{"id":613,"date":"2026-08-11T13:20:02","date_gmt":"2026-08-11T13:20:02","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=613"},"modified":"2026-08-11T13:20:02","modified_gmt":"2026-08-11T13:20:02","slug":"vulnerability-management","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/","title":{"rendered":"Vulnerability Management: Lifecycle and SLAs"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: VULNERABILITY MANAGEMENT\n     Same design system as the VAPT, MFA, Penetration Testing and ISO 27001 pages.\n     Paste the whole block into one Custom HTML block. No H1 (WP adds it).\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Vulnerability management is the ongoing process of finding weaknesses, deciding which ones matter, fixing them, and confirming the fix worked. It is a programme, not an exercise.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Testing &amp; scanning<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Vulnerability management is the continuous cycle of discovering assets, identifying weaknesses, prioritising them by real risk, remediating them, and verifying closure. Scanning and assessment are steps inside it. What makes it a management programme is ownership, agreed timeframes for fixing things, and evidence that the loop keeps running.<\/p>\n<\/div>\n\n<p>The difference between a scan and a programme is what happens after the report. Most teams can produce findings. Fewer can show who owned each one, how long it took to close, and the trend over six months. That last part is what an auditor asks for.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#lifecycle\">The lifecycle<\/a><\/li>\n    <li><a href=\"#priority\">Deciding what to fix first<\/a><\/li>\n    <li><a href=\"#sla\">Remediation timeframes<\/a><\/li>\n    <li><a href=\"#metrics\">Metrics that matter<\/a><\/li>\n    <li><a href=\"#osto\">How Osto supports the programme<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"lifecycle\">The lifecycle<\/h2>\n\n<p>Five stages, running continuously. Skipping the last one is the most common failure, because unverified fixes quietly reappear in the next scan.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 380\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Vulnerability management lifecycle: discover, assess, prioritise, remediate, verify, repeating continuously.\">\n  <circle cx=\"380\" cy=\"190\" r=\"140\" fill=\"none\" stroke=\"#dfe3f5\" stroke-width=\"2\" stroke-dasharray=\"6 7\"\/>\n\n  <g fill=\"#4a52a8\">\n    <polygon points=\"0,-6 13,0 0,6\" transform=\"translate(462.3,76.7) rotate(36)\"\/>\n    <polygon points=\"0,-6 13,0 0,6\" transform=\"translate(513.1,233.3) rotate(108)\"\/>\n    <polygon points=\"0,-6 13,0 0,6\" transform=\"translate(380,330) rotate(180)\"\/>\n    <polygon points=\"0,-6 13,0 0,6\" transform=\"translate(246.9,233.3) rotate(252)\"\/>\n    <polygon points=\"0,-6 13,0 0,6\" transform=\"translate(297.7,76.7) rotate(324)\"\/>\n  <\/g>\n\n  <rect x=\"310\" y=\"26\" width=\"140\" height=\"48\" rx=\"12\" fill=\"#e9ecfa\"\/>\n  <text x=\"380\" y=\"48\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#4a52a8\">1. Discover<\/text>\n  <text x=\"380\" y=\"65\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Know what you own<\/text>\n\n  <rect x=\"443\" y=\"123\" width=\"140\" height=\"48\" rx=\"12\" fill=\"#e3f0e9\"\/>\n  <text x=\"513\" y=\"145\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#3a6f5d\">2. Assess<\/text>\n  <text x=\"513\" y=\"162\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Scan and validate<\/text>\n\n  <rect x=\"392\" y=\"279\" width=\"140\" height=\"48\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"462\" y=\"301\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#2f6a89\">3. Prioritise<\/text>\n  <text x=\"462\" y=\"318\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Rank by real risk<\/text>\n\n  <rect x=\"228\" y=\"279\" width=\"140\" height=\"48\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"298\" y=\"301\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#a2603a\">4. Remediate<\/text>\n  <text x=\"298\" y=\"318\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Patch, configure, fix<\/text>\n\n  <rect x=\"177\" y=\"123\" width=\"140\" height=\"48\" rx=\"12\" fill=\"#f0e6f3\"\/>\n  <text x=\"247\" y=\"145\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#6b4576\">5. Verify<\/text>\n  <text x=\"247\" y=\"162\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Rescan and record<\/text>\n\n  <text x=\"380\" y=\"186\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#1c267a\">Continuous<\/text>\n  <text x=\"380\" y=\"206\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">No end state<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Discovery comes first for a reason. You cannot manage a vulnerability on an asset nobody recorded.<\/figcaption>\n<\/figure>\n\n<h2 id=\"priority\" class=\"c-sage\">Deciding what to fix first<\/h2>\n\n<p>Severity alone is a poor filter: it describes the vulnerability, not your exposure to it. Four inputs together give a workable order.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Input<\/th><th>What it tells you<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>CVSS severity<\/strong><\/td><td>How damaging the weakness is in the abstract. A starting point, not an answer.<\/td><\/tr>\n    <tr><td><strong>Known exploited status<\/strong><\/td><td>Whether the vulnerability is being used in real attacks. CISA&#8217;s KEV catalogue tracks this.<\/td><\/tr>\n    <tr><td><strong>Exploit likelihood<\/strong><\/td><td>The probability of exploitation in the near term. EPSS scores provide this.<\/td><\/tr>\n    <tr><td><strong>Asset context<\/strong><\/td><td>Whether the affected system is internet-facing, holds customer data, or sits behind a control that already blocks the path.<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The practical filter<\/p>\n  <p>Anything critical on an internet-facing asset that is also in the known exploited catalogue goes to the top, regardless of what else is queued. That single rule removes most prioritisation arguments.<\/p>\n<\/div>\n\n<h2 id=\"sla\" class=\"c-apri\">Remediation timeframes<\/h2>\n\n<p>Auditors ask whether timeframes are documented and met. Any defensible set works, provided it is written down and measured.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Common remediation targets: critical within 7 days, high within 30, medium within 90, low at the next scheduled cycle.