SOC & incident response · Lesson 5 of 5
Decide what needs fixing first
A vulnerability is a weakness; an exploit uses a weakness. When several findings compete for attention, a severity number is useful context, but it is not the whole priority decision.
Severity is only one input
Illustrative queue, after confirming each finding applies.
- Public gateway
Known exploitation, internet exposure, and an important service may justify earlier action.
- Isolated training machine
A higher base severity score may have lower urgency in this particular environment.
Read the visualDoes absence from the KEV catalog mean a finding is safe to ignore?
No. The catalog is one input and does not include every risk.
Confirm the finding applies
Check the affected product, version, and configuration. A scanner result needs validation against the asset before planning a fix.
Add threat and business context
Consider exposure, evidence of exploitation, the system’s importance, and existing safeguards. CISA’s Known Exploited Vulnerabilities catalog is one input, not a list of every risk.
Assign and verify the work
Coordinate with the system owner, document the fix or mitigation, and check that it worked. Track unresolved risk rather than treating an assigned ticket as a completed repair.
Put it in context
In a fictional queue, a public gateway has an applicable vulnerability known to be exploited. A separate finding has a higher base severity score but affects an isolated training machine. The gateway may deserve earlier action after checking the surrounding facts and the response policy.
Prioritize the risk to your environment, then verify the result.
Read the sources
Make it stick.
Try one short question to check your understanding and save this lesson to your progress.