TVM-08: Is vulnerability remediation prioritized using a risk-based model from an
industry-recognized framework?
Vulnerabilities should be prioritized in terms of their relative risk, importance, organizational impact, and urgency. When evaluating impact, consider exposure levels to applicable threats from the organization’s specific usage and/or implementation. When evaluating importance, consider the criticality and value of the affected assets. Finally, when assessing urgency, consider the Common Vulnerability Scoring System (CVSS) ratings and timeframes, the relevance to current and ongoing threats, and the effort required for remediation.
Control implemented
Control ownership
Description
Use a risk-based model for effective prioritization of vulnerability
remediation using an industry recognized framework.