« Back to DataSecurityPolicies.com

Vulnerability Management Program

The National Institute of Standards and Technology (NIST) has a document especially useful to anyone writing their vulnerability management policy. It’s Special Publication 800-40, Creating a Patch and Vulnerability Management Program. You can find it here.

Here’s an excerpt:

Organizations need to create a comprehensive, documented, and accountable process for identifying and addressing vulnerabilities, patches, and threats within an organization. One possible approach is to have a formal, centralized patch and vulnerability group that supports the security efforts of local system administrators.

Specific recommendations for organizations implementing a patch and vulnerability management program are as follows:

  1. Create an inventory of all information technology assets.
  2. Create a patch and vulnerability group.
  3. Continuously monitor for vulnerabilities, remediations, and threats.
  4. Prioritize patch application and use phased deployments as appropriate.
  5. Test patches before deployment.
  6. Deploy enterprise-wide automated patching solutions.
  7. Create a remediation database (this is often included within enterprise patch management tools).
  8. Use automatically updating applications as appropriate.
  9. Verify that vulnerabilities have been remediated.
  10. Train applicable staff on vulnerability monitoring and remediation techniques.

An archive copy of the document is here: Vulnerability Management Program

Leave a Reply