You are on page 1of 5

Resource ID: w-013-3774

Cybersecurity Tech Basics: Vulnerability


Management: Overview
SEAN ATKINSON, CIS™ (CENTER FOR INTERNET SECURITY),
WITH PRACTICAL LAW INTELLECTUAL PROPERTY & TECHNOLOGY

Search the Resource ID numbers in blue on Westlaw for more.

A Practice Note providing an overview of what „„Design, implementation, or other vendor oversights that create
defects in commercial IT products (see Hardware and Software
cyber vulnerability management programs Defects).
are, how they work, and the key role they play „„Poor setup, mismanagement, or other issues in the way an
organization installs and maintains its IT hardware and software
in any organization’s information security
components (see Unsecured Configurations).
program. This Note discusses common types of
Vulnerability management programs address these issues. Other
cyber vulnerabilities and core process steps for common vulnerabilities that organizations must also tackle in their
implementing and maintaining a vulnerability information security programs include:
„„Gaps in business processes.
management program to decrease cybersecurity
„„Human weaknesses, such as lack of user training and awareness.
risks. It also addresses common pitfalls that „„Poorly designed access controls or other safeguards.
can lead to unnecessary cyber incidents and „„Physical and environmental issues.
data breaches. Unlike threats, organizations can often directly control their
vulnerabilities and therefore minimize the opportunities for
threat actors.
Most organizations depend on a combination of commercial and
custom-developed hardware and software products to support their Organizations that develop their own in-house software should
information technology (IT) needs. These technology components use security by design techniques to avoid creating vulnerabilities.
inevitably include vulnerabilities in their design, setup, or the code that For more information on assessing overall data security risks and
runs them. Cyber vulnerabilities, coupled with growing threats, create related legal considerations, see Practice Note, Data Security Risk
risks by leaving organizations open to attacks, data breaches, and other Assessments and Reporting (W-002-2323) and Performing Data
cyber incidents. These events often lead to regulatory enforcement, Security Risk Assessments Checklist (W-002-7540).
litigation, or credibility loss. Organizations and their counsel must Vulnerability management programs:
understand these risks and address vulnerability management in a
„„Define a formal process to:
well-defined and managed information security program.
zz timely identify applicable vulnerabilities;
This Note provides an overview of what cyber vulnerability zz close the security gaps that vulnerabilities create by remediating
management programs are, how they work, and the important role
or at least mitigating their effects; and
they play in any organization’s information security program.
zz track and document an organization’s efforts.
„„Prioritize often limited IT resources. Organizations must focus
VULNERABILITY MANAGEMENT DEFINED
on vulnerabilities according to their level of risk, particularly
Vulnerabilities are weaknesses or other conditions in an organization considering the sheer volume of changes that diligent vulnerability
that a threat actor, such as a hacker, nation-state, disgruntled management can demand.
employee, or other attacker, can exploit to adversely affect data
„„Continuously monitor and evaluate an organization’s IT
security. Cyber vulnerabilities typically include a subset of those
environment to ensure compliance and avoid re-introduction
weaknesses and focus on issues in the IT software, hardware, and
of known vulnerabilities.
systems an organization uses. For example:

© 2018 Thomson Reuters. All rights reserved.


Cybersecurity Tech Basics: Vulnerability Management: Overview

„„Minimize cyber attack risks by decreasing the number of gaps that for security researchers, commit organizations to avoid legal
attackers can exploit, also known as the organization’s “attack action if others follow their policies, and provide guidance on how
surface.” to notify them of identified vulnerabilities. Some organizations
provide cash or other incentives to encourage good-faith
Some refer to vulnerability management programs as “patch responsible security researchers. The incentives are typically
management” because vendors often provide software patches known as “bug bounty” programs. Several specialist companies
or updates that organizations can apply to remediate their systems. offer bug bounty program management and support services and
However, applying patches is only one means of managing some are well-known in the security researcher community.
vulnerabilities. Organizations can also protect themselves by
using secure configurations and defense-in-depth techniques that Following vulnerability identification, vendors generally provide
layer multiple security controls. Sound vulnerability management a software patch or other fix using an advisory. Hardware defects
programs take a broad view and leverage patching and other can be more challenging to remedy in current products, although
safeguards. vendors may provide software fixes or information on mitigation
techniques. Industrial control systems and the increasing use of
Vulnerability management programs play an important role in any internet of things (IoT) devices present additional opportunities for
organization’s overall information security program by minimizing hardware defects. These products can be:
the attack surface, but they are just one component. For details on
„„More vulnerability-prone due to manufacturers’ too frequent lack
the key steps for implementing a formal vulnerability management
program, see How Vulnerability Management Programs Work. of security focus and expertise.
For information on building a comprehensive information security „„More difficult to remediate because of their limited user interfaces
program, see Information Security Toolkit (W-002-8679). and lack of update capabilities.

