<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Efrenz</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Efrenz"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Efrenz"/>
		<updated>2026-05-30T18:23:12Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:OWASP_Vulnerability_Management_Guide&amp;diff=250938</id>
		<title>Talk:OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:OWASP_Vulnerability_Management_Guide&amp;diff=250938"/>
				<updated>2019-05-02T04:54:56Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: /* 1 Detection Cycle */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[https://github.com/lizfrenz/owasp-vuln-mngmnt Please leave a comment using GitHub. ]&lt;br /&gt;
&lt;br /&gt;
= OWASP Vulnerability Management Guide v.1 =&lt;br /&gt;
&amp;lt;small&amp;gt;(&amp;quot;bare bones&amp;quot; list) &amp;lt;br&amp;gt;&amp;lt;/small&amp;gt;&lt;br /&gt;
=== 1 Detection Cycle ===&lt;br /&gt;
&lt;br /&gt;
1.1	Define/Refine scope &amp;lt;br&amp;gt;&lt;br /&gt;
1.1.1	Know the enterprise risks&amp;lt;br&amp;gt;&lt;br /&gt;
1.1.2	Know operational constraints&amp;lt;br&amp;gt; &lt;br /&gt;
1.1.3	Know technical constraints&amp;lt;br&amp;gt;&lt;br /&gt;
1.1.4	Distinguish primary assets vs. secondary&amp;lt;br&amp;gt; &lt;br /&gt;
1.1.5	Embed vulnerability management processes into the enterprise processes&amp;lt;br&amp;gt;&lt;br /&gt;
1.1.6	Build managerial support&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1.2	Optimize Tools&amp;lt;br&amp;gt; &lt;br /&gt;
1.2.1	Determine the type of your test/scan&amp;lt;br&amp;gt;&lt;br /&gt;
1.2.2	Determine the frequency of your tests/scans&amp;lt;br&amp;gt;&lt;br /&gt;
1.2.3	Ensure the latest vulnerability feed&amp;lt;br&amp;gt; &lt;br /&gt;
1.2.4	Check if vulnerability exceptions exist&amp;lt;br&amp;gt;&lt;br /&gt;
1.2.5	Test your tool for integrity&amp;lt;br&amp;gt;&lt;br /&gt;
1.2.6	Adjust your tools settings, preferences, templates&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1.3	Run Tests&amp;lt;br&amp;gt;&lt;br /&gt;
1.3.1	Scan public IP addresses&amp;lt;br&amp;gt;&lt;br /&gt;
1.3.2	Scan private subnets&amp;lt;br&amp;gt; &lt;br /&gt;
1.3.3	Scan/test web applications&amp;lt;br&amp;gt;&lt;br /&gt;
1.3.4	Scan/test mobile apps&amp;lt;br&amp;gt;&lt;br /&gt;
1.3.5	Test Users (phishing, social engineering training)&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1.4	Confirm Findings&amp;lt;br&amp;gt;&lt;br /&gt;
1.4.1	Check if your test results have valuable data&amp;lt;br&amp;gt;&lt;br /&gt;
1.4.2	Interpret and reconcile system/device fingerprinting across your tests&amp;lt;br&amp;gt; &lt;br /&gt;
1.4.3	Determine that running services  are what they are supposed to be&amp;lt;br&amp;gt;&lt;br /&gt;
1.4.4	Find something that falls out of the pattern and investigate why&amp;lt;br&amp;gt;&lt;br /&gt;
1.4.5	Randomly select vulnerabilities and confirm them with a different tool or manually&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== 2 Reporting Cycle&amp;lt;br&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
2.1	Create Assets Groups&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.1	Determine functional asset groups&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.2	Determine asset groups by type of environment&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.3	Determine asset groups by type of system&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.4	Determine groups by CVE numbering authority or underlying technology&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.5	Determine groups by type of vulnerability&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2.2	Define/Refine Metrics&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.1	Determine amount and percentage of vulnerable assets&amp;lt;br&amp;gt; &lt;br /&gt;
2.2.2	Determine amount and percentage of vulnerable assets by severity and CVSS&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3	Determine amount and percentage of new vulnerabilities:&amp;lt;br&amp;gt; &lt;br /&gt;
2.2.3.1	-by severity&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.2	-by functional groups&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.3	-by type of environment&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.4	-by type of system&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.5	-by CVE numbering authority&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.6	-by type of vulnerability&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4	Compare and analyze aging data by severity of vulnerabilities and their share:&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.1	-enterprise wide&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.2	-among all other vulnerable assets&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.3	-by functional groups&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.4	-by type of environment&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.5	-by type of system&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.6	-by CVE numbering authority&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.7	-by type of vulnerability&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.5	Draw out the trends by count and percentage utilizing KPI that matter to your enterprise risks and &lt;br /&gt;
compliance&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.6	Determine exploitability of vulnerable assets by severity; specify count, percentage, decrease or &lt;br /&gt;
increase&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2.3	Log Confirmed Findings&amp;lt;br&amp;gt;&lt;br /&gt;
2.3.1	Use your organization?s ticketing system&amp;lt;br&amp;gt;&lt;br /&gt;
2.3.2	Provide a summary of the issue&amp;lt;br&amp;gt;&lt;br /&gt;
2.3.3	Provide tools? based output&amp;lt;br&amp;gt; &lt;br /&gt;
2.3.4	Notify/assign the issue/ticket to the responsible teams or individuals&amp;lt;br&amp;gt;&lt;br /&gt;
2.3.5	Make sure that your manager/CISO is aware&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2.4	Create Reports&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.1	Maintain a consistent frequency of reporting and use it to track the changes&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.2	Aggregate and process collected data&amp;lt;br&amp;gt; &lt;br /&gt;
