Vulnerability Management Flashcards
Threat Intelligence
The continual process used to understand the threats faced by an organization.
Threat Intelligence Feed
The continuous stream of data related to potential or current threats to an organization’s security.
Open Source Intelligence (OSINT)
Intelligence that is gained from publicly available sources.
Responsible Disclosure
Term used to describe the ethical practice where security resources disclose information about vulnerabilities.
Common Vulnerability and Exposures (CSE)
System that provides a standardized way to uniquely identify and reference known vulnerabilities in software/hardware.
NESSUS
A vulnerability tool tester.
OpenVAS
A vulnerability tool tester.
Vulnerability Response and Remediation
The strategies that identify, access, and address vulnerabilities in a system or network to strengthen an organization’s security posture.
Voluntary Reporting
The process of documenting and communicating details about security weaknesses identified in software systems to the individuals or organizations responsible for addressing the issues.
Vulnerability Reporting Types
Internal, External.