\">\n  <text x=\"20\" y=\"28\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">COMMON REMEDIATION TARGETS<\/text>\n\n  <text x=\"186\" y=\"72\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#6b4576\">Critical<\/text>\n  <rect x=\"200\" y=\"54\" width=\"42\" height=\"30\" rx=\"8\" fill=\"#6b4576\"\/>\n  <text x=\"254\" y=\"74\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#6b4576\">7 days<\/text>\n  <text x=\"330\" y=\"74\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Actively exploited, or internet-facing with data<\/text>\n\n  <text x=\"186\" y=\"122\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#a2603a\">High<\/text>\n  <rect x=\"200\" y=\"104\" width=\"150\" height=\"30\" rx=\"8\" fill=\"#e0a87e\"\/>\n  <text x=\"362\" y=\"124\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#a2603a\">30 days<\/text>\n  <text x=\"440\" y=\"124\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Realistic exploitation path<\/text>\n\n  <text x=\"186\" y=\"172\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#2f6a89\">Medium<\/text>\n  <rect x=\"200\" y=\"154\" width=\"440\" height=\"30\" rx=\"8\" fill=\"#c2d9ec\"\/>\n  <text x=\"628\" y=\"174\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#25547a\">90 days<\/text>\n\n  <text x=\"186\" y=\"222\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#3a6f5d\">Low<\/text>\n  <rect x=\"200\" y=\"204\" width=\"440\" height=\"30\" rx=\"8\" fill=\"#eef1f6\" stroke=\"#d8dde8\" stroke-dasharray=\"6 5\"\/>\n  <text x=\"420\" y=\"224\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"600\" fill=\"#0f1538\">Next scheduled cycle<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full chart. <\/span>The specific numbers matter less than applying them consistently and being able to show you did.<\/figcaption>\n<\/figure>\n\n<h2 id=\"metrics\" class=\"c-plum\">Metrics that matter<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Time to remediate<\/p>\n    <p>Average days from detection to verified closure, tracked per severity.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Coverage<\/p>\n    <p>The share of known assets actually being scanned. Gaps here invalidate every other number.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Recurrence<\/p>\n    <p>Findings that return after being closed, which points at process rather than at engineering.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto supports the programme<\/h2>\n\n<p>Osto runs discovery and assessment continuously across applications, APIs, code dependencies, endpoints and cloud accounts, with findings rated by severity and mapped to affected endpoints. Because the same platform runs the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> and compliance modules, prioritisation can account for controls already limiting a finding, and closure evidence is produced where the work happened rather than assembled afterwards.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Close the loop, not just the ticket<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Continuous discovery, ranked findings and verified closure across your applications, cloud and endpoints, from one platform.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Continuous coverage &middot; Evidence auditors accept &middot; One platform, everything<\/p>\n<\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is vulnerability management?<\/summary>\n  <p>Vulnerability management is the continuous process of discovering assets, identifying weaknesses, prioritising them by real risk, remediating them and verifying closure. It differs from scanning or assessment because it includes ownership, agreed remediation timeframes and evidence that the cycle keeps running.<\/p>\n<\/details>\n\n<details>\n  <summary>How is it different from a vulnerability assessment?<\/summary>\n  <p>An assessment is a point-in-time exercise producing a ranked list of findings. Management is the programme around it: the assessment is one stage, followed by prioritisation, remediation, verification and measurement, repeated continuously.<\/p>\n<\/details>\n\n<details>\n  <summary>What remediation timeframes should we set?<\/summary>\n  <p>A common pattern is seven days for critical, thirty for high, ninety for medium, and the next scheduled cycle for low. What matters to an auditor is that the timeframes are documented, applied consistently and measured, rather than the specific numbers chosen.<\/p>\n<\/details>\n\n<details>\n  <summary>Do frameworks require vulnerability management?<\/summary>\n  <p>Yes. ISO 27001:2022 addresses it in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A<\/a> 8.8, PCI DSS requires quarterly scanning and defined remediation under Requirement 11, and SOC 2 auditors look for <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-evidence-collection\/\">evidence of identification and remediation<\/a> under CC7.1. All of them expect a repeatable process rather than a single report.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the most common failure in a programme?<\/summary>\n  <p>Incomplete asset discovery. Findings on systems nobody recorded are never triaged, and coverage gaps make every other metric misleading. The second most common is skipping verification, which allows closed findings to reappear unnoticed.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-scanning\/\">Vulnerability Scanning<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-assessment\/\">Vulnerability Assessment<\/a> &middot; CVSS &middot; CVE &middot; Patch Management &middot; CTEM<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Vulnerability management is the ongoing process of finding weaknesses, deciding which ones matter, fixing them, and confirming the fix worked.\u2026<\/p>\n","protected":false},"author":8,"featured_media":614,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[202,200,201,199,97,198],"class_list":["post-613","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-epss","tag-kev-catalogue","tag-patch-management","tag-remediation-sla","tag-vulnerability-management","tag-vulnerability-management-lifecycle"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/613","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=613"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/613\/revisions"}],"predecessor-version":[{"id":615,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/613\/revisions\/615"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/614"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=613"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=613"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=613"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}