2.4.3	Using CVSS, apply unique environmental traits to your vulnerability analysis&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.4	State vulnerability trends&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.5	Hypothesize about these trends in one sentence&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.6	In one paragraph, add your recommendations&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.7	Apply data sensitivity classification to your report&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.8	Make a shorter version (1-2 pages) of your report&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.9	Submit both versions of the report to your manager/CISO&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.10	Create and maintain your own vulnerability management repository for internal or external audit&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.11	Be able to explain the details of the vulnerability detection and reporting process&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== 3	Remediation Cycle&amp;lt;br&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
3.1	Prioritize Vulnerabilities&amp;lt;br&amp;gt;&lt;br /&gt;
3.1.1	Use your reports&amp;lt;br&amp;gt;&lt;br /&gt;
3.1.2	Use your trend analysis&amp;lt;br&amp;gt; &lt;br /&gt;
3.1.3	Use information from additional sources&amp;lt;br&amp;gt;&lt;br /&gt;
3.1.4	Apply other environmental factors&amp;lt;br&amp;gt;&lt;br /&gt;
3.1.5	Communicate to responsible and accountable stakeholders&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3.2	Patching&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.1	Find the stakeholders responsible for patching&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.2	Communicate your findings via the tools and processes they use&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.3	Establish a frequency and scope of patching&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.4	Establish a group of assets dedicated for patch testing&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.5	Report back your test results to the responsible stakeholders&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.6	Use the ticketing system or change management system to resolve the patch management issues&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.7	Always assign these tickets&amp;lt;br&amp;gt; &lt;br /&gt;
3.2.8	Include responsible, accountable, stakeholders, and who needs to be informed on unresolved &lt;br /&gt;
issues&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.9	Use the frequency of your reporting cycle to follow up on open issues&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3.3	Investigate False Positives (FP)&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.1	Ensure integrity of a claim&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.2	Construct a repeatable business process&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.3	Document all FP submissions&amp;lt;br&amp;gt; &lt;br /&gt;
3.3.4	Find SMEs who can agree or argue a false positive claim&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.5	Set a time frame at which FP should be reevaluated&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.6	Document each FP and store it in an auditable repository&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.7	Create an appropriate policy&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.8	Communicate this policy to all employees&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3.4	Control Vulnerability Exception Process&amp;lt;br&amp;gt; &lt;br /&gt;
3.4.1	Find an executive authority to sign off on a cyber security exception&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.2	Establish ground rules for vulnerability exceptions&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.3	Establish periodic reviews of  vulnerability exceptions&amp;lt;br&amp;gt; &lt;br /&gt;
3.4.4	Establish acceptable compensating controls&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.5	Document each exception and store it in the company?s audit system&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.6	Create an appropriate policy&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.7	Communicate this policy to all employees&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.8	Have vulnerability exception solicitors asking the executive authority for an approval every time&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=250925</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=250925"/>
				<updated>2019-05-02T03:17:49Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Vulnerability Management Guide==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Vulnerability management is one of the most effective means of controlling cybersecurity risk.  Yet, as indicated by the wave of massive data breaches and ransomware attacks, all too often organizations are compromised over missing patches and misconfigurations.  Vulnerability management seeks to help organizations identify such weaknesses in its security posture so that they can be rectified before they are exploited by attackers.  The OWASP Vulnerability Management Guide project seeks to establish guidance on the best practices that organizations can use establish a vulnerability management program within their organization.  The guide provides in depth coverage of the full vulnerability management lifecycle including the preparation phase, the vulnerability identification/scanning phase, the reporting phase, and remediation phase.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The vulnerability management guide should help to breakdown vulnerability management process into a manageable repeatable cycles tailored to your organizational needs. Target audience: information security practitioners of all levels, IT professionals, and business leaders.&lt;br /&gt;
&lt;br /&gt;
[[Talk:OWASP_Vulnerability_Management_Guide#OWASP_Vulnerability_Management_Guide_v.1|Vulnerability Management Cycle]]:&lt;br /&gt;
* DETECTION&lt;br /&gt;
* REPORTING&lt;br /&gt;
* REMEDIATION&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Vulnerability Management project is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
As of '''September 2018''', the highest priorities for the next 8 months are: &lt;br /&gt;
* a “bare bones” list (done!); &lt;br /&gt;
* a logical diagram (coming soon); &lt;br /&gt;
* a Power Point presentation (coming soon); &lt;br /&gt;
* a DIY guide with notes that reference controls, useful sources, and examples (coming 2019);&lt;br /&gt;
* a DIY guide with the notes, examples, and illustrations (coming 2020).&lt;br /&gt;
&lt;br /&gt;
Subsequent releases will be unscheduled: &lt;br /&gt;
* Bug Fix&lt;br /&gt;
* Internationalization&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Get Involved by:&lt;br /&gt;
* '''Promoting'''. Please spread the word! &lt;br /&gt;
* '''Adopting'''. The best contribution is your adoption! &lt;br /&gt;
* '''Collaborating'''. Please specify in comments how would you like to contribute on [https://github.com/lizfrenz/owasp-vuln-mngmnt GitHub]. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Efrenz Elizabeth Frenz]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Donate to OWASP ==&lt;br /&gt;
