From the course: Vulnerability Management: Assessing the Risks with CVSS v3.1

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Accepting vulnerability risks

Accepting vulnerability risks

From the course: Vulnerability Management: Assessing the Risks with CVSS v3.1

Start my 1-month free trial

Accepting vulnerability risks

- [Instructor] Have you ever gotten a crack in your windshield that was too big to repair? If the crack isn't in your main line of sight you might just accept that there's a crack and deal with it or you might wait and see if it gets worse before you pony up for the insurance deductible. Deciding how to handle some vulnerabilities is a similar proposition. So far we've addressed how to fix or resolve vulnerabilities but we've been avoiding a very real problem. What do you do when you find vulnerabilities that you just can't fix? And what about vulnerabilities you don't think are worth fixing? How about vulnerabilities that have a patch, but applying the patches risky it might break something? Red 30, like most companies has a few legacy systems that are critical to the business. Sometimes these systems are very fragile and it seems like they can't handle anything other than their assigned purpose. There can be a number of…

Contents