Strategic Vulnerability and Threat Management
Vulnerability management training for the person who owns the backlog nobody is closing. Eight weeks on running it as a programme: coverage, prioritisation with exploitability and threat context, service level agreements that hold, and reporting that shows risk coming down.
Scanners are the easy part. The course focuses on the decisions and the negotiation with the teams who have to do the patching.
- Duration
- 8 weeks
- Format
- Live online, instructor-led
- Prerequisites
- None required
- Class size
- Capped at 12 learners

What you will be able to do
- Measure scanning coverage honestly and find the assets nobody is scanning
- Prioritise using exploitability, exposure and asset value rather than CVSS alone
- Apply known exploited vulnerability data and threat intelligence to your queue
- Negotiate remediation SLAs that engineering teams will actually meet
- Design an exception process with owners, compensating controls and expiry dates
- Evaluate scanning and prioritisation tooling against your own requirements
- Report risk reduction over time instead of counting open findings
- Run a programme review that removes work rather than only adding it
Course outline
6 modules
- Defining the programme scope, owners and decision rights
- Asset inventory as the limiting factor on everything else
- Cloud, container, mobile and unmanaged device coverage gaps
- Establishing a baseline you can measure improvement against
- Where vulnerability management ends and configuration management begins
What you need before you start
- Experience with vulnerability scanning output or patch management operations
- Understanding of CVE and CVSS at a working level
- Access to your own programme data or willingness to use supplied data sets
- About four hours a week outside class for the prioritisation exercises
Who this course is for
- Vulnerability management leads and programme owners
- Security managers accountable for patching outcomes across IT teams
- Infrastructure and platform leads who receive the findings
- Risk and compliance staff who report on remediation performance
Where this leads
Prepares you for
CRISC
Awarded by ISACA
Prioritisation, treatment and monitoring content here supports the risk response and reporting domains of ISACA CRISC. The exam, experience requirement and certificate come from ISACA. This academy provides preparation and practice only.
Questions about this course
More in security leadership and governance
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