&amp;lt;div class=&amp;quot;center&amp;quot; style=&amp;quot;width: auto; margin-left: auto; margin-right: auto;&amp;quot;&amp;gt;{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Other (Website Donation) }}&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243658</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243658"/>
				<updated>2018-09-24T04:45:09Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Vulnerability Management Guide==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Vulnerability management is one of the most effective means of controlling cybersecurity risk.  Yet, as indicated by the wave of massive data breaches and ransomware attacks, all too often organizations are compromised over missing patches and misconfigurations.  Vulnerability management seeks to help organizations identify such weaknesses in its security posture so that they can be rectified before they are exploited by attackers.  The OWASP Vulnerability Management Guide project seeks to establish guidance on the best practices that organizations can use establish a vulnerability management program within their organization.  The guide provides in depth coverage of the full vulnerability management lifecycle including the preparation phase, the vulnerability identification/scanning phase, the reporting phase, and remediation phase.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The vulnerability management guide should help to breakdown vulnerability management process into a manageable repeatable cycles tailored to your organizational needs. Target audience: information security practitioners of all levels, IT professionals, and business leaders.&lt;br /&gt;
&lt;br /&gt;
[[Talk:OWASP_Vulnerability_Management_Guide#OWASP_Vulnerability_Management_Guide_v.1|Vulnerability Management Cycle]]:&lt;br /&gt;
* DETECTION&lt;br /&gt;
* REPORTING&lt;br /&gt;
* REMEDIATION&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Vulnerability Management project is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
As of '''September 2018''', the highest priorities for the next 8 months are: &lt;br /&gt;
* a “bare bones” list (done!); &lt;br /&gt;
* a logical diagram (coming Q4 2018); &lt;br /&gt;
* a Power Point presentation (coming Q4 2018); &lt;br /&gt;
* a DIY guide with notes that reference controls, useful sources, and examples (coming Q1 2019);&lt;br /&gt;
* a DIY guide with the notes, examples, and illustrations (coming Q1 2019).&lt;br /&gt;
&lt;br /&gt;
Subsequent releases will be unscheduled: &lt;br /&gt;
* Bug Fix&lt;br /&gt;
* Internationalization&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Get Involved by:&lt;br /&gt;
* '''Promoting'''. Please spread the word! &lt;br /&gt;
* '''Adopting'''. The best contribution is your adoption! &lt;br /&gt;
* '''Collaborating'''. Please specify in comments how would you like to contribute on [https://github.com/lizfrenz/owasp-vuln-mngmnt GitHub]. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Efrenz Elizabeth Frenz]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Donate to OWASP ==&lt;br /&gt;
&amp;lt;div class=&amp;quot;center&amp;quot; style=&amp;quot;width: auto; margin-left: auto; margin-right: auto;&amp;quot;&amp;gt;{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Other (Website Donation) }}&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243657</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243657"/>
				<updated>2018-09-24T04:42:49Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Vulnerability Management Guide==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Vulnerability management is one of the most effective means of controlling cybersecurity risk.  Yet, as indicated by the wave of massive data breaches and ransomware attacks, all too often organizations are compromised over missing patches and misconfigurations.  Vulnerability management seeks to help organizations identify such weaknesses in its security posture so that they can be rectified before they are exploited by attackers.  The OWASP Vulnerability Management Guide project seeks to establish guidance on the best practices that organizations can use establish a vulnerability management program within their organization.  The guide provides in depth coverage of the full vulnerability management lifecycle including the preparation phase, the vulnerability identification/scanning phase, the reporting phase, and remediation phase.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The vulnerability management guide should help to breakdown vulnerability management process into a manageable repeatable cycles tailored to your organizational needs. Target audience: information security practitioners of all levels, IT professionals, and business leaders.&lt;br /&gt;
&lt;br /&gt;
[[Talk:OWASP_Vulnerability_Management_Guide#OWASP_Vulnerability_Management_Guide_v.1|Vulnerability Management Cycle]]:&lt;br /&gt;
* DETECTION&lt;br /&gt;
* REPORTING&lt;br /&gt;
* REMEDIATION&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Vulnerability Management project is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
As of '''September 2018''', the highest priorities for the next 8 months are: &lt;br /&gt;
* a “bare bones” list (done!); &lt;br /&gt;
* a logical diagram (coming Q4 2018); &lt;br /&gt;
* a Power Point presentation (coming Q4 2018); &lt;br /&gt;
* a DIY guide with notes that reference controls, useful sources, and examples (coming Q1 2019);&lt;br /&gt;
* a DIY guide with the notes, examples, and illustrations (coming Q1 2019).&lt;br /&gt;
&lt;br /&gt;
Subsequent releases will be unscheduled: &lt;br /&gt;
* Bug Fix&lt;br /&gt;
* Internationalization&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Get Involved by:&lt;br /&gt;
* '''Promoting'''. Please spread the word! &lt;br /&gt;
* '''Adopting'''. The best contribution is your adoption! &lt;br /&gt;
* '''Collaborating'''. Please specify in comments how would you like to contribute on [https://github.com/lizfrenz/owasp-vuln-mngmnt GitHub]. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Efrenz Elizabeth Frenz]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243656</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243656"/>
				<updated>2018-09-24T04:40:37Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Vulnerability Management Guide==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Vulnerability management is one of the most effective means of controlling cybersecurity risk.  Yet, as indicated by the wave of massive data breaches and ransomware attacks, all too often organizations are compromised over missing patches and misconfigurations.  Vulnerability management seeks to help organizations identify such weaknesses in its security posture so that they can be rectified before they are exploited by attackers.  The OWASP Vulnerability Management Guide project seeks to establish guidance on the best practices that organizations can use establish a vulnerability management program within their organization.  The guide provides in depth coverage of the full vulnerability management lifecycle including the preparation phase, the vulnerability identification/scanning phase, the reporting phase, and remediation phase.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The vulnerability management guide should help to breakdown vulnerability management process into a manageable repeatable cycles tailored to your organizational needs. Target audience: information security practitioners of all levels, IT professionals, and business leaders.&lt;br /&gt;
