Week 8
Design a Continuous Vulnerability Scanning Program
Client Background
A mid-size company runs vulnerability scans inconsistently and has no formal program. Design a continuous vulnerability management program covering scan scope, cadence, and ownership.
Business Environment
Cascade Logistics runs a 1,200-device estate mixing cloud workloads (AWS + Azure), on-prem warehouses, and hundreds of IoT/OT sensors on the warehouse floor. A three-person security team runs manual scans quarterly with no unified asset inventory or prioritization.
Security Incident
No breach yet; the engagement is proactive program design. The driver was a recent ransomware incident at a competitor traced to a 9-month-old unpatched CVE, escalating the board's demand for continuous, prioritized coverage rather than quarterly snapshots before a SOC 2 Type II audit.
Scope
Enterprise-wide vulnerability scanning program design covering all in-scope asset classes.
Objectives
- Define scan scope across internal and external assets
- Establish scan cadence and authenticated scanning practices
- Define severity-based SLAs for remediation
- Assign ownership and escalation paths
Required Deliverables