Chapter 3

Program and Organization

The structure and composition of an IT or compliance organization can have a significant impact on the effectiveness of vulnerability management (VM). It is important to understand the relationship between the business stakeholders and the managers of underlying IT assets. It is this relationship that should reflect the adage that IT exists to support the business. If you can get the support of the business, then IT will be driven to support a VM program and comply with supporting policy. To put it more simply, VM must be a business priority. Otherwise, it is not worth doing.

Support of the business is the essence of the VM program. It encompasses all activities, technology, ...

Get Vulnerability Management, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.