&lt;br /&gt;
Vulnerability Management Cycle:&lt;br /&gt;
* DETECTION&lt;br /&gt;
* REPORTING&lt;br /&gt;
* REMEDIATION&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Vulnerability Management project is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
As of '''September 2018''', the highest priorities for the next 8 months are: &lt;br /&gt;
* a “bare bones” list (done!); &lt;br /&gt;
* a logical diagram (coming Q4 2018); &lt;br /&gt;
* a Power Point presentation (coming Q4 2018); &lt;br /&gt;
* a DIY guide with notes that reference controls, useful sources, and examples (coming Q1 2019);&lt;br /&gt;
* a DIY guide with the notes, examples, and illustrations (coming Q1 2019).&lt;br /&gt;
&lt;br /&gt;
Subsequent releases will be unscheduled: &lt;br /&gt;
* Bug Fix&lt;br /&gt;
* Internationalization&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Get Involved by:&lt;br /&gt;
* '''Promoting'''. Please spread the word! &lt;br /&gt;
* '''Adopting'''. The best contribution is your adoption! &lt;br /&gt;
* '''Collaborating'''. Please specify in comments how would you like to contribute on [https://github.com/lizfrenz/owasp-vuln-mngmnt GitHub]. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Efrenz Elizabeth Frenz]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243655</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243655"/>
				<updated>2018-09-24T04:34:14Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Vulnerability Management Guide==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Vulnerability management is one of the most effective means of controlling cybersecurity risk.  Yet, as indicated by the wave of massive data breaches and ransomware attacks, all too often organizations are compromised over missing patches and misconfigurations.  Vulnerability management seeks to help organizations identify such weaknesses in its security posture so that they can be rectified before they are exploited by attackers.  The OWASP Vulnerability Management Guide project seeks to establish guidance on the best practices that organizations can use establish a vulnerability management program within their organization.  The guide provides in depth coverage of the full vulnerability management lifecycle including the preparation phase, the vulnerability identification/scanning phase, the reporting phase, and remediation phase.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The vulnerability management guide should help to breakdown vulnerability management process into a manageable repeatable cycles tailored to your organizational needs. Target audience: information security practitioners of all levels, IT professionals, and business leaders.&lt;br /&gt;
&lt;br /&gt;
Vulnerability Management Cycle:&lt;br /&gt;
* DETECTION&lt;br /&gt;
* REPORTING&lt;br /&gt;
* REMEDIATION&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Vulnerability Management project is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
As of '''September 2018''', the highest priorities for the next 8 months are: &lt;br /&gt;
* a “bare bones” list (done!); &lt;br /&gt;
* a logical diagram (coming Q4 2018); &lt;br /&gt;
* a Power Point presentation (coming Q4 2018); &lt;br /&gt;
* a DIY guide with notes that reference controls, useful sources, and examples (coming Q1 2019);&lt;br /&gt;
* a DIY guide with the notes, examples, and illustrations (coming Q1 2019).&lt;br /&gt;
&lt;br /&gt;
Subsequent releases will be unscheduled: &lt;br /&gt;
* Bug Fix&lt;br /&gt;
* Internationalization&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Get Involved by:&lt;br /&gt;
* '''Promoting'''. Please spread the word! &lt;br /&gt;
* '''Adopting'''. The best contribution is your adoption! &lt;br /&gt;
* '''Collaborating'''. Please leave a comment using Discussion tab link to GitHub. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Efrenz Elizabeth Frenz]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243654</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243654"/>
				<updated>2018-09-24T04:32:55Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Vulnerability Management Guide==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Vulnerability management is one of the most effective means of controlling cybersecurity risk.  Yet, as indicated by the wave of massive data breaches and ransomware attacks, all too often organizations are compromised over missing patches and misconfigurations.  Vulnerability management seeks to help organizations identify such weaknesses in its security posture so that they can be rectified before they are exploited by attackers.  The OWASP Vulnerability Management Guide project seeks to establish guidance on the best practices that organizations can use establish a vulnerability management program within their organization.  The guide provides in depth coverage of the full vulnerability management lifecycle including the preparation phase, the vulnerability identification/scanning phase, the reporting phase, and remediation phase.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The vulnerability management guide should help to breakdown vulnerability management process into a manageable repeatable cycles tailored to your organizational needs. Target audience: information security practitioners of all levels, IT professionals, and business leaders.&lt;br /&gt;
&lt;br /&gt;
Vulnerability Management Cycle:&lt;br /&gt;
* DETECTION&lt;br /&gt;
* REPORTING&lt;br /&gt;
* REMEDIATION&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Vulnerability Management project is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
As of '''September 2018''', the highest priorities for the next 8 months are: &lt;br /&gt;
* a “bare bones” list (coming soon); &lt;br /&gt;
* a logical diagram (coming Q4 2018); &lt;br /&gt;
* a Power Point presentation (coming Q4 2018); &lt;br /&gt;
* a DIY guide with notes that reference controls, useful sources, and examples (coming Q1 2019);&lt;br /&gt;
* a DIY guide with the notes, examples, and illustrations (coming Q1 2019).&lt;br /&gt;
&lt;br /&gt;
Subsequent releases will be unscheduled: &lt;br /&gt;
* Bug Fix&lt;br /&gt;
