CONTACT US

MANAGED CYBER SECURITY SERVICES

Managed Vulnerability Management Service

What is Vulnerability Management?

Vulnerability management is the process of detecting, evaluating, eliminating, and reporting vulnerabilities in systems and software running on those systems. This process is vital for businesses to prioritize potential threats and minimize attack surfaces.

Vulnerabilities refer to technological weaknesses that allow attackers to compromise a product and the information it contains. This process needs to be performed continuously to keep up with new systems added to networks over time, changes made to systems, and the discovery of new vulnerabilities. The cycle starts with vulnerability scanning and ends with the closure of the vulnerability by the responsible professionals and the reporting of the process. Security scanning is just one stage of this lifecycle.

What are the Stages of Vulnerability Management?

Vulnerability Management consists of four steps as follows:

Identifying Vulnerabilities

At the heart of a typical vulnerability management solution is a vulnerability scanner. The scanning process consists of four stages:

1- Scanning network-accessible systems, 
2- Identifying the ports on the scanned systems and the services listening on those ports, 
3- Logging into the systems remotely to collect detailed system information if possible, 
4- Correlating the system information with known vulnerabilities.

Vulnerability scanners can identify various systems running on the network, such as laptops and desktops, virtual and physical servers, databases, firewalls, switches, and printers. Identified systems are analyzed for different characteristics, such as the operating system, open ports, installed software, user accounts, file system structure, and system configurations. This information is then used to associate known vulnerabilities with the scanned systems. To perform this association, vulnerability scanners make use of a vulnerability database that contains a list of publicly known vulnerabilities.

Properly configuring vulnerability scans is an important part of the vulnerability management process. Vulnerability scanners can sometimes disrupt the networks and systems they scan. For this reason, vulnerability scans should be scheduled to coincide with business downtime, especially when the process puts a strain on systems.

If some systems on the network become unstable or behave erratically when scanned, they may need to be excluded from vulnerability scans or the scans may need to be fine-tuned to make the application less intrusive. Adaptive scanning is a new approach to further automate and streamline vulnerability scans based on changes in the network. For example, when a new system is connected to the network, a vulnerability scanner will scan only that system as soon as possible, rather than waiting for the weekly or monthly scanning schedule for the entire network.

Many EDR software solutions allow vulnerability management solutions to continuously collect vulnerability data from systems without the need for network scanning.

Assessing Vulnerabilities

Once vulnerabilities have been identified, the risks they pose need to be assessed to be addressed in line with the organization's risk management strategy. Vulnerability management solutions clarify the security posture through risk scoring methods such as the Common Vulnerability Scoring System (CVSS). These scores help determine which vulnerabilities should be focused on first, but the actual risk from any vulnerability depends on a number of other factors beyond these off-the-shelf risk ratings and scores.

Here are some examples of additional factors to consider when assessing vulnerabilities:

•  Does this vulnerability really exist or is it a false positive? 
•  Can someone exploit this vulnerability directly over the internet? 
•  How difficult is it to exploit this vulnerability? 
•  Is there known, published exploit code for this vulnerability? 
•  What would be the business impact if this vulnerability were exploited? 
•  Are there other security controls that reduce the likelihood and/or impact of exploiting this vulnerability?
•  How long has the said vulnerability existed?

Closing Security Gaps

Once a vulnerability has been validated and recognized as a risk, the next step is to decide how to address the vulnerability with stakeholders in the business or network. There are different ways to eliminate vulnerabilities, including the following:

Eliminate Completely: Completely fix or patch the vulnerability so that it cannot be exploited. This is the ideal way, but it may not be possible in all cases.

Mitigating the Impact: The possibilitylikelihood or impact of exploitation of the vulnerability is reduced. This is required when no appropriate fix or patch is available for the identified vulnerability.

Accepting the Risk: No action is taken to correct the possibilitylikelihood and consequences of the vulnerability being exploited. This is generally acceptable where the vulnerability is considered low risk and the cost of remediating the vulnerability is significantly higher than the cost the organization would incur if the vulnerability were exploited.

In some cases, the proposed remediation may not be the ideal way to address the vulnerability. In these cases, the right remediation approach needs to be determined by the organization'’s security team, system owners and system administrators. The remediation can be as simple as applying an off-the-shelf software patch or as complex as changing the physical server pool on the organization'’s network.

Once the remediations are complete, it is necessary to run another vulnerability scan to verify that the vulnerability has been fully resolved.

Reporting the Full Cycle

It is extremely important to record the entire process from detection of the vulnerability to its closure and to ensure that, these records are included in the vulnerability management memory of the enterprise. In this way, it is ensured that the processes that fail within the enterprise are followed up quickly and improvement efforts are planned correctly.

What is Managed Vulnerability Management Service?

Thanks to the Managed Vulnerability Management Service offered by ADEO, all of the processes described above, which are vital for businesses, are operated by ADEO cyber security and risk experts on a 24x7 basis. In this way, we make the vulnerability management process, which requires in-depth expertise, accessible as a service that every businesses can easily access.
 

Take advantage of maximum cyber security.

Experience the difference between a sense of security and real security.

CONTACT US

Add an ally to your defense

Add an ally to your defense


Experience first-hand how ADEO's 24x7 end-to-end security approach can help you achieve better results. Enhance your security coverage with our team of security experts, who work as an extension of your team, and reduce your risks with their rapid response capabilities. Maximize the value of your current security products by incorporating operational functionality into your telemetry data.

Reduce your average remediation time with our automation, playbooks, and incident response expertise. Take control of all your security alerts by managing, prioritizing, and viewing them from a single dashboard across your entire security infrastructure.