Cyber Security

Vulnerability Management Guide

8 min read 1 August 2025

Why Is Vulnerability Management Critical?

In 2024, the number of publicly disclosed CVEs (Common Vulnerabilities and Exposures) exceeded 29,000. A significant portion of these vulnerabilities were exploited through systems that had patches available but not yet applied. A regular vulnerability management program reduces the attack surface, satisfies compliance requirements (ISO 27001, PCI DSS, KVKK), and dramatically lowers the cost of potential breaches.

The Vulnerability Management Cycle

Vulnerability management is a cyclical process consisting of five phases:

  1. Asset Discovery: Inventorying all systems, applications, and devices on the network
  2. Scanning: Automatically detecting known vulnerabilities using specialized tools
  3. Prioritization: Ranking vulnerabilities by risk and business impact
  4. Remediation: Applying patches, correcting configurations, or implementing compensating controls
  5. Verification: Confirming closure by re-scanning after patches are applied

Scanning Tools

Nessus (Tenable)

One of the most widely used enterprise vulnerability management platforms:

  • Nessus Essentials: Free for up to 16 IPs
  • Nessus Professional: Unlimited IPs, advanced plugins
  • Tenable.io / Tenable.sc: For large enterprises; continuous monitoring, CMDB integration
# Nessus CLI ile temel tarama başlatma
/opt/nessus/sbin/nessuscli scan --name "Haftalik_Tarama" \
  --targets 192.168.1.0/24

OpenVAS / Greenbone

Open-source alternative; also known as Greenbone Community Edition:

# Docker ile hızlı kurulum
docker run -d -p 9392:9392 --name openvas greenbone/community-edition
# Web arayüzü: https://localhost:9392
# Varsayılan kimlik: admin/admin (değiştirin!)

Quick Port and Service Scanning with Nmap

# Versiyon ve OS tespiti
nmap -sV -O --script vuln 192.168.1.0/24 -oN tarama_sonucu.txt

# Belirli servislerin NSE scriptleri ile taranması
nmap -sV --script=http-vuln* -p 80,443,8080 192.168.1.10

CVE Prioritization: CVSS and EPSS

CVSS Score

CVSS RangeSeverityRecommended SLA
9.0–10.0Critical24–48 hours
7.0–8.9High7 days
4.0–6.9Medium30 days
0.1–3.9Low90 days

EPSS (Exploit Prediction Scoring System)

CVSS alone is insufficient; a vulnerability with a high CVSS score may never be exploited. EPSS estimates the probability (0–1) that a vulnerability will be actively exploited within the next 30 days.

Prioritization formula: High CVSS + High EPSS = Immediate action required

# Basit önceliklendirme mantığı
if cvss >= 9.0 and epss > 0.5:
    priority = "P1 - Derhal Yama"
elif cvss >= 7.0 or epss > 0.3:
    priority = "P2 - Bu Hafta"
else:
    priority = "P3 - Planlı Döngü"

Patch Management Process

Windows — WSUS and Microsoft Endpoint Manager

# WSUS sunucusuna bağlı makinelerde yama durumu kontrolü
Get-WsusComputer | Where {$_.UpdatesNeedingFiles -gt 0} |
  Select FullDomainName, LastSyncTime, UpdatesNeedingFiles

# Intune yönetilen cihazlarda acil yama politikası
# Microsoft Endpoint Manager > Devices > Update rings

Linux — Automated Updates and Patch Logging

# Ubuntu — Güvenlik güncellemelerini listele
apt list --upgradable 2>/dev/null | grep -i security

# AlmaLinux/CentOS — Güvenlik yamalarını uygula
sudo dnf upgrade --security -y

# Yama geçmişini görüntüle
sudo dnf history list

Third-Party Application Patches

  • Chocolatey (Windows): choco upgrade all -y
  • Homebrew (macOS): brew upgrade
  • Java, Adobe, web browsers, and VPN clients are particularly targeted components.

Handling Non-Compliant Systems

Some systems cannot be patched (legacy industrial control systems, proprietary applications):

  • Virtual Patching: IPS/WAF rules temporarily block the vulnerability
  • Network segmentation: The unpatched system is moved to an isolated VLAN
  • Enhanced monitoring: Custom alerts are created for abnormal traffic targeting the system
  • Compensating controls are documented and a risk acceptance form is signed

Reporting and KPIs

Metrics to track in order to measure the effectiveness of a vulnerability management program:

KPITarget
Mean time to remediate (Critical)< 48 hours
Mean time to remediate (High)< 7 days
Patched critical vulnerability rate> 95%
Recurring vulnerability rate< 5%
Scan coverage (total assets)100%

Conclusion

Vulnerability management is not a product — it is a continuously operated program. Organizations that run the scan, prioritize, remediate, and verify cycle in a regular and measurable manner are significantly more resilient against cyberattacks. NRC Sistem provides comprehensive consulting and implementation support for establishing your vulnerability management program, selecting the right tools, and automating patch processes.

All posts