* Internationalization&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Get Involved by:&lt;br /&gt;
* '''Promoting'''. Please spread the word! &lt;br /&gt;
* '''Adopting'''. The best contribution is your adoption! &lt;br /&gt;
* '''Collaborating'''. Please leave a comment using Discussion tab link to GitHub. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Efrenz Elizabeth Frenz]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:OWASP_Vulnerability_Management_Guide&amp;diff=243653</id>
		<title>Talk:OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:OWASP_Vulnerability_Management_Guide&amp;diff=243653"/>
				<updated>2018-09-24T04:23:22Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[https://github.com/lizfrenz/owasp-vuln-mngmnt Please leave a comment using GitHub. ]&lt;br /&gt;
&lt;br /&gt;
= OWASP Vulnerability Management Guide v.1 =&lt;br /&gt;
&amp;lt;small&amp;gt;(&amp;quot;bare bones&amp;quot; list) &amp;lt;br&amp;gt;&amp;lt;/small&amp;gt;&lt;br /&gt;
=== 1 Detection Cycle ===&lt;br /&gt;
&lt;br /&gt;
1.1	Define/Refine scope &amp;lt;br&amp;gt;&lt;br /&gt;
1.1.1	Know the enterprise risks&amp;lt;br&amp;gt;&lt;br /&gt;
1.1.2	Know operational constraints&amp;lt;br&amp;gt; &lt;br /&gt;
1.1.3	Know technical constraints&amp;lt;br&amp;gt;&lt;br /&gt;
1.1.4	Distinguish primary assets vs. secondary&amp;lt;br&amp;gt; &lt;br /&gt;
1.1.5	Embed vulnerability management processes into the enterprise processes&amp;lt;br&amp;gt;&lt;br /&gt;
1.1.6	Build managerial support&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1.2	Optimize Tools&amp;lt;br&amp;gt; &lt;br /&gt;
1.2.1	Determine the type of your test/scan&amp;lt;br&amp;gt;&lt;br /&gt;
1.2.2	Determine the frequency of your tests/scans&amp;lt;br&amp;gt;&lt;br /&gt;
1.2.3	Ensure the latest vulnerability feed&amp;lt;br&amp;gt; &lt;br /&gt;
1.2.4	Check if vulnerability exceptions exist&amp;lt;br&amp;gt;&lt;br /&gt;
1.2.5	Test your tool for integrity&amp;lt;br&amp;gt;&lt;br /&gt;
1.2.6	Adjust your tools settings, preferences, templates&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1.3	Confirm Findings&amp;lt;br&amp;gt;&lt;br /&gt;
1.3.1	Check if your test results have valuable data&amp;lt;br&amp;gt;&lt;br /&gt;
1.3.2	Interpret and reconcile system/device fingerprinting across your tests&amp;lt;br&amp;gt; &lt;br /&gt;
1.3.3	Determine that running services  are what they are supposed to be&amp;lt;br&amp;gt;&lt;br /&gt;
1.3.4	Find something that falls out of the pattern and investigate why&amp;lt;br&amp;gt;&lt;br /&gt;
1.3.5	Randomly select vulnerabilities and confirm them with a different tool or manually&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== 2 Reporting Cycle&amp;lt;br&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
2.1	Create Assets Groups&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.1	Determine functional asset groups&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.2	Determine asset groups by type of environment&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.3	Determine asset groups by type of system&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.4	Determine groups by CVE numbering authority or underlying technology&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.5	Determine groups by type of vulnerability&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2.2	Define/Refine Metrics&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.1	Determine amount and percentage of vulnerable assets&amp;lt;br&amp;gt; &lt;br /&gt;
2.2.2	Determine amount and percentage of vulnerable assets by severity and CVSS&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3	Determine amount and percentage of new vulnerabilities:&amp;lt;br&amp;gt; &lt;br /&gt;
2.2.3.1	-by severity&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.2	-by functional groups&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.3	-by type of environment&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.4	-by type of system&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.5	-by CVE numbering authority&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.6	-by type of vulnerability&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4	Compare and analyze aging data by severity of vulnerabilities and their share:&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.1	-enterprise wide&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.2	-among all other vulnerable assets&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.3	-by functional groups&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.4	-by type of environment&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.5	-by type of system&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.6	-by CVE numbering authority&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.7	-by type of vulnerability&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.5	Draw out the trends by count and percentage utilizing KPI that matter to your enterprise risks and &lt;br /&gt;
compliance&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.6	Determine exploitability of vulnerable assets by severity; specify count, percentage, decrease or &lt;br /&gt;
increase&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2.3	Log Confirmed Findings&amp;lt;br&amp;gt;&lt;br /&gt;
2.3.1	Use your organization?s ticketing system&amp;lt;br&amp;gt;&lt;br /&gt;
2.3.2	Provide a summary of the issue&amp;lt;br&amp;gt;&lt;br /&gt;
2.3.3	Provide tools? based output&amp;lt;br&amp;gt; &lt;br /&gt;
2.3.4	Notify/assign the issue/ticket to the responsible teams or individuals&amp;lt;br&amp;gt;&lt;br /&gt;
2.3.5	Make sure that your manager/CISO is aware&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2.4	Create Reports&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.1	Maintain a consistent frequency of reporting and use it to track the changes&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.2	Aggregate and process collected data&amp;lt;br&amp;gt; &lt;br /&gt;
2.4.3	Using CVSS, apply unique environmental traits to your vulnerability analysis&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.4	State vulnerability trends&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.5	Hypothesize about these trends in one sentence&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.6	In one paragraph, add your recommendations&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.7	Apply data sensitivity classification to your report&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.8	Make a shorter version (1-2 pages) of your report&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.9	Submit both versions of the report to your manager/CISO&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.10	Create and maintain your own vulnerability management repository for internal or external audit&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.11	Be able to explain the details of the vulnerability detection and reporting process&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== 3	Remediation Cycle&amp;lt;br&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
