Reporting for Vulnerability Management

Out-of-the-box vulnerability reports are not very useful. I have found that by simplifying the information we are reporting to the remediation teams and also by targeting individuals with only the vulnerabilities they are responsible for remediating two things happen. More vulnerabilities get worked on and people start to speak up when there are roadblocks. Both of these outcomes are positive and lead to higher levels of engagement and deeper analysis and problem solving.

