272 ◾ Information Security Management Handbook
invulnerable to this specific attack. Additionally, since systems visible to the Internet may be a more
accessible target, security analysts can refine their search to only those specific systems. e result is
a list of systems which are potentially vulnerable to an exploit and which may require attention. If
the enterprise must conduct a vulnerability assessment of the systems, an exploit may have already
occurred, costing the enterprise in financial, productivity, and potentially reputation losses.
While many security professionals conduct cursory assessment of their environment based
upon what they know of the configuration, the real solution and implementation of predictive
vulnerability asse