Patch Management

Vulnerability Management & the Art of Prioritization of Risk – SCW #45

September 29, 2020

There was a pretty extensive discussion on the Discord server during last week’s show that we thought was appropriate to discuss on air.

Josh kicked off the discussion by asking, “Anybody know any vulnerability remediation timeline guidance? Formalized, scientifically based stuff?”

Josh further clarified, “just trying to find the science behind why and when I should give a crap about vulnerabilities”.

He finally stated, “I am troubled by the lack of empirically based standards of remediation timing, remediation prioritization, remediation adjustment/offsets based on compensating controls.”

This launched a multi-threaded conversation that touched on vulnerability management, how to pass various compliance audits/assessments, the many vendors that have latched on to “prioritization” of vulnerabilities, or simply “Risk-Based Vulnerability Management”.

Of course, PCI became a focal point for much of the discussion because of the mention of vulnerability management, compensating controls, remediation timing, etc. – all of which is addressed within the PCI DSS (despite what Quadling thinks).

We’re going to try to find consensus on the problem, possible solutions (based on recognized sources), and provide advice. Visit for all the latest episodes!

Full Episode Show Notes

Vulnerability Management & the Art of Prioritization of Risk—-threats/vulnerability-management/vulnerability-prioritization-are-you-getting-it-right/a/d-id/1338519


[caption id="attachment_210" align="alignleft" width="120"]Jeff Man Jeff Man - Sr. InfoSec Consultant[/caption] [caption id="attachment_210" align="alignleft" width="120"]John Snyder John Snyder - CEO[/caption] [caption id="attachment_210" align="alignleft" width="120"]Josh Marpet Josh Marpet - COO[/caption] [caption id="attachment_210" align="alignleft" width="120"]Scott Lyons Scott Lyons - CEO[/caption]


[caption id="attachment_210" align="alignleft" width="120"]Liam Downward Liam Downward - CEO [/caption]


  • It’s official! Security Weekly, in partnership with CyberRisk Alliance, is excited to present Security Weekly Unlocked on December 10, 2020. The inaugural edition of Security Weekly Unlocked also celebrates Security Weekly’s 15th Anniversary. Registration and call for speakers is now open. Visit to submit your speaking session and register for free!

  • In our October 22nd technical training, we will provide a first look at a new, free resource that delivers thousands of remedies as a service to bridge the gap between vulnerabilities found, and vulnerabilities fixed! Visit to see what we have coming up! Or visit to view our previously recorded webcasts!

[audio src=""]
prestitial ad