3.1	Prioritize Vulnerabilities&amp;lt;br&amp;gt;&lt;br /&gt;
3.1.1	Use your reports&amp;lt;br&amp;gt;&lt;br /&gt;
3.1.2	Use your trend analysis&amp;lt;br&amp;gt; &lt;br /&gt;
3.1.3	Use information from additional sources&amp;lt;br&amp;gt;&lt;br /&gt;
3.1.4	Apply other environmental factors&amp;lt;br&amp;gt;&lt;br /&gt;
3.1.5	Communicate to responsible and accountable stakeholders&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3.2	Patching&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.1	Find the stakeholders responsible for patching&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.2	Communicate your findings via the tools and processes they use&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.3	Establish a frequency and scope of patching&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.4	Establish a group of assets dedicated for patch testing&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.5	Report back your test results to the responsible stakeholders&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.6	Use the ticketing system or change management system to resolve the patch management issues&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.7	Always assign these tickets&amp;lt;br&amp;gt; &lt;br /&gt;
3.2.8	Include responsible, accountable, stakeholders, and who needs to be informed on unresolved &lt;br /&gt;
issues&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.9	Use the frequency of your reporting cycle to follow up on open issues&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3.3	Investigate False Positives (FP)&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.1	Ensure integrity of a claim&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.2	Construct a repeatable business process&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.3	Document all FP submissions&amp;lt;br&amp;gt; &lt;br /&gt;
3.3.4	Find SMEs who can agree or argue a false positive claim&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.5	Set a time frame at which FP should be reevaluated&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.6	Document each FP and store it in an auditable repository&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.7	Create an appropriate policy&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.8	Communicate this policy to all employees&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3.4	Control Vulnerability Exception Process&amp;lt;br&amp;gt; &lt;br /&gt;
3.4.1	Find an executive authority to sign off on a cyber security exception&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.2	Establish ground rules for vulnerability exceptions&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.3	Establish periodic reviews of  vulnerability exceptions&amp;lt;br&amp;gt; &lt;br /&gt;
3.4.4	Establish acceptable compensating controls&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.5	Document each exception and store it in the company?s audit system&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.6	Create an appropriate policy&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.7	Communicate this policy to all employees&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.8	Have vulnerability exception solicitors asking the executive authority for an approval every time&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:OWASP_Vulnerability_Management_Guide&amp;diff=243652</id>
		<title>Talk:OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:OWASP_Vulnerability_Management_Guide&amp;diff=243652"/>
				<updated>2018-09-24T04:21:47Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[https://github.com/lizfrenz/owasp-vuln-mngmnt Please leave a comment using GitHub. ]&lt;br /&gt;
&lt;br /&gt;
== OWASP Vulnerability Management Guide v.1 ==&lt;br /&gt;
&amp;lt;small&amp;gt;(&amp;quot;bare bones&amp;quot; list) &amp;lt;br&amp;gt;&amp;lt;/small&amp;gt;&lt;br /&gt;
=== 1 Detection Cycle ===&lt;br /&gt;
&lt;br /&gt;
1.1	Define/Refine scope &amp;lt;br&amp;gt;&lt;br /&gt;
1.1.1	Know the enterprise risks&amp;lt;br&amp;gt;&lt;br /&gt;
1.1.2	Know operational constraints&amp;lt;br&amp;gt; &lt;br /&gt;
1.1.3	Know technical constraints&amp;lt;br&amp;gt;&lt;br /&gt;
1.1.4	Distinguish primary assets vs. secondary&amp;lt;br&amp;gt; &lt;br /&gt;
1.1.5	Embed vulnerability management processes into the enterprise processes&amp;lt;br&amp;gt;&lt;br /&gt;
1.1.6	Build managerial support&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1.2	Optimize Tools&amp;lt;br&amp;gt; &lt;br /&gt;
1.2.1	Determine the type of your test/scan&amp;lt;br&amp;gt;&lt;br /&gt;
1.2.2	Determine the frequency of your tests/scans&amp;lt;br&amp;gt;&lt;br /&gt;
1.2.3	Ensure the latest vulnerability feed&amp;lt;br&amp;gt; &lt;br /&gt;
1.2.4	Check if vulnerability exceptions exist&amp;lt;br&amp;gt;&lt;br /&gt;
1.2.5	Test your tool for integrity&amp;lt;br&amp;gt;&lt;br /&gt;
1.2.6	Adjust your tools settings, preferences, templates&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1.3	Confirm Findings&amp;lt;br&amp;gt;&lt;br /&gt;
1.3.1	Check if your test results have valuable data&amp;lt;br&amp;gt;&lt;br /&gt;
1.3.2	Interpret and reconcile system/device fingerprinting across your tests&amp;lt;br&amp;gt; &lt;br /&gt;
1.3.3	Determine that running services  are what they are supposed to be&amp;lt;br&amp;gt;&lt;br /&gt;
1.3.4	Find something that falls out of the pattern and investigate why&amp;lt;br&amp;gt;&lt;br /&gt;
1.3.5	Randomly select vulnerabilities and confirm them with a different tool or manually&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== 2 Reporting Cycle&amp;lt;br&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
2.1	Create Assets Groups&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.1	Determine functional asset groups&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.2	Determine asset groups by type of environment&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.3	Determine asset groups by type of system&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.4	Determine groups by CVE numbering authority or underlying technology&amp;lt;br&amp;gt;&lt;br /&gt;
2.1.5	Determine groups by type of vulnerability&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2.2	Define/Refine Metrics&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.1	Determine amount and percentage of vulnerable assets&amp;lt;br&amp;gt; &lt;br /&gt;
2.2.2	Determine amount and percentage of vulnerable assets by severity and CVSS&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3	Determine amount and percentage of new vulnerabilities:&amp;lt;br&amp;gt; &lt;br /&gt;
