← Back to Learning

Vulnerability Management

Establish and operate a vulnerability management process for software products, based on IEC 62443-4-1.

Modules
7
Level
Practitioner
Formats
Online package, classroom
Online duration
Approximately 90 minutes
Based on
IEC 62443-4-1 · EU Cyber Resilience Act · NIS2 Directive

Vulnerability management is a systematic process for identifying, analysing, addressing, and communicating security vulnerabilities in software products. It is a core part of secure product development and operations — and it is required by standards such as IEC 62443-4-1 and by regulations such as the EU Cyber Resilience Act and the NIS2 Directive.

This course walks through the full lifecycle, from setting up reporting channels and disclosure policies to triaging findings, assigning severity in the context of your own product, coordinating remediation and disclosure, and closing the loop with root cause analysis and lessons learned.

The material is drawn from the vulnerability management practices Cyberismo consultants use with customers, reworked for learning rather than for day-to-day process use.

Who it is for

Product security and PSIRT teams, development and maintenance teams responsible for fixing vulnerabilities, and quality and compliance specialists who need to evidence a working vulnerability handling process.

What you will learn

Course outline

Each module is divided into short sections, and ends with a knowledge-check quiz so learners can assess their own progress. Every section also works as a standalone reference.

Module 1: Introduction to vulnerability management

What vulnerability management is, the four phases of the lifecycle, the key definitions used throughout the course, and why the underlying standards matter.

Sections

  • Course overview
  • What is vulnerability management?
  • The vulnerability management lifecycle
  • Key definitions
  • Why standards matter
  • Knowledge check

Module 2: Preparations

Everything that has to exist before the first report arrives: reporting and communication channels, handling and disclosure policies, a technology management process, tooling, and operational security controls.

Sections

  • Establish reporting and communication channels
  • Establish vulnerability handling and disclosure policies
  • Establish a technology management process
  • Select tools and applications
  • Establish operational security controls
  • Knowledge check

Module 3: Identifying vulnerabilities

Where vulnerabilities come from — continuous monitoring, SBOM analysis, and external reports — how to handle incoming reports, and how to decide when a finding becomes a formal security issue.

Sections

  • Sources of vulnerabilities
  • Handling incoming reports
  • From findings to security issues
  • Knowledge check

Module 4: Analysing security issues

A structured triage process covering transferability, applicability, severity assessment adjusted to your product’s security context, and mitigation planning.

Sections

  • Analysis steps
  • Knowledge check

Module 5: Addressing and communicating security issues

Implementing fixes, notifying stakeholders, producing reports and advisories, and closing issues — with remediation and communication running in parallel.

Sections

  • Addressing and communication steps
  • Knowledge check

Module 6: Post-release actions

Monitoring remediation, finalising case records, root cause analysis, updating public disclosures, writing lessons learned, and determining case closure.

Sections

  • Monitor remediation
  • Finalise case records
  • Conduct root cause analysis
  • Update public disclosures
  • Write lessons learned
  • Determine case closure
  • Knowledge check

Module 7: Course summary and final assessment

A recap of the full lifecycle and the key takeaways, followed by a final assessment covering the whole course.

Sections

  • What you have learned
  • Key takeaways
  • Final assessment

How to take this course

Online learning package

Self-paced, taken whenever it suits the learner, with a knowledge check at the end of every module. Also available as a SCORM package for your own learning management system.

Classroom training

Delivered on site or remotely by an experienced Cyberismo consultant, with the emphasis of each module tailored to your audience, your products, and your obligations. Priced per engagement.

You can read through the complete content of this course in our online service before deciding whether to purchase it. Access to the preview service is licensed per customer — get in touch and we will set it up for your organisation.

Ask for preview access

Other Cyberismo courses