans are completed and audited more frequently.
You should include a verification process to make sure that where a vulnerability has been fixed using a reconfiguration or mitigation, you have verified that the vulnerability is no longer present. If the mitigation is only a temporary workaround, you will need to keep monitoring it. This could be because another vulnerability emerges that compromises the workaround, a flaw means the workaround is no longer effective, or a vendor releases an update that should be installed in place of the temporary workaround. All of these cases should supersede any temporary measures.
Using third-party penetration tests is a good way to verify that the vulnerability management process is working as it should. The NCSC has guidance on penetration testing.
You should regularly review your vulnerability management process to keep pace with any changes in your organisation’s estate, for example, an architectural change which makes more services internet facing. New threats or newly discovered vulnerabilities are additional reasons to keep reviewing. Subscribing to security alerts from vendors, suppliers and services you use will alert you to developments that you can then reflect in your vulnerability management process.


