712-50 Question 351
Single answerDevelop vulnerability management systemsA newly appointed CISO is redesigning the enterprise vulnerability management program after several audit findings showed inconsistent scanning, weak remediation tracking, and poor alignment to business risk. The organization operates on-premises data centers, a growing cloud footprint, and several internet-facing customer applications managed by different business units. Budget is limited, so the CISO must first establish a vulnerability management system that improves risk reduction and executive reporting without creating excessive operational overhead. Which action should the CISO prioritize FIRST to build an effective vulnerability management system?
- A
Acquire the most advanced vulnerability scanning platform with threat intelligence feeds and deploy it across all environments immediately
- B
Define a risk-based vulnerability management framework that includes asset criticality, ownership, scan coverage requirements, remediation SLAs, exception handling, and reporting metrics
- C
Mandate immediate patching of all high and critical vulnerabilities within 48 hours across the enterprise, regardless of asset type or operational constraints
- D
Outsource all vulnerability remediation activities to a managed security service provider so business units are no longer responsible for patching
Show answer and explanation
Correct answer: B
Explanation
An effective vulnerability management system starts with governance and risk alignment, not just scanning or patching. CCISO-level decision making focuses on building a repeatable enterprise process that integrates asset inventory, business criticality, ownership, scanning, validation, prioritization, remediation, exception management, and metrics for leadership oversight. Best practices from NIST's Vulnerability Management guidance, NIST SP 800-40 on enterprise patch management, the CIS Critical Security Controls, and common industry practice all emphasize risk-based prioritization and clearly defined roles and processes. In this scenario, the audit findings point to systemic weaknesses: inconsistent scanning, weak tracking, and poor business alignment. Therefore, the CISO should first define the framework and governance model that the tooling and operational teams will follow. Once that is in place, the organization can select tools, set realistic SLAs, and produce executive reporting that reflects actual risk reduction rather than raw vulnerability counts.
- A. Incorrect.
This is not the best first action. Tooling can improve visibility, but purchasing and deploying a sophisticated scanner before establishing governance, scope, asset criticality, ownership, and remediation processes often reproduces the same weaknesses at larger scale. A common misconception is that vulnerability management problems are primarily technology problems; in practice, ineffective prioritization, unclear accountability, and weak reporting are frequent root causes.
- B. Correct.
This is correct. At the executive level, the first priority is to establish the operating model for vulnerability management: what assets are in scope, who owns them, how criticality is assigned, how often assets are scanned, how findings are prioritized based on business risk, what remediation timelines apply, how compensating controls and risk exceptions are approved, and which metrics are reported to management. This creates a sustainable system that can then be supported by appropriate tools and service providers.
- C. Incorrect.
This is incorrect because it applies a uniform remediation rule without regard to business context, asset criticality, exploitability, maintenance windows, compensating controls, or operational risk. While aggressive patching sounds strong, mature vulnerability management programs are risk-based rather than severity-only. For example, a CVSS high finding on an isolated internal system may present less risk than a medium-severity vulnerability on a critical internet-facing application with known exploitation activity.
- D. Incorrect.
This is incorrect as a first priority. External support may help with operational capacity, but outsourcing remediation does not remove internal accountability for asset ownership, change management, risk acceptance, and business prioritization. Vulnerability management is a governance and risk management function as much as a technical one. Without internal standards and decision rights, outsourcing can reduce visibility and create further inconsistency.