What are ENISA’s recommendations for vulnerability management?
The NIS2 Directive expects organizations to manage vulnerabilities as an ongoing process, not a one-off exercise. ENISA's Technical Implementation Guidance sets out what this looks like in practice. This article summarizes the main recommendations so you can compare them against how your organization works today.
Treat vulnerability management as part of risk management
ENISA recommends a systematic and continuous approach to vulnerability management, covering identification, assessment, prioritization, remediation, and disclosure. It should not sit on its own. Vulnerabilities should be handled as part of your wider processes for risk management, security testing, patching, change management, and incident response.
How to identify and assess vulnerabilities
Organizations should have processes in place to identify vulnerabilities from trusted sources, including suppliers, service providers, security authorities, and CSIRTs. They should also monitor their own systems for newly disclosed vulnerabilities. This is especially important for third-party and open-source components, where new vulnerabilities can emerge long after deployment.
Once identified, vulnerabilities should be prioritized based on the actual risk they pose to your organization. ENISA is clear that scoring systems like CVSS and EPSS are useful, but severity alone is not enough. Prioritization should also consider the importance of the affected assets, the potential impact and likelihood, relevant threat intelligence, existing controls, and your specific operating environment. In short: take a risk-based approach.
How to plan and track remediation
Every identified risk should be captured in a documented treatment plan. The plan should spell out what needs to be done to reduce or eliminate the risk, who is responsible, and when it needs to happen. Possible responses include fixing the vulnerability, avoiding the risk, sharing it (for example through insurance), or accepting a residual level of risk where that is justified. ENISA is clear that critical vulnerabilities should not be accepted if they can be fixed.
Vulnerability handling should link into your patching and change management processes. When you cannot fix something immediately, the risk should be assessed and managed rather than left open. Document any exceptions and add compensating measures where appropriate. Then keep checking that your treatment plan is actually reducing risk in practice.
Review and disclose
ENISA recommends reviewing your vulnerability and remediation activity regularly. Risk assessments and treatment plans should be reviewed at least once a year, and any time there is a major incident, an operational change, a shift in the threat landscape, or a significant change in vulnerabilities. You should also have a vulnerability disclosure procedure and follow the coordinated disclosure arrangements in your country, including how to work with your national CSIRT.
Summary
Overall, ENISA’s recommendation is to manage vulnerabilities as a continuous, documented, and risk-based process: vulnerabilities should be identified promptly, assessed in their organizational context, prioritized according to risk, remediated or otherwise formally treated, and continuously monitored and reviewed.
Read more
Download and read ENISA’s technical implementation guidance for NIS2 (external link)
Related articles
...