1 of 7

CISO ADVISORS · SECURITY ADVISORY

How to Build a Vulnerability

Management Program

from Scratch

A Practical Step-by-Step Implementation Guide

For Security Teams Building or Maturing Their First VM Program

Ed Moore, CISSP · CISM · C-CISO · CEH | CISO Advisors | cisoadvisors.com

CISO Advisors · cisoadvisors.com · Confidential

1 / 12

2 of 7

CA

PROGRAM ARCHITECTURE

The 6-Phase VM Program Framework

Each phase builds on the last — do them in order for fastest time to value

CISO Advisors · cisoadvisors.com · Confidential

2 / 12

1

Asset Inventory

Know what you have

2

Scanning & Discovery

Find the vulnerabilities

3

Risk Prioritization

Focus on what matters

4

Remediation

Fix and verify

5

Exception Management

Handle the exceptions

6

Metrics & Reporting

Measure and improve

Recommended Platforms:

Qualys — Full-featured enterprise VM platform — gold standard

Tenable Nessus/SC — Industry standard — broad plugin coverage; Nessus Essentials free

Rapid7 InsightVM — Good integration with ticketing and SIEM; strong container scanning

Wiz (cloud-native) — Best for cloud/container environments; agentless; CSPM built in

Microsoft Defender for Endpoint — Included in M365 E5 — covers endpoints if already licensed

3 of 7

CA

PHASE 1 & 2

Asset Inventory & Vulnerability Scanning

You can't fix what you don't know exists — start here

CISO Advisors · cisoadvisors.com · Confidential

3 / 12

Phase 1: Asset Inventory

All endpoints (Windows, Mac, Linux, mobile)

All servers (physical, virtual, cloud)

Network infrastructure (firewalls, switches, routers)

Cloud assets (EC2, VMs, containers, serverless)

Web applications and APIs

OT/IoT devices if applicable

Third-party and shadow IT assets

Phase 2: Scanning Configuration

Authenticated scanning (not just unauthenticated) — finds 10x more vulns

Weekly scans for internal assets; daily for internet-facing

Continuous monitoring for cloud assets (agentless preferred)

Include dev/test environments — vulnerabilities migrate to prod

API and web application scanning (DAST) separate from infra scanning

Container image scanning in CI/CD pipeline

⚠️ Unauthenticated scanning finds ~30% of vulnerabilities. Authenticated scanning is required for a real VM program.

4 of 7

CA

PHASE 3

Risk-Based Prioritization

Not all vulnerabilities are equal — prioritization separates a VM program from a scanner dump

CISO Advisors · cisoadvisors.com · Confidential

4 / 12

Severity

CVSS Range

Exploit Status

Remediation SLA

Description

Critical

9.0–10.0

Active exploitation in wild

24–48 hours

Remote code execution, privilege escalation with active exploits

High

7.0–8.9

Public exploit available

7 days

Significant exposure; exploit available but not widely used

Medium

4.0–6.9

No public exploit

30 days

Requires specific conditions or adjacent access to exploit

Low

0.1–3.9

Theoretical

90 days

Minimal risk; typically information disclosure or best-practice gaps

Informational

N/A

N/A

Next review cycle

Configuration improvements; no direct exploitability

Prioritization multiplier: CVSS score × Asset criticality × Data sensitivity × Exploit availability = Risk score

Lows and Mediums – They have to have attention too. Do not just complete all the criticals and some of the highs and think that you are doing well in your program.

5 of 7

CA

PHASES 4 & 5

Remediation Tracking & Exception Management

The process that turns scan results into closed vulnerabilities — and handles what can't be fixed

CISO Advisors · cisoadvisors.com · Confidential

5 / 12

Phase 4: Remediation Process

Assign vulnerabilities to system owner via ServiceNow/Jira

Set SLA based on severity (Critical=24h, High=7d, Med=30d, Low=90d)

Weekly remediation status review with IT leadership

Verify fixes — rescan after patching to confirm closure

Track Mean Time to Remediate (MTTR) as primary KPI

Escalate SLA breaches to CISO at 50% of time elapsed

Phase 5: Exception Management

Define what qualifies for an exception (can't patch without downtime, vendor support EoL, etc.)

Require: business justification + compensating control + remediation plan

All exceptions require CISO written approval

Maximum exception duration: 90 days (Critical), 180 days (High)

Track exceptions in exception register; review monthly

Exceptions are NOT permanent — they have expiration dates

6 of 7

CA

PHASE 6

VM Program Metrics & KPIs

What to measure and report to demonstrate program effectiveness

CISO Advisors · cisoadvisors.com · Confidential

6 / 12

Metric

Target

Escalate If

Why It Matters

Mean Time to Remediate (MTTR) — Critical

< 48 hours

> 7 days

The single most important VM metric — how fast critical vulns get fixed

Critical/High Open Vulnerability Count

Decreasing trend

Increasing trend

Should decrease over time as the program matures

Patch Compliance Rate

> 95% within SLA

< 80%

% of vulnerabilities remediated within their defined SLA

Asset Scan Coverage

100% of known assets

< 90%

Are all assets being scanned? Gaps = blind spots

Exception Rate

< 5% of open vulns

> 15%

High exception rates indicate systemic patching problems

Reintroduced Vulnerability Rate

< 2%

> 5%

Vulns fixed and then re-introduced — indicates process breakdown

Report MTTR and open critical count monthly to CISO. Quarterly trend report to executive team. Annual program maturity assessment to board.

7 of 7

KEY TAKEAWAYS

Action Items & Next Steps

Start with authenticated scanning — unauthenticated finds only 30% of vulnerabilities

Risk-based prioritization is the difference between a VM program and a scanner dump

MTTR is your #1 metric — Critical vulns must be closed in 24-48 hours

Exceptions are not waivers — they require compensating controls and expiration dates

Report VM metrics monthly to CISO; quarterly to executives; annually to board

CISO Advisors · Ed Moore

emoore@cisoadvisors.org · cisoadvisors.com

CISO Advisors · cisoadvisors.com · Confidential

12 / 12