In Safeguard 7.1, we discussed the difference between running a vulnerability scanner and operating a vulnerability management program. A scan may identify weaknesses, but the organization still needs a documented process that explains what happens next. That brings us to CIS Safeguard 7.2: Establish and Maintain a Remediation Process. The safeguard calls for a documented, risk-based remediation strategy that is reviewed at least monthly. The phrase “risk-based” matters. Most organizations...