HARDWARE AND SOFTWARE DEFECTS For more information on gathering vendor advisories, see
Maintaining Awareness and Detecting Vulnerabilities.
Defective hardware and software products are the source of many
cyber vulnerabilities. Vendors fail to follow security by design UNSECURED CONFIGURATIONS
principles or fully test their products. The tactics, techniques, and
Improper configurations or poor system management can cause
procedures (TTPs) that attackers use have grown increasingly
cyber vulnerabilities even in fully patched hardware and software
sophisticated. Changing TTPs mean that some vendors’ designs
components. Factory-default settings may include easily guessed
may not have contemplated certain attack strategies. Attackers also
passwords or leave unnecessary services running.
range from unskilled amateurs, known as script kiddies, that use
other hackers’ tools to malicious insiders, activists, criminals, and Each organization’s IT environment and business needs are
highly funded nation-state actors. For more information on common unique. Reviewing typical device and software categories allows
cyber attacks, see Practice Note, Cybersecurity Tech Basics: Hacking an organization to recognize and avoid potential vulnerabilities, by
and Network Intrusions: Overview (W-003-3498). considering, for example:
This heightened threat climate results in a larger number of „„Network elements. Various network elements, such as routers,

identified vulnerabilities. Vendors typically identify hardware and switches, and firewalls, provide internal and external connectivity
software product vulnerabilities using several methods, including: and control network traffic. Organizations configure these
devices with rules to distinguish potentially malicious traffic from
„„Testing. Vendors perform their own product testing, and in some
legitimate data flows. Incorrectly applied rules, misconfigured
cases, employ internal or external security specialists that focus
access controls, or unnecessarily open hardware and software
on discovering and fixing vulnerabilities. These specialists are
entry points or “ports” can:
usually called white hats, red teams, ethical hackers, or in the case
of external experts, penetration testers. Building in strong security zz create unnecessary vulnerabilities; and
measures or fixing identified vulnerabilities often competes with zz make the organization vulnerable to network intrusions and data
other business priorities. This conflict and the complexity of full theft or exfiltration.
security testing for many products, especially given attackers’ „„Servers. Organizations often maintain their own servers for various
changing TTPs, results in distributed products that still contain IT functions, including end user file sharing and printer support,
vulnerabilities. databases, applications, and websites. General purpose servers
„„Active exploits. Vendors may learn of product vulnerabilities commonly run Windows, Linux, or Unix operating systems and
only after attackers exploit them and victims, law enforcement, by default enable a wide variety of services and communication
or other incident responders identify them as the attack’s cause. mechanisms. Organizations should tailor these default settings
These unfortunate situations are called “zero-day vulnerabilities.” to a server’s particular purpose and their specific needs to reduce
Vendors generally have time to provide a fix for identified the attack surface. Servers also often have factory-default
vulnerabilities before attackers exploit them. Here that is not administrative settings and passwords that may leave the
the case, hence the zero-day term. Some actors, including organization vulnerable to attack unless changed.
governments, allegedly identify and hoard vulnerabilities, using „„End user devices. Attackers increasingly target end user
them to attack others rather than timely notifying vendors. devices, such as desktops, laptops, and mobile devices, because
„„Bug bounty and vulnerability disclosure programs. Formal they provide an entry point into an organization’s broader IT
vulnerability disclosure programs and policies set boundaries environment (for more details on these attacks against end users,

2 © 2018 Thomson Reuters. All rights reserved.


