Dealing with false information
False positives– A vulnerability is identified that doesn’t really exist
* This is different than a low-severity vulnerability– It’s real, but it may not be your highest priority
* False negatives– A vulnerability exists, but you didn’t detect it
* Update to the latest signatures– If you don’t know about it, you can’t see it
* Work with the vulnerability detection manufacturer– They may need to update their signatures for your
environment
Prioritizing vulnerabilities
CVSS
CVE
Vulnerability classification
Exposure factor
Environmental variables
Industry/organizational impact
Risk tolerance