Vulnerability Management’s New Mandate: Remediate What’s Real
嗯,用户让我用中文总结一篇文章,控制在100字以内,而且不需要用“文章内容总结”这样的开头。首先,我需要仔细阅读这篇文章,理解它的主要观点。
文章讲的是漏洞管理正在经历一个转折点,从过去的可见性转向修复能力。过去二十年,组织在扫描、聚合和报告漏洞上投入了很多,但很多安全事件还是源于已知的漏洞。现在,漏洞管理进入了SLA时代,修复速度变得越来越重要。持续扫描已经不够了,还需要证明运营上的跟进。另外,文章提到原始严重性评分并不直接对应实际风险,关键在于漏洞是否可被利用以及在环境中的可达性。AI在这里的作用是减少繁琐的工作,让团队专注于真正影响风险的漏洞。最后,漏洞管理正在从报告功能转向执行纪律。
接下来,我需要把这些要点浓缩到100字以内。重点包括:转折点、从可见性到修复、修复速度的重要性、AI的作用以及从报告到执行的转变。
可能的结构是:首先点明转折点和转变方向,然后提到修复速度和AI的作用,最后总结转变的结果。
现在开始组织语言:
“漏洞管理正经历转折:从可见性转向修复能力。修复速度成为关键指标;AI助力减少繁琐工作;从报告转向执行。”
检查字数:这句话大约45个字左右,可能需要扩展一些内容。
再加一些细节:
“漏洞管理正经历转折:从可见性转向修复能力。修复速度成为关键指标;AI助力减少繁琐工作;从报告转向执行。”
这样可能更全面。
</think>
漏洞管理正经历转折:从可见性转向修复能力。修复速度成为关键指标;AI助力减少繁琐工作;从报告转向执行。
2025-12-19 18:3:26
Author: securityboulevard.com(查看原文)
阅读量:4
收藏
Live from AWS re:Invent, Snir Ben Shimol makes the case that vulnerability management is at an inflection point: visibility is no longer the differentiator—remediation is. Organizations have spent two decades getting better at scanning, aggregating and reporting findings. But the uncomfortable truth is that many of today’s incidents still trace back to vulnerabilities that were already known internally, while the time between disclosure and exploitation keeps shrinking.
That reality is pushing vulnerability management out of its “infinite backlog” era and into an SLA era. It’s not enough to show auditors you can produce a list. Regulators, cyber insurers and enterprise customers increasingly expect commitments around how quickly critical issues are fixed, especially for teams selling SaaS into regulated industries. Continuous scanning is now table stakes; proof of operational follow-through is the new bar.
A core theme is that raw severity scores don’t map cleanly to real-world risk. What matters is exploitability and reachability in your environment—whether compensating controls, segmentation, encryption policies or service configurations effectively neutralize a theoretical issue. Security teams often know this intuitively, but validating it at scale has historically required time-consuming manual analysis and cross-team coordination.
Ben Shimol also surfaces the human cost: vulnerability teams spend their days chasing tickets, fighting backlog gravity, and struggling to define what “winning” looks like beyond “we didn’t get breached today.” The promise of AI in this context isn’t magic automation; it’s reduction of toil—helping teams focus on the smaller set of vulnerabilities that truly move risk, and translating that work into outcomes leadership and auditors can understand.
The bigger takeaway: vulnerability management is evolving from a reporting function into an execution discipline—where prioritization, context, and remediation speed define security maturity.

Alan Shimel
Throughout his career spanning over 25 years in the IT industry, Alan Shimel has been at the forefront of leading technology change. From hosting and infrastructure, to security and now DevOps, Shimel is an industry leader whose opinions and views are widely sought after.
Alan’s entrepreneurial ventures have seen him found or co-found several technology related companies including TriStar Web, StillSecure, The CISO Group, MediaOps, Inc., DevOps.com and the DevOps Institute. He has also helped several companies grow from startup to public entities and beyond. He has held a variety of executive roles around Business and Corporate Development, Sales, Marketing, Product and Strategy.
Alan is also the founder of the Security Bloggers Network, the Security Bloggers Meetups and awards which run at various Security conferences and Security Boulevard.
Most recently Shimel saw the impact that DevOps and related technologies were going to have on the Software Development Lifecycle and the entire IT stack. He founded DevOps.com and then the DevOps Institute. DevOps.com is the leading destination for all things DevOps, as well as the producers of multiple DevOps events called DevOps Connect. DevOps Connect produces DevSecOps and Rugged DevOps tracks and events at leading security conferences such as RSA Conference, InfoSec Europe and InfoSec World. The DevOps Institute is the leading provider of DevOps education, training and certification.
Alan has a BA in Government and Politics from St Johns University, a JD from New York Law School and a lifetime of business experience.
His legal education, long experience in the field, and New York street smarts combine to form a unique personality that is always in demand to appear at conferences and events.
alan has 132 posts and counting.See all posts by alan
文章来源: https://securityboulevard.com/2025/12/vulnerability-managements-new-mandate-remediate-whats-real/
如有侵权请联系:admin#unsafe.sh