Cybersecurity Tech Basics: Vulnerability Management: Overview

see Practice Note, Cybersecurity Tech Basics: Malware and End MAINTAINING AN ASSET INVENTORY
User Attacks: Overview (W-003-4711)). Vulnerabilities commonly Organizations cannot protect assets unless they know about them.
occur when organizations fail to securely configure and maintain Maintaining a detailed IT hardware and software asset inventory,
the devices with: including specific versions, is a foundational element of any best
zz current anti-virus and other tools to counter malicious software practices based information security program (see Best Practices).
(malware);
Tracking IT assets at an enterprise level can be complex and
zz host-based firewalls to protect them from unauthorized internet challenging because:
traffic; and
„„Organizations constantly add, remove, and change their IT assets.
zz data encryption of personal information or other confidential data.
„„Virtual server environments that run multiple systems or functions
„„Browsers. Web browsers typically include configuration settings
on a single hardware platform often include various software
for code execution and digital certificate handling. Mismanaging packages and versions.
these settings creates vulnerabilities by potentially allowing
„„Organizations typically allow at least some individuals to install
unauthorized programs to run or users to access malicious,
unsecured, or otherwise unreliable websites. software on the laptops or other end user devices that they use,
creating significant variation and more software packages to track.
„„Other software and applications. Commercial software and
„„Bring Your Own Device (BYOD) programs that allow employees
applications often similarly include default configuration settings
that organizations must tailor to avoid vulnerabilities, such as: to connect their own mobile devices to an organization’s network
and systems, while convenient and cost-effective, often require
zz allowing for unauthorized code execution; and organizations to manage additional software packages. For more
zz creating unprotected internet communication channels. information on BYOD programs and a sample policy, see Standard
Document, Bring Your Own Device to Work (BYOD) Policy
Organizations should maintain an accurate asset inventory and
(1-521-3920).
establish secure configuration standards for each major device and
software category to avoid creating unnecessary vulnerabilities. For „„Increased use of cloud computing environments may require
more on these process steps, see Maintaining an Asset Inventory and unique management processes, according to the particular
Establishing Secure Configurations. deployment models chosen.
Some organizations integrate automated IT asset tracking systems
HOW VULNERABILITY MANAGEMENT PROGRAMS WORK into their procurement, deployment, and maintenance processes.
Vulnerability management requires an ongoing, cyclical process These tools can help track larger and more complex environments,
because: but can be costly to implement and maintain. Other organizations
use ticketing systems, custom-developed databases, or even manual
„„New vulnerabilities are regularly identified and made public.
processes and spreadsheets to maintain inventory lists.
„„Previously identified vulnerabilities can still create cyber attack
opportunities, if organizations: Regardless of the method or tools chosen, reasonably controlling
zz do not promptly remediate them; or vulnerabilities requires organizations to:
„„Diligently maintain their IT asset inventories.
zz allow their re-introduction through poorly configured
or mismanaged devices and systems (see Unsecured „„Assign authority and establish information security policies to ensure
Configurations). that they acquire, develop, and track IT assets in a secure manner.

Five core process steps help organizations implement and maintain For more details on developing information security policies and a
a reasonable vulnerability management program. Specifically, model policy, see Practice Note, Developing Information Security
organizations must: Policies (W-001-1336) and Standard Document, Information Security
„„Understand their current IT environments by tracking hardware
Policy (W-001-2990).
and software assets, including current versions and applied
ESTABLISHING SECURE CONFIGURATIONS
patches (see Maintaining an Asset Inventory).
Organizations often create unnecessary cyber vulnerabilities by
„„Set standards for the hardware and software components
deploying IT hardware and software components with default
that they use to avoid creating unnecessary vulnerabilities (see
settings or unnecessary services (see Unsecured Configurations).
Establishing Secure Configurations).
Defining standard secure configurations for the organization’s
„„Stay abreast of newly identified vulnerabilities in the hardware and preferred network elements, servers, and end user devices helps
software products that they use or plan to use (see Maintaining manage vulnerabilities by:
Awareness and Detecting Vulnerabilities).
„„Creating deployment checklists, templates, or system images that
„„Remediate or at least mitigate the effects of identified take the guess work out of ensuring secure deployments.
vulnerabilities according to the risk and exposure levels that they
„„Avoiding activation of unnecessary services or other security gaps by
create (see Mitigating and Remediating Identified Vulnerabilities).
tailoring setup to the organization’s particular needs and environment.
„„Continuously monitor their IT environments to identify vulnerable
„„Minimizing the number of variations, especially in large organizations
assets and avoid re-introduction of known vulnerabilities (see
that may have hundreds or thousands of each device type.
Continuously Monitoring the Organization’s IT Environment).

