Glossary · OT cybersecurity
Vulnerability management
Also known as: Vulnerability handling
German: Schwachstellenmanagement
In cybersecurity, vulnerability management is the continuous process of identifying, assessing, prioritizing, treating and verifying vulnerabilities in systems and products. For asset owners it covers installed assets; for product suppliers it includes handling reported vulnerabilities and delivering fixes.
- OT security
In one sentence
Vulnerability management is the continuous process of identifying, assessing, prioritizing, treating and verifying vulnerabilities in systems and products.
Example
When a new advisory for a switch model arrives, the plant's vulnerability management process matches it to the asset inventory, rates exposure, schedules the firmware update and applies a temporary firewall rule.
Explained in context
Context cards connect this term with others to answer one question. Also in British English and German.
- The SBOM under BSI TR-03183-2: an inventory, not a vulnerability reportWhat does BSI TR-03183-2 require of a software bill of materials, and how does it relate to the CRA?UKDeutsch
- Receiving vulnerability reports under BSI TR-03183-3: report, notification, advisoryWhat does BSI TR-03183-3 expect a manufacturer to have in place before the first vulnerability report arrives?UKDeutsch
How it applies
- Operation: Asset owners combine Asset inventory, advisory feeds and scans to find vulnerabilities, then decide per case: patch, mitigate (segmentation, disabling a service), accept with justification, or replace the device. In OT, patching often waits for a maintenance window, so mitigations bridge the gap.
- Product development: Suppliers need a process to receive reports, analyze and fix vulnerabilities and publish advisories. The Cyber Resilience Act (CRA) makes vulnerability handling an essential requirement for products with digital elements, and IEC 62443-4-1 covers it in its practices.
- Maintenance: Verification closes the loop: confirm that the fix or mitigation is in place and effective.
- Documentation: Keep decisions and justifications, especially accepted risks, as records. Product documentation should explain how customers are informed about vulnerabilities and where advisories are published.
Vulnerability management vs. patch management
Patch management handles the deployment of software updates. Vulnerability management is broader and also covers assessment, mitigations without patches and risk acceptance.