TechKnowSurge
CompTIA CySA+ 2.5 CompTIA Security+ 2.5 NIST CSF ID.RA-06 NIST 800-53 RA-7
VideoSecurityFree

Action Plan

Vulnerability remediation requires a structured action plan that outlines the steps needed to address identified security weaknesses, from simple patches to complex mitigation strategies. This content covers the planning phase of the vulnerability management cycle and the most common remediation approaches used in practice.

Complete this video to capture a CTF flag worth 1 point.

About this video

After vulnerabilities have been identified, assessed, and ranked by priority, the vulnerability management cycle moves into the planning phase. This is where organizations determine exactly how each vulnerability will be remediated and document those steps in a formal action plan. That plan often takes the form of a report delivered to management, clients, or other stakeholders as evidence of a structured, accountable approach to reducing exposure. Remediation strategies vary widely depending on the nature of the vulnerability and the environment in which it exists. When a vendor patch is available, applying it is typically the most straightforward path. For situations where a direct fix is not practical, compensating controls can be introduced to reduce risk without eliminating the underlying weakness. Legacy systems that cannot be updated may need to be segmented or isolated from the broader network to limit their attack surface. Configuration management improvements and security awareness training for staff are also common mitigation measures, as is revisiting business requirements when those requirements themselves contribute to the risk. A well-constructed action plan ensures that remediation efforts are organized, traceable, and aligned with organizational priorities.

What you'll learn

What's covered

Vulnerability Action Planning

Aligned to

CompTIA CySA+
2.5 Explain concepts related to vulnerability response, handling, and management.
CompTIA Security+
2.5 Explain the purpose of mitigation techniques used to secure the enterprise.
NIST CSF
ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated.
NIST 800-53
RA-7 Risk Response

Key terms

Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Patch Management
The process of acquiring, testing, and installing software updates to fix vulnerabilities and improve functionality.
Network Segmentation
The practice of dividing a network into smaller segments to improve performance and limit the spread of security threats.
Configuration Management
The process of tracking and controlling changes to hardware, software, and documentation throughout a system's lifecycle.
Risk Management
The ongoing process of identifying, assessing, and mitigating risks to an acceptable level.
Compensating Control
An alternative security measure implemented to offset a known risk or vulnerability when a primary control cannot be fully applied. A compensating control must provide an equivalent or greater level of protection.
Vulnerability Action Plan
A documented set of actionable steps outlining how identified vulnerabilities will be prioritized and mitigated.
Security Awareness Training
An ongoing program that educates employees about cybersecurity threats, safe practices, and organizational policies to reduce human-based risk. Effective training covers topics like phishing recognition, password hygiene, and social engineering.

Topics

Vulnerability Management Patch Management Compensating Controls Network Segmentation Configuration Management Security Awareness Training Cybersecurity

Transcript

Sometimes if we were to find a vulnerability, it could be as simple as just doing a simple patch or some other simple fix to fix that vulnerability, where other times it could be a whole project to fix that vulnerability. In that case we might want to create an action plan. I even had a customer that, when we found vulnerabilities, they wanted to see our action plan and how we were going to fix that vulnerability.

We've reached the planning phase in our cycle here. We've already discovered vulnerabilities, we've assessed those vulnerabilities, prioritized the order in which we want to fix them, and now we need to have a plan on how we're going to fix those vulnerabilities. Many times this plan would actually result in a report, a report that we may have to hand over to others to show what is going to be our actionable steps in mitigating these vulnerabilities.

Common mitigating actions

Here's some common actions that we would take to mitigate these vulnerabilities:

  • Maybe we just have to do some patching, because there's already a patch for that vulnerability.
  • Maybe we take out some extra insurance to compensate, so we have some sort of compensating controls.
  • Perhaps we can't fix this legacy system or something that's going on, and so maybe we want to segment or isolate that machine from the rest of the network.
  • Maybe we need to improve our configuration management or change the configuration.
  • There's also awareness, education and training, where maybe we need to educate our employees better, or change our processes.
  • Maybe we just adjust our business requirements.

An action plan is really going to help us take an organized approach to mitigating these vulnerabilities that we find.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →