CISO ADVISORS · SECURITY ADVISORY
How to Build a Vulnerability
Management Program
from Scratch
A Practical Step-by-Step Implementation Guide
For Security Teams Building or Maturing Their First VM Program
Ed Moore, CISSP · CISM · C-CISO · CEH | CISO Advisors | cisoadvisors.com
CISO Advisors · cisoadvisors.com · Confidential
1 / 12
CA
PROGRAM ARCHITECTURE
The 6-Phase VM Program Framework
Each phase builds on the last — do them in order for fastest time to value
CISO Advisors · cisoadvisors.com · Confidential
2 / 12
1
Asset Inventory
Know what you have
2
Scanning & Discovery
Find the vulnerabilities
3
Risk Prioritization
Focus on what matters
4
Remediation
Fix and verify
5
Exception Management
Handle the exceptions
6
Metrics & Reporting
Measure and improve
Recommended Platforms:
Qualys — Full-featured enterprise VM platform — gold standard
Tenable Nessus/SC — Industry standard — broad plugin coverage; Nessus Essentials free
Rapid7 InsightVM — Good integration with ticketing and SIEM; strong container scanning
Wiz (cloud-native) — Best for cloud/container environments; agentless; CSPM built in
Microsoft Defender for Endpoint — Included in M365 E5 — covers endpoints if already licensed
CA
PHASE 1 & 2
Asset Inventory & Vulnerability Scanning
You can't fix what you don't know exists — start here
CISO Advisors · cisoadvisors.com · Confidential
3 / 12
Phase 1: Asset Inventory
All endpoints (Windows, Mac, Linux, mobile)
All servers (physical, virtual, cloud)
Network infrastructure (firewalls, switches, routers)
Cloud assets (EC2, VMs, containers, serverless)
Web applications and APIs
OT/IoT devices if applicable
Third-party and shadow IT assets
Phase 2: Scanning Configuration
Authenticated scanning (not just unauthenticated) — finds 10x more vulns
Weekly scans for internal assets; daily for internet-facing
Continuous monitoring for cloud assets (agentless preferred)
Include dev/test environments — vulnerabilities migrate to prod
API and web application scanning (DAST) separate from infra scanning
Container image scanning in CI/CD pipeline
⚠️ Unauthenticated scanning finds ~30% of vulnerabilities. Authenticated scanning is required for a real VM program.
CA
PHASE 3
Risk-Based Prioritization
Not all vulnerabilities are equal — prioritization separates a VM program from a scanner dump
CISO Advisors · cisoadvisors.com · Confidential
4 / 12
Severity
CVSS Range
Exploit Status
Remediation SLA
Description
Critical
9.0–10.0
Active exploitation in wild
24–48 hours
Remote code execution, privilege escalation with active exploits
High
7.0–8.9
Public exploit available
7 days
Significant exposure; exploit available but not widely used
Medium
4.0–6.9
No public exploit
30 days
Requires specific conditions or adjacent access to exploit
Low
0.1–3.9
Theoretical
90 days
Minimal risk; typically information disclosure or best-practice gaps
Informational
N/A
N/A
Next review cycle
Configuration improvements; no direct exploitability
Prioritization multiplier: CVSS score × Asset criticality × Data sensitivity × Exploit availability = Risk score
Lows and Mediums – They have to have attention too. Do not just complete all the criticals and some of the highs and think that you are doing well in your program.
CA
PHASES 4 & 5
Remediation Tracking & Exception Management
The process that turns scan results into closed vulnerabilities — and handles what can't be fixed
CISO Advisors · cisoadvisors.com · Confidential
5 / 12
Phase 4: Remediation Process
Assign vulnerabilities to system owner via ServiceNow/Jira
Set SLA based on severity (Critical=24h, High=7d, Med=30d, Low=90d)
Weekly remediation status review with IT leadership
Verify fixes — rescan after patching to confirm closure
Track Mean Time to Remediate (MTTR) as primary KPI
Escalate SLA breaches to CISO at 50% of time elapsed
Phase 5: Exception Management
Define what qualifies for an exception (can't patch without downtime, vendor support EoL, etc.)
Require: business justification + compensating control + remediation plan
All exceptions require CISO written approval
Maximum exception duration: 90 days (Critical), 180 days (High)
Track exceptions in exception register; review monthly
Exceptions are NOT permanent — they have expiration dates
CA
PHASE 6
VM Program Metrics & KPIs
What to measure and report to demonstrate program effectiveness
CISO Advisors · cisoadvisors.com · Confidential
6 / 12
Metric
Target
Escalate If
Why It Matters
Mean Time to Remediate (MTTR) — Critical
< 48 hours
> 7 days
The single most important VM metric — how fast critical vulns get fixed
Critical/High Open Vulnerability Count
Decreasing trend
Increasing trend
Should decrease over time as the program matures
Patch Compliance Rate
> 95% within SLA
< 80%
% of vulnerabilities remediated within their defined SLA
Asset Scan Coverage
100% of known assets
< 90%
Are all assets being scanned? Gaps = blind spots
Exception Rate
< 5% of open vulns
> 15%
High exception rates indicate systemic patching problems
Reintroduced Vulnerability Rate
< 2%
> 5%
Vulns fixed and then re-introduced — indicates process breakdown
Report MTTR and open critical count monthly to CISO. Quarterly trend report to executive team. Annual program maturity assessment to board.
KEY TAKEAWAYS
Action Items & Next Steps
Start with authenticated scanning — unauthenticated finds only 30% of vulnerabilities
Risk-based prioritization is the difference between a VM program and a scanner dump
MTTR is your #1 metric — Critical vulns must be closed in 24-48 hours
Exceptions are not waivers — they require compensating controls and expiration dates
Report VM metrics monthly to CISO; quarterly to executives; annually to board
CISO Advisors · Ed Moore
emoore@cisoadvisors.org · cisoadvisors.com
CISO Advisors · cisoadvisors.com · Confidential
12 / 12