Skip to content
Weekly Signal

Knowledge centre

Topic: Vulnerability Management

Glossary term 1 min

Vulnerability debt

The accumulated exposure and operational burden created when vulnerability treatment is delayed or repeatedly deferred.

Read more

Glossary term 1 min

CVE

A public identifier for a specific, disclosed cyber-security vulnerability.

Read more

Glossary term 1 min

CVSS

A standard for describing the technical severity and characteristics of a vulnerability.

Read more

Glossary term 1 min

EPSS

A daily estimate of the probability that a published CVE will be exploited in the wild during the next 30 days.

Read more

Glossary term 1 min

KEV

CISA’s catalog of vulnerabilities with evidence of exploitation in the wild.

Read more

Glossary term 1 min

EASM

The continuous discovery and assessment of internet-visible assets and services from an external perspective.

Read more

Glossary term 1 min

CTEM

A continuous programme for scoping, discovering, prioritising, validating and mobilising action around material exposure.

Read more

Glossary term 1 min

SSVC

A decision-tree approach that maps vulnerability evidence and stakeholder context to an action outcome.

Read more

Glossary term 1 min

CPE

A structured naming scheme used to identify hardware, operating systems and applications.

Read more