What to track for each vulnerability
| Field | Why it matters |
|---|---|
| Asset | Shows which system, service, application, device, or supplier is affected. |
| Owner | Makes remediation accountable. |
| Source | Scanner, vendor notice, researcher report, internal finding, or incident. |
| Severity | Provides technical risk signal. |
| Business criticality | Shows whether the affected service matters to customers or operations. |
| Exposure | Internet-facing, internal, privileged, sensitive data, or supplier-managed. |
| Action and due date | Turns the finding into work. |
| Exception | Records accepted risk, compensating controls, and review date. |
| Verification | Shows that remediation was checked. |
Do not prioritize by CVSS alone
Technical severity is important, but it is not the whole story. A medium vulnerability on an internet-facing customer portal may need faster action than a high vulnerability on a retired internal test system. Context matters.
Useful prioritization combines severity, exploitability, exposure, asset criticality, data sensitivity, available mitigations, supplier dependency, and whether the weakness is connected to an active incident.
Evidence for vulnerability management
- Vulnerability register or ticket queue.
- Scanner reports or vendor advisories.
- Patch deployment records.
- Change approvals where required.
- Exception approvals and review dates.
- Verification screenshots, scans, logs, or tickets.
- Management escalation for overdue critical findings.
- Supplier notices and remediation confirmations.
Where Framework-Pro helps
Framework-Pro can help generate vulnerability management policy drafts, control mapping, owner expectations, evidence placeholders, and recurring review tasks. That gives teams a structured starting point before choosing more tooling.
The organization still needs to run the process, patch systems, validate fixes, and manage exceptions responsibly.
Quick FAQ
What is NIS2 vulnerability management?
It is the process for identifying, prioritizing, fixing, accepting, verifying, and reviewing vulnerabilities that affect systems, services, suppliers, or data.
What should be tracked?
Track asset, owner, source, severity, exploitability, business criticality, action, due date, exception, verification, and supplier dependency.
Is a vulnerability scanner enough?
No. A scanner finds issues, but teams still need ownership, prioritization, remediation, evidence, exceptions, and review.
How does Framework-Pro help?
It can help create policy drafts, control mappings, and evidence placeholders for the vulnerability management process.
Official sources used
These pages were used for factual grounding. aneo summarizes them in original wording and does not provide legal advice.
