A little learning. A little more confidence.Your next step starts here

SOC & incident response · Lesson 5 of 5

Decide what needs fixing first

A vulnerability is a weakness; an exploit uses a weakness. When several findings compete for attention, a severity number is useful context, but it is not the whole priority decision.

SEE THE IDEA

Severity is only one input

Illustrative queue, after confirming each finding applies.

  1. Public gateway

    Known exploitation, internet exposure, and an important service may justify earlier action.

  2. Isolated training machine

    A higher base severity score may have lower urgency in this particular environment.

Compare exposure, exploitation, impact, applicability, and safeguards using your response policy.
Read the visualDoes absence from the KEV catalog mean a finding is safe to ignore?

No. The catalog is one input and does not include every risk.

Confirm the finding applies

Check the affected product, version, and configuration. A scanner result needs validation against the asset before planning a fix.

Add threat and business context

Consider exposure, evidence of exploitation, the system’s importance, and existing safeguards. CISA’s Known Exploited Vulnerabilities catalog is one input, not a list of every risk.

Assign and verify the work

Coordinate with the system owner, document the fix or mitigation, and check that it worked. Track unresolved risk rather than treating an assigned ticket as a completed repair.

Put it in context

In a fictional queue, a public gateway has an applicable vulnerability known to be exploited. A separate finding has a higher base severity score but affects an isolated training machine. The gateway may deserve earlier action after checking the surrounding facts and the response policy.

Prioritize the risk to your environment, then verify the result.

Read the sources

Make it stick.

Try one short question to check your understanding and save this lesson to your progress.

YOUR LEARNING SPACE