Build an asset inventory and scan coverage model that reflects actual infrastructure exposure.
Vulnerability Management Programmes and Patch Prioritisation
Builds risk-based vulnerability scoring, patch prioritisation and exception governance so remediation effort targets genuinely exploitable risk first.
Course Overview
Most organisations can identify thousands of vulnerabilities in a single scan and remediate only a fraction before the next scan finds thousands more, which makes prioritisation the actual discipline rather than detection. This course teaches vulnerability management programme design centred on risk-based patch prioritisation: combining CVSS scoring, Exploit Prediction Scoring System data and the CISA Known Exploited Vulnerabilities catalogue to focus effort where exploitation is real. Participants learn to build asset inventory and scan coverage models, run software composition analysis for open source risk, and design patch testing and staged rollout processes that avoid faulty updates causing outages. Sessions also cover documented risk acceptance workflows for vulnerabilities that cannot be remediated immediately and the reporting needed to show programme performance. Exercises include scoring a sample vulnerability set with context-aware criteria, building a prioritisation model for a mixed asset environment, and drafting a risk acceptance record with compensating controls and an expiry date. Participants leave with reusable scoring criteria, prioritisation templates and a reporting structure for remediation metrics.
Expected Learning Outcomes
Score vulnerabilities using CVSS, EPSS and the CISA Known Exploited Vulnerabilities catalogue.
Build a risk-based patch prioritisation model that goes beyond raw CVSS severity scores.
Test and stage patch deployment to limit the blast radius of faulty updates.
Run software composition analysis and maintain a software bill of materials for critical applications.
Design a documented risk acceptance workflow for vulnerabilities that cannot be patched immediately.
Report mean time to remediate and vulnerability ageing trends to programme stakeholders.
Who Should Attend
Vulnerability management analysts responsible for scan coverage and remediation tracking.
Security engineers building or maturing a formal vulnerability management programme.
IT operations teams accountable for patch testing, deployment and change coordination.
Application security engineers managing open source and container image risk.
Risk and compliance officers reviewing exception and risk acceptance workflows.
Chief information security officers reporting remediation performance to the board.
Course Modules
Select any module to see its sessions and points.
01Building the Vulnerability Management Programme
2 sessions · 8 points
Session 1Establishing Asset Visibility and Scan Coverage
- Build and maintain an asset inventory that scanning coverage can be measured against.
- Choose authenticated scanning where credentials are available to reduce false negatives.
- Schedule scan cadence by asset criticality and exposure rather than one fixed interval.
- Extend coverage to cloud misconfigurations, container images and open source dependencies.
Session 2Scoring and Contextualising Vulnerabilities
- Apply CVSS base, temporal and environmental scoring to reflect actual exploitability in context.
- Incorporate Exploit Prediction Scoring System data to separate theoretical from active risk.
- Cross-reference findings against the CISA Known Exploited Vulnerabilities catalogue for urgency.
- Weight asset business criticality alongside technical severity when ranking remediation order.
02Prioritising and Planning Remediation
2 sessions · 8 points
Session 1Risk-Based Patch Prioritisation
- Build a prioritisation model combining exploitability, asset criticality and exposure, not CVSS alone.
- Set patch service level agreements that vary remediation deadlines by calculated risk tier.
- Distinguish vulnerabilities requiring emergency out-of-cycle patching from routine cycle inclusion.
- Communicate prioritisation rationale clearly to the asset owners who must schedule the work.
Session 2Testing and Deploying Patches Safely
- Test patches in a representative non-production environment before wide deployment.
- Stage patch rollout across environment rings to limit the blast radius of a faulty update.
- Coordinate patch deployment windows with change management to avoid conflicting releases.
- Apply compensating controls such as network segmentation when immediate patching is not feasible.
03Managing Software Supply Chain and Open Source Risk
2 sessions · 8 points
Session 1Software Composition Analysis and SBOM Practice
- Run software composition analysis to identify vulnerable open source dependencies in application code.
- Generate and maintain a software bill of materials for critical applications.
- Prioritise dependency updates that fix vulnerabilities without introducing breaking changes.
- Track transitive dependency risk that direct dependency scanning alone tends to miss.
Session 2Container and Cloud Workload Scanning
- Scan container images for known vulnerabilities before they are promoted to a registry.
- Block deployment of images that exceed an agreed vulnerability severity threshold.
- Scan cloud workloads and configurations continuously rather than at a single fixed point.
- Remediate vulnerable base images by rebuilding rather than patching running containers.
04Governance, Exceptions and Continuous Reporting
2 sessions · 8 points
Session 1Handling Exceptions and Residual Risk
- Design a risk acceptance workflow for vulnerabilities that miss the standard remediation deadline.
- Require documented compensating controls and expiry dates on every accepted risk.
- Escalate ageing high-risk exceptions to appropriate governance forums for renewed decisions.
- Audit exception records periodically to confirm compensating controls remain effective.
Session 2Measuring and Reporting Programme Performance
- Track mean time to remediate by severity tier and asset criticality as the core programme metric.
- Report vulnerability ageing trends that reveal remediation bottlenecks by team or system.
- Present programme performance to leadership alongside residual risk and resourcing needs.
- Define a zero-day response process that can bypass standard cycles during active exploitation.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
