Vulnerability prioritization is the process of ranking identified security weaknesses by severity so remediation efforts are applied in the most effective order. Understanding when to escalate urgent patches and how zero-day vulnerabilities fit into this workflow are key components of a sound vulnerability management program.
Vulnerability Prioritization
Once we've found vulnerabilities on our network, and we've also done an assessment of what kind of vulnerabilities they are and classified them, the next step is that we've got to prioritize them: in which order we're going to fix these vulnerabilities, or remediate these vulnerabilities.
When it comes to vulnerability management, the first step is going to be to discover those vulnerabilities. Next, what we have to do is we have to validate the vulnerabilities and assess the vulnerabilities. Once we've done that, then we're going to start prioritizing them in the order in which we're going to tackle or fix or remediate these vulnerabilities.
This actually could be a pretty simple step. That is, you've already got some sort of classification, you've done some analysis on this and you've got some classification to it, so it could be categorized by a number or by these classifications of low, medium, high or critical. And then you'll have to decide now which order to put them in, and it's probably going to be based off of these classifications. You're going to tackle all the criticals, and then all the highs, and then all the mediums, and so on and so forth.
Now, we might not 100% of the time go with whatever the most critical one is first. There are other reasons why I prioritize; I have all different methods of prioritizing my projects, and in this case vulnerabilities and the fixes for those vulnerabilities. However, most of the time it's just going to be based off of the rating and what we should tackle.
There are times when things need to be escalated right away. That is, there is a patch that comes out and it needs to be applied right away, immediately, and if not it could put us at big risk. Now, you don't always find this through a vulnerability scan or pen testing. Usually it's found because there are big announcements and it's on news feeds, and this is an issue with this type of system and you need to patch it right away. And so we escalate it to being the top priority and we are going to push it out right away.
Now, sometimes this is mislabeled as zero day. Zero day is when the developers have zero days to respond to something, because they don't know about it, or maybe it's just been discovered. And so zero day happens pretty early on in the life cycle of a vulnerability. A lot of times I find that the patches come out, you need to deploy it ASAP, but for some reason people still call this a zero day. I think it's just mislabeled, but it is a term that's used and popular.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →