Publication Cover
EDPACS
The EDP Audit, Control, and Security Newsletter
Volume 38, 2008 - Issue 1
191
Views
0
CrossRef citations to date
0
Altmetric
Original Articles

Improving the Vulnerability Management Process

Pages 13-22 | Published online: 24 Jun 2008
 

Abstract

Notes

1. DHS reported that in FY 2007, there were 12,986 incidents reported by agencies (OMB 2008).

2. Some ideas for metrics within the vulnerability management process can be found in Global Technology Audit Guide (GTAG) 6: Managing and Auditing IT Vulnerabilities (CitationRomanosky et al. 2006) as well as in NIST SP 800-40 (CitationMell et al., 2005).

3. The CERT Resiliency Engineering Framework (REF) is an effort to provide guidance to organizations looking to mature and improve the processes they use to ensure operational resiliency. The process improvement framework provided in CERT REF, more fully expands on the interdependencies between the vulnerability management process and other enterprise capabilities, such as information security risk management. The framework applies structured process engineering principles to an enterprise's security and business continuity activities, with the goal of ensuring optimum resource application and maximizing the investments that an organization makes in managing operational risk. For more information about the CERT Resiliency Engineering Framework, visit http://www.cert.org/resiliency_engineering/

URLs are valid as of the date of publication of this document.

Log in via your institution

Log in to Taylor & Francis Online

Issue Purchase

  • 30 days online access to complete issue
  • Article PDFs can be downloaded
  • Article PDFs can be printed
USD 52.00 Add to cart

PDF download + Online access

  • 48 hours access to article PDF & online version
  • Article PDF can be downloaded
  • Article PDF can be printed
USD 61.00 Add to cart

* Local tax will be added as applicable

Related Research

People also read lists articles that other readers of this article have read.

Recommended articles lists articles that we recommend and is powered by our AI driven recommendation engine.

Cited by lists all citing articles based on Crossref citations.
Articles with the Crossref icon will open in a new tab.