From the course: Vulnerability Management: Assessing the Risks with CVSS v3.1
Unlock the full course today
Join today to access over 24,700 courses taught by industry experts.
Remediating vulnerabilities
From the course: Vulnerability Management: Assessing the Risks with CVSS v3.1
Remediating vulnerabilities
- [Instructor] It's pretty easy to understand tailoring CVSS scores on a few systems. But, what happens when you have hundreds, thousands, or hundreds of thousands of systems, and then each of those systems has at least a dozen vulnerabilities if not more? Assessing vulnerabilities individually probably isn't possible. It just doesn't scale to a large environment, It's not a sustainable process. Unless your vulnerability scanner gives you the ability to customize scores based on customer attributes, some do. And there's a whole subset of platforms that help address the issues in a space called threat and vulnerability management. But how do you tackle such a big problem if you don't have those tools or the budget for them? You need a strategy to handle the problem little by little. As they say, "You can't boil the ocean." There's a few ways you can tackle this, but you have to break it up so you can address it by assets…