2.2.3.1	-by severity&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.2	-by functional groups&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.3	-by type of environment&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.4	-by type of system&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.5	-by CVE numbering authority&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.3.6	-by type of vulnerability&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4	Compare and analyze aging data by severity of vulnerabilities and their share:&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.1	-enterprise wide&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.2	-among all other vulnerable assets&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.3	-by functional groups&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.4	-by type of environment&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.5	-by type of system&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.6	-by CVE numbering authority&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.4.7	-by type of vulnerability&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.5	Draw out the trends by count and percentage utilizing KPI that matter to your enterprise risks and &lt;br /&gt;
compliance&amp;lt;br&amp;gt;&lt;br /&gt;
2.2.6	Determine exploitability of vulnerable assets by severity; specify count, percentage, decrease or &lt;br /&gt;
increase&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2.3	Log Confirmed Findings&amp;lt;br&amp;gt;&lt;br /&gt;
2.3.1	Use your organization?s ticketing system&amp;lt;br&amp;gt;&lt;br /&gt;
2.3.2	Provide a summary of the issue&amp;lt;br&amp;gt;&lt;br /&gt;
2.3.3	Provide tools? based output&amp;lt;br&amp;gt; &lt;br /&gt;
2.3.4	Notify/assign the issue/ticket to the responsible teams or individuals&amp;lt;br&amp;gt;&lt;br /&gt;
2.3.5	Make sure that your manager/CISO is aware&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
2.4	Create Reports&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.1	Maintain a consistent frequency of reporting and use it to track the changes&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.2	Aggregate and process collected data&amp;lt;br&amp;gt; &lt;br /&gt;
2.4.3	Using CVSS, apply unique environmental traits to your vulnerability analysis&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.4	State vulnerability trends&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.5	Hypothesize about these trends in one sentence&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.6	In one paragraph, add your recommendations&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.7	Apply data sensitivity classification to your report&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.8	Make a shorter version (1-2 pages) of your report&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.9	Submit both versions of the report to your manager/CISO&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.10	Create and maintain your own vulnerability management repository for internal or external audit&amp;lt;br&amp;gt;&lt;br /&gt;
2.4.11	Be able to explain the details of the vulnerability detection and reporting process&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== 3	Remediation Cycle&amp;lt;br&amp;gt; ===&lt;br /&gt;
&lt;br /&gt;
3.1	Prioritize Vulnerabilities&amp;lt;br&amp;gt;&lt;br /&gt;
3.1.1	Use your reports&amp;lt;br&amp;gt;&lt;br /&gt;
3.1.2	Use your trend analysis&amp;lt;br&amp;gt; &lt;br /&gt;
3.1.3	Use information from additional sources&amp;lt;br&amp;gt;&lt;br /&gt;
3.1.4	Apply other environmental factors&amp;lt;br&amp;gt;&lt;br /&gt;
3.1.5	Communicate to responsible and accountable stakeholders&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3.2	Patching&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.1	Find the stakeholders responsible for patching&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.2	Communicate your findings via the tools and processes they use&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.3	Establish a frequency and scope of patching&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.4	Establish a group of assets dedicated for patch testing&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.5	Report back your test results to the responsible stakeholders&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.6	Use the ticketing system or change management system to resolve the patch management issues&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.7	Always assign these tickets&amp;lt;br&amp;gt; &lt;br /&gt;
3.2.8	Include responsible, accountable, stakeholders, and who needs to be informed on unresolved &lt;br /&gt;
issues&amp;lt;br&amp;gt;&lt;br /&gt;
3.2.9	Use the frequency of your reporting cycle to follow up on open issues&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3.3	Investigate False Positives (FP)&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.1	Ensure integrity of a claim&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.2	Construct a repeatable business process&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.3	Document all FP submissions&amp;lt;br&amp;gt; &lt;br /&gt;
3.3.4	Find SMEs who can agree or argue a false positive claim&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.5	Set a time frame at which FP should be reevaluated&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.6	Document each FP and store it in an auditable repository&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.7	Create an appropriate policy&amp;lt;br&amp;gt;&lt;br /&gt;
3.3.8	Communicate this policy to all employees&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
3.4	Control Vulnerability Exception Process&amp;lt;br&amp;gt; &lt;br /&gt;
3.4.1	Find an executive authority to sign off on a cyber security exception&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.2	Establish ground rules for vulnerability exceptions&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.3	Establish periodic reviews of  vulnerability exceptions&amp;lt;br&amp;gt; &lt;br /&gt;
3.4.4	Establish acceptable compensating controls&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.5	Document each exception and store it in the company?s audit system&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.6	Create an appropriate policy&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.7	Communicate this policy to all employees&amp;lt;br&amp;gt;&lt;br /&gt;
3.4.8	Have vulnerability exception solicitors asking the executive authority for an approval every time&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:OWASP_Vulnerability_Management_Guide&amp;diff=243651</id>
		<title>Talk:OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:OWASP_Vulnerability_Management_Guide&amp;diff=243651"/>
