Vulnerability management as an organizational and technical process

Authors

  • Lysetskyi Yu.M. https://orcid.org/0000-0002-5080-1856 , Limited Liability Company SNT Ukraine

DOI:

https://doi.org/10.34121/1028-9763-2026-2-38-45

Keywords:

vulnerability management, process, vulnerability scanners, IT systems, challenges, limitations

Abstract

Vulnerability management is an organizational and technical process and a set of practices for identifying, assessing, prioritizing, addressing, and validating vulnerabilities in the software and hardware of IT infrastructure and industrial automation systems used by organizations and institutions. The emergence and development of the vulnerability management process are inextricably linked to the history of information and telecommunications technologies. A landmark event in this field was the launch in 1999 of Common Vulnerabilities and Exposures (CVE), a publicly accessible registry of identified vulnerabilities, which laid the foundation for the standardization of names, information exchange, and the systematic use of scanners, databases, and exploit feeders. The next significant step forward was the development of the Common Vulnerability Scoring System, i.e. a system for comparing vulnerabilities based on common metrics of impact and exploitation probability. These achievements drastically expanded the scope and automation capabilities of VM tools. In the overall VM process, scanning — both network and endpoint — plays a key role, as does gathering context about the IT environment, mathematical/statistical models for prioritizing findings, and operational response processes, such as patch planning or rollback when necessary. The iterative VM cycle can be viewed as a continuous chain: detection → normalization of findings → prioritization of findings → remediation → verification → reporting. The introduction of CVE marked a significant step forward in the history of vulnerability management in IT systems. Vulnerability scanners have become a fundamental tool not only for VM but for cybersecurity in general. They remain an essential, yet insufficient, component for cyber defense. CVE works well for identifying known issues but its limitations require supplementation with other methods: contextual risk analysis, integration with DevSecOps processes, and the use of predictive models and threat analytics. In the future, the trend is moving toward intelligent vulnerability management where scanners become just one module in a broader cybersecurity ecosystem. Fig.: 1. Refs.: 25 titles.

References

1. Holm H., Sommestad T., Almroth J., Persson M. A quantitative evaluation of vulnerability scanning. Information Management & Computer Security. 2011. Vol. 19 (4). P. 231–247.

2. Scanning Large Networks with Nessus. URL: https://www.tenable.com/blog/scanning-large-networks-with-nessus (дата звернення: 07.01.2026).

3. Karlsson M. The Edit History of the National Vulnerability Database and similar Vulnerability Databases. 2012. 100 p.

4. Лисецький Ю.М., Старовойтенко О.О. Керування вразливостями ІТ-систем. Вісник воєнної розвідки. 2026. №92. С. 29–33.

5. Brumă O.-V. Vulnerabilities of Information Systems. International Journal of Information Security and Cybercrime. 2020. Vol. 9 (1). P. 9–14.

6. Mell P., Scarfone K., Romanosky S. A proposed metric for vulnerability exploitation probability. NIST Computer Security White Paper. National Institute of Standards and Technology. 2025. 34 p.

7. Souppaya M., Scarfone K. NIST Special Publication 800-40 Revision 4: Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology. National Institute of Standards and Technology. URL: https://csrc.nist.gov/pubs/sp/800/40/r4/final. NIST Computer Security Resource Center+1 (дата звернення: 10.01.2026).

8. Bennouk K., Ait Aali N., El Bouzekri El Idrissi Y., Sebai B., Faroukhi A.Z., Mahouachi D. A Comprehensive Review and Assessment of Cybersecurity Vulnerability Detection Methodologies. Journal of Cybersecurity and Privacy. 2024. Vol. 4 (4). P. 853–908.

9. History. URL: https://www.cve.org/about/history (дата звернення: 12.01.2026).

10. Li Z., Sun L., Xu W., Chi C.H., Xue Y. Vulnerability scanning and analysis in large-scale heterogeneous systems. Journal of Computer Security. 2021. Vol. 29 (2). Р. 135–162.

11. Shu R., Gu X., Enck W. A study of security vulnerabilities on Docker Hub. Proс. of the Seventh ACM Conference on Data and Application Security and Privacy. 2017. P. 269–280.

12. Khan R., McLaughlin K., Laverty D., Sezer S. STRIDE-based threat modeling for cyber-physical systems. 2017 IEEE PES Innovative Smart Grid Technologies Conference Europe (ISGT-Europe). 2020. P. 1–6.

13. Fruhlinger J. What is vulnerability management? A process for securing software and networks. CSO Online. URL: https://www.csoonline.com/ (дата звернення: 14.01.2026).

14. Doupe A., Cova M., Vigna G. Why Johnny can’t pentest: An analysis of black-box web vulnerability scanners. Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA 2010). 2010. P. 111–131.

15. Mell P., Scarfone K., Romanosky S. A complete guide to the Common Vulnerability Scoring System version 2.0. Forum of Incident Response and Security Teams (FIRST). 2007. 23 p.

16. Jacobs J., Spring J., Stoner E., Sauerwein C. Exploit Prediction Scoring System (EPSS). Proc. of the 2021 IEEE European Symposium on Security and Privacy Workshops. 2021. P. 587–596.

17. Sabottke C., Suciu O., Dumitraş T. Vulnerability disclosure in the age of social media: Exploiting Twitter for predicting real-world exploits. 24th USENIX Security Symposium (USENIX Security 15). 2015. P. 1041–1056.

18. Mell P., Scarfone K., Romanosky S. A Complete Guide to the Common Vulnerability Scoring System Version 2.0. FIRST-Forum of Incident Response and Security Teams. 2007. P. 1–23.

19. Gupta S., Badve O., Vora P. Automated vulnerability assessment and penetration testing using Nessus. International Journal of Computer Applications. 2020. Vol. 176 (38). P. 1–7.

20. Fang Z., Zhang L., Chen Y., Chen Z. Research on vulnerability detection technology in software security. IEEE Access. 2020. Vol. 8. 2020. P. 586–600.

21. Shu R., Gu X., & Enck, W. A study of security vulnerabilities on Docker Hub. Proc. of the Seventh ACM Conference on Data and Application Security and Privacy. 2017. P. 269–280.

22. Li Z., Sun L., Xu W., Chi C.H., Xue Y. Vulnerability scanning and analysis in large-scale heterogeneous systems. Journal of Computer Security. 2021. Vol. 29 (2). P. 135–162.

23. Zhang Y., Chen X., Xiang Y. Context-aware risk-based vulnerability management. Future Generation Computer Systems. 2019. Vol. 94. P. 444–456.

24. Jacobs J., Spring J., Stoner E., Sauerwein C. Exploit Prediction Scoring System (EPSS). Proc. of the 2021 IEEE European Symposium on Security and Privacy Workshops. 2021. P. 587–596.

25. Rahman M.S., Williams L., Bradshaw G. A framework for improving security patch management in DevOps. Proc. of the 2019 International Conference on Software and System Processes. 2019. P. 134–143.

Downloads

Views: 150
Downloads: 77

Published

2026-05-07

Issue

Section

INFORMATION AND TELECOMMUNICATION TECHNOLOGY

How to Cite

Vulnerability management as an organizational and technical process. (2026). Mathematical Machines and Systems, 2, 38-45. https://doi.org/10.34121/1028-9763-2026-2-38-45