Vulnerability debt
The accumulated exposure and operational burden created when vulnerability treatment is delayed or repeatedly deferred.
Knowledge centre
The accumulated exposure and operational burden created when vulnerability treatment is delayed or repeatedly deferred.
Design exceptions as visible, expiring risk decisions rather than permanent ticket closures.
A public identifier for a specific, disclosed cyber-security vulnerability.
A standard for describing the technical severity and characteristics of a vulnerability.
A daily estimate of the probability that a published CVE will be exploited in the wild during the next 30 days.
CISA’s catalog of vulnerabilities with evidence of exploitation in the wild.
The continuous discovery and assessment of internet-visible assets and services from an external perspective.
A continuous programme for scoping, discovering, prioritising, validating and mobilising action around material exposure.
A decision-tree approach that maps vulnerability evidence and stakeholder context to an action outcome.
A structured naming scheme used to identify hardware, operating systems and applications.