Independent DIB implementation resource — not affiliated with or endorsed by the U.S. Department of WarView the official DoW campaign ↗
IT-06IT SYSTEMSOFFICIAL INTENTEXPERT REVIEWED

Risk-Based Vulnerability Management

You will never fix every vulnerability, so fix the ones that matter first. Risk-based vulnerability management pairs regular scanning with prioritization by exploitability and exposure — known-exploited vulnerabilities and internet-facing systems go to the front — and drives remediation against agreed timelines you actually meet.

EXPLAINER · 5 SCENES · ≈40 SEC · CAPTIONS, NO AUDIO

IT-06 in 40 seconds

The problem, the plain-words meaning, three key moves, and what “done” looks like.

Official intent

What the campaign asks for

Run risk-based vulnerability management: find exposures, prioritize by real-world risk, and remediate on a schedule. The official source remains authoritative.

Read the official campaign ↗

Why it matters

Attackers exploit known, unpatched vulnerabilities far more often than novel ones. A program that scans, ranks by real risk, and closes exposures on a clock removes the openings adversaries scan for every day. Prioritization is what keeps the work finite and finishable instead of an endless backlog.

Minimum / Strong / Advanced

1
Minimum

Authenticated vulnerability scans run regularly and critical, internet-facing findings are remediated on a defined timeline.

2
Strong

Findings are prioritized by exploitability (e.g., known-exploited status) and exposure, with SLAs by severity that are tracked and met.

3
Advanced

Coverage is continuous across endpoints, servers, cloud, and applications; remediation is measured, and mean-time-to-remediate trends down.

Implementation timeline

First 24 hours
  • Confirm scanning covers internet-facing systems
  • Check for any known-exploited vulnerabilities already public
Next 30 days
  • Run authenticated scans across endpoints and servers
  • Set remediation SLAs by severity
Next 60 days
  • Prioritize by exploitability and exposure, not raw CVSS alone
  • Close the critical and known-exploited findings first
By day 90
  • Extend coverage to cloud and applications
  • Report remediation rates and mean-time-to-remediate

Implementation steps

  1. Deploy authenticated vulnerability scanning across endpoints, servers, cloud, and network devices.
  2. Prioritize findings by real risk — known-exploited status and internet exposure ahead of raw CVSS.
  3. Set and agree remediation SLAs by severity, and align them with your patch process.
  4. Remediate on schedule; where you cannot patch, document a compensating control and a deadline.
  5. Track remediation rates and mean-time-to-remediate, and feed misses back into the process.

Validation

  • Confirm the last authenticated scan actually covered the full asset inventory, not a subset.
  • Verify critical and known-exploited findings were remediated within their SLA.
  • Check that exceptions have a documented compensating control and a review date.

Evidence to retain

Governance

Vulnerability management policy with severity SLAs

Configuration

Scanner coverage/configuration showing authenticated scans

Operations

Remediation tracking report and exception register

Validation

Trend of mean-time-to-remediate against SLA

Common failure modes

What looks done but is not

Unauthenticated scans that miss most of the risk, a scanner pointed at only part of the estate, and a backlog ranked by raw score while a known-exploited flaw sits open. A scan report nobody remediates is documentation of risk, not management of it.

Framework mappings

Independent mappings are aids, not authoritative equivalence or compliance determinations.

FrameworkRequirementRelationshipConfidence
NIST SP 800-1713.11.2DirectHigh
CMMC Level 2RA.L2-3.11.3DirectHigh
CIS Controls v8.17.1DirectHigh