Why Is Vulnerability Management Critical?
In 2024, the number of publicly disclosed CVEs (Common Vulnerabilities and Exposures) exceeded 29,000. A significant portion of these vulnerabilities were exploited through systems that had patches available but not yet applied. A regular vulnerability management program reduces the attack surface, satisfies compliance requirements (ISO 27001, PCI DSS, KVKK), and dramatically lowers the cost of potential breaches.
The Vulnerability Management Cycle
Vulnerability management is a cyclical process consisting of five phases:
- Asset Discovery: Inventorying all systems, applications, and devices on the network
- Scanning: Automatically detecting known vulnerabilities using specialized tools
- Prioritization: Ranking vulnerabilities by risk and business impact
- Remediation: Applying patches, correcting configurations, or implementing compensating controls
- Verification: Confirming closure by re-scanning after patches are applied
Scanning Tools
Nessus (Tenable)
One of the most widely used enterprise vulnerability management platforms:
- Nessus Essentials: Free for up to 16 IPs
- Nessus Professional: Unlimited IPs, advanced plugins
- Tenable.io / Tenable.sc: For large enterprises; continuous monitoring, CMDB integration
# Nessus CLI ile temel tarama başlatma
/opt/nessus/sbin/nessuscli scan --name "Haftalik_Tarama" \
--targets 192.168.1.0/24
OpenVAS / Greenbone
Open-source alternative; also known as Greenbone Community Edition:
# Docker ile hızlı kurulum
docker run -d -p 9392:9392 --name openvas greenbone/community-edition
# Web arayüzü: https://localhost:9392
# Varsayılan kimlik: admin/admin (değiştirin!)
Quick Port and Service Scanning with Nmap
# Versiyon ve OS tespiti
nmap -sV -O --script vuln 192.168.1.0/24 -oN tarama_sonucu.txt
# Belirli servislerin NSE scriptleri ile taranması
nmap -sV --script=http-vuln* -p 80,443,8080 192.168.1.10
CVE Prioritization: CVSS and EPSS
CVSS Score
| CVSS Range | Severity | Recommended SLA |
|---|---|---|
| 9.0–10.0 | Critical | 24–48 hours |
| 7.0–8.9 | High | 7 days |
| 4.0–6.9 | Medium | 30 days |
| 0.1–3.9 | Low | 90 days |
EPSS (Exploit Prediction Scoring System)
CVSS alone is insufficient; a vulnerability with a high CVSS score may never be exploited. EPSS estimates the probability (0–1) that a vulnerability will be actively exploited within the next 30 days.
Prioritization formula: High CVSS + High EPSS = Immediate action required
# Basit önceliklendirme mantığı
if cvss >= 9.0 and epss > 0.5:
priority = "P1 - Derhal Yama"
elif cvss >= 7.0 or epss > 0.3:
priority = "P2 - Bu Hafta"
else:
priority = "P3 - Planlı Döngü"
Patch Management Process
Windows — WSUS and Microsoft Endpoint Manager
# WSUS sunucusuna bağlı makinelerde yama durumu kontrolü
Get-WsusComputer | Where {$_.UpdatesNeedingFiles -gt 0} |
Select FullDomainName, LastSyncTime, UpdatesNeedingFiles
# Intune yönetilen cihazlarda acil yama politikası
# Microsoft Endpoint Manager > Devices > Update rings
Linux — Automated Updates and Patch Logging
# Ubuntu — Güvenlik güncellemelerini listele
apt list --upgradable 2>/dev/null | grep -i security
# AlmaLinux/CentOS — Güvenlik yamalarını uygula
sudo dnf upgrade --security -y
# Yama geçmişini görüntüle
sudo dnf history list
Third-Party Application Patches
- Chocolatey (Windows):
choco upgrade all -y - Homebrew (macOS):
brew upgrade - Java, Adobe, web browsers, and VPN clients are particularly targeted components.
Handling Non-Compliant Systems
Some systems cannot be patched (legacy industrial control systems, proprietary applications):
- Virtual Patching: IPS/WAF rules temporarily block the vulnerability
- Network segmentation: The unpatched system is moved to an isolated VLAN
- Enhanced monitoring: Custom alerts are created for abnormal traffic targeting the system
- Compensating controls are documented and a risk acceptance form is signed
Reporting and KPIs
Metrics to track in order to measure the effectiveness of a vulnerability management program:
| KPI | Target |
|---|---|
| Mean time to remediate (Critical) | < 48 hours |
| Mean time to remediate (High) | < 7 days |
| Patched critical vulnerability rate | > 95% |
| Recurring vulnerability rate | < 5% |
| Scan coverage (total assets) | 100% |
Conclusion
Vulnerability management is not a product — it is a continuously operated program. Organizations that run the scan, prioritize, remediate, and verify cycle in a regular and measurable manner are significantly more resilient against cyberattacks. NRC Sistem provides comprehensive consulting and implementation support for establishing your vulnerability management program, selecting the right tools, and automating patch processes.