© 2018 Thomson Reuters. All rights reserved. 3


Cybersecurity Tech Basics: Vulnerability Management: Overview

„„Simplifying patch management when vendors provide fixes for organizations with simple environments that consistent mainly of
hardware and software defects (see Hardware and Software Defects). end user devices may depend on vendors’ automatic update features,
„„Providing a known baseline that organizations can deviate from such as Microsoft’s Windows Update.
when special needs arise by documenting exceptions in the Some systems cannot tolerate patching because:
organization’s asset inventory (see Maintaining an Asset Inventory).
„„Testing for internally or custom-developed software fails.
For resources and guidance on establishing secure configurations, „„Different vendor product combinations create incompatibilities.
see Best Practices.
Organizations may require additional time to patch systems that
MAINTAINING AWARENESS AND DETECTING VULNERABILITIES run highly available business critical operations. Patches may not be
Organizations must maintain constant awareness and diligence to available for older legacy systems that organizations still depend on
stay abreast of newly identified vulnerabilities in the hardware and for important business functions.
software products that they use or plan to use. Specific individuals Mitigation techniques or compensating controls help manage
should be accountable for monitoring various resources, such as: risks on these systems. For example, an organization may isolate
„„Applicable vendor security advisory email lists and blogs, vulnerable systems on dedicated network segments or apply
including technically detailed versions for IT professionals. Many additional access, auditing, or monitoring controls.
vendors provide security-related information on their websites at
Organizations with more complex environments, especially those
[company].com/security.
with internally or custom-developed software, generally test patches
„„Government agency email lists and blogs that aggregate vendor
and other remediation measures in dedicated testing environments
reports and provide public security advisory notices in some before deployment. Software patches can have unintended effects,
countries. Examples include: so remediation plans should include system restoral options.
zz US Computer Emergency Readiness Team (US-CERT) bulletins Organizations should integrate their vulnerability mitigation
on their National Cyber Awareness System and the National and remediation activities into existing IT change management
Institute of Standards (NIST) National Vulnerability Database; procedures to avoid inadvertent business impact.
zz UK National Cyber Security Centre threat alerts and advisories;
Mitigation and remediation activities are not complete until they
zz South Korea’s KrCERT security bulletins (in Korean); and update the organization’s asset inventory to document changes
zz Canadian Cyber Incident Response Centre (CCIRC) bulletins. made and software installed (see Maintaining an Asset Inventory).
„„Cyber information sharing groups, such as industry and sector-
CONTINUOUSLY MONITORING THE ORGANIZATION’S IT
specific information sharing and analysis centers (ISACs). Some ENVIRONMENT
ISACs focus on particular geographies, while others serve common
critical infrastructure sectors, such as financial services. Sound vulnerability management requires ongoing vigilance to
identify vulnerable assets in an organization’s IT environment and
The sheer volume of advisories can be overwhelming for some avoid re-introduction of known vulnerabilities, because:
organizations, especially those that use a variety of hardware and „„Over time, system configurations change, sometimes weakening
software products. Organizations should: security controls and creating inadvertent gaps.
„„Determine exposure levels for each specific vulnerability by
„„New installs or changes to an organization’s IT environment may
reviewing published risk ratings and their own IT environment’s leave specific network elements, servers, laptops, or other devices
characteristics. unprotected from known vulnerabilities. For example, some
„„Set remediation priorities according to risk and exposure levels. For updates may inadvertently remove previously applied patches or
example, a low risk advisory that applies to one or two internally change secure settings.
facing servers likely does not require the same level of urgency as a
high risk advisory that affects all laptops and desktops. Organizations ideally scan and assess their environments on a
continuous basis, especially higher risk or more exposed elements.
For resources on understanding typical risk ratings and other Regularly scheduled assessments demonstrate diligence and help
information often found in advisories, see Best Practices. minimize gaps. Various commercial and open source tools provide
these monitoring capabilities. The security content automation
MITIGATING AND REMEDIATING IDENTIFIED VULNERABILITIES protocol (SCAP) and related specifications define a set of standards
Organizations typically remediate identified vulnerabilities by: for vulnerability scanners. Organizations use these tools to scan their
„„Applying patches or other vendor-supplied updates for hardware environments and identify:
and software defects (see Hardware and Software Defects). „„Devices that have not been patched to remediate known hardware

„„Updating configurations to use more secure settings or deactivate and software defects (see Hardware and Software Defects).
unnecessary services or communication channels (see Unsecured „„Systems with unsecured configurations settings or other security
Configurations). gaps (see Unsecured Configurations).
Some organizations use automated software distribution tools NIST’s SCAP Validation Program accredits independent laboratories
or other products to apply patches and track software updates, which in turn test and validate vendor products against the SCAP
especially those with large or complex IT environments. Smaller standards. NIST maintains a list of currently validated products.

4 © 2018 Thomson Reuters. All rights reserved.


