Vulnerability management is a continuous process to identify, assess, prioritize, and remediate security weaknesses across IT assets. The method combines scanning, asset inventories, risk-based prioritization and coordinated remediation workflows. It aims to reduce attack surface, improve patching cadence, and clarify cross-team responsibilities.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Executable approach: can be applied and produces an outcome.
What organizes, connects, or makes decisions possible.
Vulnerability management is the continuous process of finding, assessing, fixing or consciously accepting vulnerabilities, and tracking their treatment.
The practice grew from the need to govern technical weaknesses across their lifecycle; NIST described it as an enterprise task in SP 800-40 Rev. 3 in 2012, while tools such as DefectDojo operationalize tracking.
Inventory sources and assets, assess exploitability and business impact, prioritize actions, verify remediation, and record residual risk.
A traceable list of findings with affected assets and current status.
Treatment order derived from technical danger, exposure, and business impact.
A technical or organizational action that reduces or removes a vulnerability.
Vulnerability management connects security findings with ownership, deadlines, and verifiable decisions.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.