CISO's perspective from the frontlines

Vulnerability Management: More Than Just discovering your Flaws

V

In this episode of Defense in Depth, I joined David Spark and Mike Johnson – CISO at Rivian to discuss the topic of vulnerability management. We make the argument that simply finding vulnerabilities is not enough, and true vulnerability management requires prioritizing, tracking, fixing, and assessing risks.

Vulnerability Management

What we need is a comprehensive approach that includes IT hygiene, asset management, and understanding the business context so we can properly prioritize the risk and remediation.

It also worth noting that patch management is not vulnerability management. Patch management is more of a routine maintenance of systems, where vulnerability management addressing the risks of unpatched systems.

Lastly, for effective vulnerability management we also recognized the importance of a nuanced approach that considers business impact and risk.

You can listen to the episode using the link below or on the CISO Series website. I would love to hear your thought about it.

About the author

yaron

Yaron is a seasoned multi-industry Cyber Security Leader. He is 2x CISO, Research Fellow for the Cloud Security Alliance, Security Tinkerer, Advisory Board Member for several cyber security startups and venture firms, and a Mentor to other CISOs and members of the security community.

By yaron
CISO's perspective from the frontlines

Topics

Follow me

Get in touch

Do you want to get in touch? have a question? want me to speak at your event? need advice? please use the form below. No sales messages please!
Please enable JavaScript in your browser to complete this form.