Cybersecurity
Cybersecurity Tech
Tech Basics:
Basics: Vulnerability
Vulnerability Management:
Management: Overview
Overview

AVOIDING COMMON PITFALLS zz Control #9: limitation and control of network ports, protocols,
Organizations still battle the same cybersecurity issues identified and services; and
more than 15 years ago, particularly in supporting proactive zz Control #11: secure configuration for network devices, such as
vulnerability management and continuous monitoring. Several firewalls, routers, and switches.
common pitfalls hamper many organizations’ efforts to manage „„Detailed guidance on secure configurations for common devices
cyber vulnerabilities, including: and systems, which are available from most vendors and
„„Lack of a current well-maintained hardware and software asset independent sources, such as:
inventory. zz NIST’s Common Configuration Enumeration (CCE) resources; and
„„Failure to routinely monitor vendor and other reliable sources for zz the Center for Internet Security’s CIS Benchmarks™.
vulnerability advisories. „„The Common Vulnerability Scoring System (CVSS), which defines
„„Failure to prioritize vulnerabilities according to the exposure and a standardized approach for describing and scoring vulnerabilities,
risk levels they create for the organization. according to risk and severity levels.
„„Lack of resources or willingness to timely remediate or mitigate „„The Common Vulnerabilities and Exposures (CVE) list, which
known vulnerabilities. provides an internationally recognized standard for naming and
„„Use of outdated hardware, software, and legacy systems that cataloging known cybersecurity vulnerabilities, with a maintained
cannot tolerate patching. list of many publicly released advisories.
„„Lack of standards for common device and system configurations, Organizations should:
complicating patching and other remediation efforts.
„„Garner leadership support and resources by emphasizing the
„„Failure to test patches before deployment or align vulnerability preventive nature of vulnerability management programs.
management activities with IT change management processes,
„„Cleary communicate the urgency and importance of remediating
leading to inadvertent business impacts or other unintended
vulnerabilities across the organization. Promptly remediating
consequences.
vulnerabilities can prevent many data breaches and cyber
„„Failure to continuously monitor the organization’s IT environment incidents.
to identify vulnerable components and avoid re-introducing known
„„Use established methods to score identified vulnerabilities
vulnerabilities.
according to their risk and exposure levels and accordingly
Organizations can avert these issues by: prioritize their remediation plans.
„„Establishing leadership support. „„Document their vulnerability management activities, including the

„„Allocating sufficient resources.


time required to patch or otherwise remediate issues. Program
documentation allows organizations to:
„„Following well-established best practices.
zz continuously improve their programs; and
„„Conducting periodic audits and program reviews.
zz demonstrate their diligence if a data breach or other cyber incident
For more resources on building strong information security occurs and regulatory enforcement action or litigation ensues.
programs and avoiding common pitfalls, see Information Security „„Perform regular program audits to ensure they are addressing
Toolkit (W-002-8679). vulnerabilities in a timely manner and according to risk and
exposure levels.
BEST PRACTICES „„Treat their vulnerability management process as one element of
Vulnerability management programs have long been a part of a comprehensive information security program that is actionable,
reasonable information security programs. Best practices and other repeatable, and measurable.
resources are widely available to help organizations build robust
programs, including:
„„The NIST Cybersecurity Framework, which is a risk-based
methodology for building a comprehensive information security ABOUT PRACTICAL LAW
program, including vulnerability management (for more details
Practical Law provides legal know-how that gives lawyers a better starting
on the Framework, see Practice Note, The NIST Cybersecurity
point. Our expert team of attorney editors creates and maintains thousands of
Framework (5-599-6825)). up-to-date, practical resources across all major practice areas. We go beyond
„„The CIS™ (Center for Internet Security) Critical Security Controls, primary law and traditional legal research to give you the resources needed to
which provide an informative reference for the NIST Framework practice more efficiently, improve client service and add more value.
and detail 20 key information security controls, including:
If you are not currently a subscriber, we invite you to take a trial of our online
zz Control #1: inventory and control of hardware assets;
services at legalsolutions.com/practical-law. For more information or to
zz Control #2: inventory and control of software assets; schedule training, call 1-800-733-2889 or e-mail referenceattorneys@tr.com.
zz Control #3: continuous vulnerability management;
07-18
zz Control #5: secure configuration for hardware and software on
© 2018 Thomson Reuters. All rights reserved. Use of Practical Law websites and services is subject to the
mobile devices, laptops, workstations, and servers; Terms of Use (http://static.legalsolutions.thomsonreuters.com/static/agreement/westlaw-additional-terms.pdf)
and Privacy Policy (https://a.next.westlaw.com/Privacy).

You might also like