Skip to content
compliancebase

Vulnerability management

The recurring process for identifying, prioritizing, remediating, and verifying weaknesses in systems and software.

In practice

Combine authenticated scanning, dependency alerts, risk-based SLAs, exceptions, and closure evidence.

Common confusion

A yearly penetration test does not replace continuous vulnerability management.

Related controls

Framework versions referenced in this page:

Last verified: August 2026 · Primary sources linked above