Resources
The Vulnerability Management Lifecycle
Vulnerability management is not a scan — it's a continuous loop. This guide walks through the six stages of the vulnerability management process and shows how an orchestration platform like NSO automates each one.
You can't protect what you don't know about. Discovery builds a live inventory of your assets — domains, hosts, and services — and continuously scans them for weaknesses. In NSO, asset onboarding is verified through DNS ownership checks, and scheduled scans (including OpenVAS/GVM) keep the inventory current instead of relying on annual point-in-time assessments.
Raw scanner output is noise. Prioritization ranks findings by severity, exploitability, and the business context of the affected asset so teams fix what matters first. NSO triages scan results per tenant, letting analysts sort and filter findings instead of working through a flat list of CVEs.
Assessment validates that a finding is real and understands its blast radius: Is the service reachable? Is the vulnerable version actually deployed? AI-powered result analysis in NSO summarizes scanner output, flags likely false positives, and explains impact in plain language so engineers spend time on confirmed risk.
Remediation is the fix: patching, configuration changes, compensating controls, or an accepted-risk decision with an expiry date. Track every action against the finding it resolves — untracked fixes are how the same vulnerability reopens every quarter.
Never mark a finding resolved on faith. Re-scan the affected asset and confirm the vulnerability is gone before closing it. NSO's recurring scan jobs close the loop automatically: a follow-up scan of the same asset either confirms the fix or re-surfaces the finding.
Reporting turns scan data into audit-ready evidence: what was found, when, how it was prioritized, and proof it was fixed. NSO keeps platform audit events, verification audit logs, and scan history per tenant so compliance reviews pull from records, not memory.
Why the loop matters more than the scan
One-off scans age badly — new CVEs drop daily and infrastructure changes constantly. Mature programs run the lifecycle continuously: discovery feeds prioritization, verified fixes feed reporting, and reporting feeds the next planning cycle. Frameworks from OWASP and guidance from vendors like Rapid7 describe the same loop; the difference between programs is how much of it is automated and how much lives in spreadsheets.
NSO runs that loop for you: verified asset onboarding, scheduled scanning, AI-assisted triage, and audit-ready evidence — per tenant, with a full audit trail.