Cybersecurity vulnerability assessments are performed, at least in an ad hoc manner
There are many types of assessment techniques that an enterprise can use to discover vulnerabilities, such as internal vulnerability audits and assessments, external-entity assessments, penetration tests, software-based scans, and reviewing the results of internal and external audits. Vulnerabilities can also be discovered from review and capture from the organization’s standard list of sources of vulnerability information.
Related Practices · Progression: This practice is part of a practice progression. Practice progressions are groups of related practices that represent increasingly complete or more advanced implementations of an activity. The practices in this progression include: THREAT-1c, THREAT-1f, THREAT-1k.