A Vulnerability Scanner Is Not a Vulnerability Management Program As we move into CIS Control 7, Continuous Vulnerability Management, we're going to spend several weeks discussing how organizations identify and address weaknesses in their technology environments. We begin with Safeguard 7.1: Establish and Maintain a Vulnerability Management Process. That wording matters. This safeguard isn't asking whether you own a scanning tool or install patches. It's asking whether you have a documented...















