Vulnerability Management - Category Vision
## Overview **For the full Vulnerability Management strategy and industry overview, see our [Direction page](https://about.gitlab.com/direction/secure/vulnerability_management/)** At its very simplest, vulnerability management aims to help security professionals efficiently and effectively determine what weaknesses to address in what order. In this mature, relatively crowded space, programs and solutions try to differentiate how broadly beyond this core function they stretch. Starting farther “to the left”, some vendors include their own vulnerability scanners (typically DAST or, more recently, container scanning) to capture new weaknesses before they are introduced into production. Others extend farther “to the right” by providing integration and feedback loops with infrastructure tools such as IPSes, WAFs, and patch management. Ultimately, all of these additional capabilities will fall well short of their potential if not built around a rock-solid system for not just prioritizing the ever-growing pile of vulnerability information the modern security professional must face but one that [reduces the friction and breaks through the silos that prevent quick, efficient remediation](https://www.darkreading.com/endpoint/the-flaw-in-vulnerability-management-its-time-to-get-real/a/d-id/1335465). This understanding that an effective, well-defined, repeatable system for assessing the risk and relative priority of a given vulnerability is crucial to success in the Vulnerability Management space is what will drive our thinking as we mature the category. To help frame our thinking, three key themes will serve as lenses through which to view how we can improve both the breadth and depth of functionality. Each step up in maturity will include initiatives that improve on all three themes, which are: * Flexibility * Efficiency * Situational Awareness ## Flexibility While the security industry has no shortage of standards and best practices, almost every organization is unique in which practices they adopt—and how they chose to implement them. This need for flexibility means there is no one size fits all solution when it comes to security (or even one aspect of security). At the same time, unlimited flexibility can be undesirable as it can lead to long setup times and over-complicated customizations. Our philosophy is to provide a best practices-informed set of defaults with settings-driven configuration where we see most need. This will allow rapid rollout and adoption of vulnerability management. Over time, you can adapt the features and workflows to suite your organization's needs down to the team level. Part of this flexibility will also include top-down configurations. By applying settings at the Instance level, you can easily establish new defaults and internal best practices org-wide. And of course where you chose to allow it, these settings can be overridden at the Group or Project level. Flexibility also means what information we present to the users, when we present it, and in what format. There are multiple roles that will interact with and benefit from various aspects of vulnerability management outside just engineers and security professionals. Serving these roles will encompass everything from dashboard visualizations to reports geared towards non-GitLab users such as CISOs, auditors, and compliance officers. Having the right information in the right context at the right time not only allows for better decision making, it serves as an enabler of the next theme. ## Efficiency The majority of modern security departments are overworked and understaffed. The sheer month-over-month increase in the number of threats, rate of change in environments, accelerating adoption of new technologies, and novel potential attack vectors [makes staying on top of things manually effectively impossible](https://securityboulevard.com/2020/04/the-big-switch-a-lack-of-employable-security-professionals-causes-companies-to-make-the-switch-to-ai/). Security software can help—but only if it cuts down more noise than the new signal it detects. This is why making our vulnerability management process as efficient as possible is essential for successful adoption. We will start by making the tedious and time consuming easier through UX enhancements. Longer-term, we will look to automate more and lean on analytics techniques (including ML) to help users make quicker, smarter decisions. ## Situational Awareness The final theme is perhaps most important of all from a business standpoint. Situational awareness means we will provide the best available information so the user can make a risk-informed decision. This will start by simply adding more depth to the information we show from the existing scanners to help better quantify risk more granularly than a few basic severity levels. Over time, users will have the ability to set custom policies based on configurable definitions of risk tolerance. We will help our customers maintain compliance with industry and internal policies by making it easy to map our Vulnerability Management program to risk management and compliance frameworks. We will also start tying in additional sources of information such as external vulnerability feeds, reports from responsible disclosure programs, and alert data from our own Contain Security applications. Ultimately, we want our customers to have the best possible understanding of their risk posture as it relates to their entire SDLC.
epic