Vulnerability Management Workflow
Vulnerability Management provides an integrated remediation workflow. Instead of identifying vulnerabilities and then switching to a separate patching solution, you can detect, prioritize, remediate, and verify vulnerabilities from a single experience.
This helps you reduce the time between detection and remediation while providing visibility into remediation status and results.
Vulnerability remediation workflow
Use the following workflow to identify and remediate security risks on managed devices.
Before you begin
Ensure that managed devices are reporting to the platform and that vulnerability data is available.
1. Identify vulnerabilities
Review detected vulnerabilities across your environment.
You can perform a vulnerability scan to collect the most current information before beginning remediation.
2. Prioritize vulnerabilities
Determine which vulnerabilities require immediate attention.
Prioritize vulnerabilities using available risk indicators, such as:
- CVSS scores
- EPSS scores
- CISA Known Exploited Vulnerabilities (KEV)
- Device and site context
- Business impact
- Number of affected devices
3. Select devices
Select the devices that you want to remediate. You can target:
- Individual devices
- Multiple devices
- Device groups
4. Choose a remediation action
Choose the remediation action that best addresses the vulnerability. Available actions may include:
- Patch the affected application
- Upgrade the application
- Remove the application
- Run a remediation script
- Accept the risk when remediation is not required or is not currently possible
5. Deploy remediation
Deploy the selected remediation action to the target devices.
Depending on the remediation type, you may be able to:
- Schedule deployment
- Configure restart behavior
- Notify users before remediation begins
6. Monitor remediation progress
Review remediation status to identify successful, pending, or failed actions. If a remediation action fails, review the results and take corrective action as needed.
7. Verify remediation results
After remediation completes, verify that the vulnerability has been resolved. You can verify remediation by:
- Running a new scan
- Reviewing device status
- Confirming that the vulnerability is no longer detected
8. Review remediation reports
Review remediation reports to measure remediation effectiveness and demonstrate compliance.
For more information about scanning, risk assessment, remediation actions, and reporting, see the related Vulnerability Management topics.
`