				<updated>2018-09-24T04:03:56Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[https://github.com/lizfrenz/owasp-vuln-mngmnt Please leave a comment using GitHub. ]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
OWASP Vulnerability Management Guide v.1&lt;br /&gt;
(“bare bones” list)&lt;br /&gt;
&lt;br /&gt;
1	Detection Cycle&lt;br /&gt;
&lt;br /&gt;
1.1	Define/Refine scope&lt;br /&gt;
1.1.1	Know the enterprise risks&lt;br /&gt;
1.1.2	Know operational constraints &lt;br /&gt;
1.1.3	Know technical constraints &lt;br /&gt;
1.1.4	Distinguish primary assets vs. secondary &lt;br /&gt;
1.1.5	Embed vulnerability management processes into the enterprise processes&lt;br /&gt;
1.1.6	Build managerial support&lt;br /&gt;
&lt;br /&gt;
1.2	Optimize Tools &lt;br /&gt;
1.2.1	Determine the type of your test/scan&lt;br /&gt;
1.2.2	Determine the frequency of your tests/scans&lt;br /&gt;
1.2.3	Ensure the latest vulnerability feed &lt;br /&gt;
1.2.4	Check if vulnerability exceptions exist&lt;br /&gt;
1.2.5	Test your tool for integrity&lt;br /&gt;
1.2.6	Adjust your tools settings, preferences, templates&lt;br /&gt;
&lt;br /&gt;
1.3	Confirm Findings&lt;br /&gt;
1.3.1	Check if your test results have valuable data&lt;br /&gt;
1.3.2	Interpret and reconcile system/device fingerprinting across your tests &lt;br /&gt;
1.3.3	Determine that running services  are what they are supposed to be&lt;br /&gt;
1.3.4	Find something that falls out of the pattern and investigate why&lt;br /&gt;
1.3.5	Randomly select vulnerabilities and confirm them with a different tool or manually&lt;br /&gt;
&lt;br /&gt;
2	Reporting Cycle&lt;br /&gt;
&lt;br /&gt;
2.1	Create Assets Groups&lt;br /&gt;
2.1.1	Determine functional asset groups&lt;br /&gt;
2.1.2	Determine asset groups by type of environment&lt;br /&gt;
2.1.3	Determine asset groups by type of system&lt;br /&gt;
2.1.4	Determine groups by CVE numbering authority or underlying technology&lt;br /&gt;
2.1.5	Determine groups by type of vulnerability&lt;br /&gt;
&lt;br /&gt;
2.2	Define/Refine Metrics&lt;br /&gt;
2.2.1	Determine amount and percentage of vulnerable assets &lt;br /&gt;
2.2.2	Determine amount and percentage of vulnerable assets by severity and CVSS&lt;br /&gt;
2.2.3	Determine amount and percentage of new vulnerabilities: &lt;br /&gt;
2.2.3.1	-by severity&lt;br /&gt;
2.2.3.2	-by functional groups&lt;br /&gt;
2.2.3.3	-by type of environment&lt;br /&gt;
2.2.3.4	-by type of system&lt;br /&gt;
2.2.3.5	-by CVE numbering authority&lt;br /&gt;
2.2.3.6	-by type of vulnerability&lt;br /&gt;
2.2.4	Compare and analyze aging data by severity of vulnerabilities and their share:&lt;br /&gt;
2.2.4.1	-enterprise wide&lt;br /&gt;
2.2.4.2	-among all other vulnerable assets&lt;br /&gt;
2.2.4.3	-by functional groups&lt;br /&gt;
2.2.4.4	-by type of environment&lt;br /&gt;
2.2.4.5	-by type of system&lt;br /&gt;
2.2.4.6	-by CVE numbering authority&lt;br /&gt;
2.2.4.7	-by type of vulnerability&lt;br /&gt;
2.2.5	Draw out the trends by count and percentage utilizing KPI that matter to your enterprise risks and compliance&lt;br /&gt;
2.2.6	Determine exploitability of vulnerable assets by severity; specify count, percentage, decrease or increase&lt;br /&gt;
&lt;br /&gt;
2.3	Log Confirmed Findings&lt;br /&gt;
2.3.1	Use your organization’s ticketing system&lt;br /&gt;
2.3.2	Provide a summary of the issue&lt;br /&gt;
2.3.3	Provide tools’ based output &lt;br /&gt;
2.3.4	Notify/assign the issue/ticket to the responsible teams or individuals&lt;br /&gt;
2.3.5	Make sure that your manager/CISO is aware&lt;br /&gt;
&lt;br /&gt;
2.4	Create Reports&lt;br /&gt;
2.4.1	Maintain a consistent frequency of reporting and use it to track the changes&lt;br /&gt;
2.4.2	Aggregate and process collected data &lt;br /&gt;
2.4.3	Using CVSS, apply unique environmental traits to your vulnerability analysis&lt;br /&gt;
2.4.4	State vulnerability trends&lt;br /&gt;
2.4.5	Hypothesize about these trends in one sentence&lt;br /&gt;
2.4.6	In one paragraph, add your recommendations&lt;br /&gt;
2.4.7	Apply data sensitivity classification to your report&lt;br /&gt;
2.4.8	Make a shorter version (1-2 pages) of your report&lt;br /&gt;
2.4.9	Submit both versions of the report to your manager/CISO&lt;br /&gt;
2.4.10	Create and maintain your own vulnerability management repository for internal or external audit&lt;br /&gt;
2.4.11	Be able to explain the details of the vulnerability detection and reporting process&lt;br /&gt;
&lt;br /&gt;
3	Remediation Cycle&lt;br /&gt;
&lt;br /&gt;
3.1	Prioritize Vulnerabilities&lt;br /&gt;
3.1.1	Use your reports&lt;br /&gt;
3.1.2	Use your trend analysis &lt;br /&gt;
3.1.3	Use information from additional sources&lt;br /&gt;
3.1.4	Apply other environmental factors&lt;br /&gt;
3.1.5	Communicate to responsible and accountable stakeholders&lt;br /&gt;
&lt;br /&gt;
3.2	Patching&lt;br /&gt;
3.2.1	Find the stakeholders responsible for patching&lt;br /&gt;
3.2.2	Communicate your findings via the tools and processes they use&lt;br /&gt;
3.2.3	Establish a frequency and scope of patching&lt;br /&gt;
3.2.4	Establish a group of assets dedicated for patch testing&lt;br /&gt;
3.2.5	Report back your test results to the responsible stakeholders&lt;br /&gt;
3.2.6	Use the ticketing system or change management system to resolve the patch management issues&lt;br /&gt;
3.2.7	Always assign these tickets &lt;br /&gt;
3.2.8	Include responsible, accountable, stakeholders, and who needs to be informed on unresolved issues&lt;br /&gt;
3.2.9	Use the frequency of your reporting cycle to follow up on open issues&lt;br /&gt;
&lt;br /&gt;
3.3	Investigate False Positives (FP)&lt;br /&gt;
3.3.1	Ensure integrity of a claim&lt;br /&gt;
3.3.2	Construct a repeatable business process&lt;br /&gt;
3.3.3	Document all FP submissions &lt;br /&gt;
3.3.4	Find SMEs who can agree or argue a false positive claim&lt;br /&gt;
3.3.5	Set a time frame at which FP should be reevaluated&lt;br /&gt;
3.3.6	Document each FP and store it in an auditable repository&lt;br /&gt;
3.3.7	Create an appropriate policy&lt;br /&gt;
3.3.8	Communicate this policy to all employees&lt;br /&gt;
&lt;br /&gt;
3.4	Control Vulnerability Exception Process &lt;br /&gt;
3.4.1	Find an executive authority to sign off on a cyber security exception&lt;br /&gt;
3.4.2	Establish ground rules for vulnerability exceptions&lt;br /&gt;
3.4.3	Establish periodic reviews of  vulnerability exceptions &lt;br /&gt;
3.4.4	Establish acceptable compensating controls&lt;br /&gt;
3.4.5	Document each exception and store it in the company’s audit system&lt;br /&gt;
3.4.6	Create an appropriate policy&lt;br /&gt;
3.4.7	Communicate this policy to all employees&lt;br /&gt;
3.4.8	Have vulnerability exception solicitors asking the executive authority for an approval every time&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:OWASP_Vulnerability_Management_Guide&amp;diff=243650</id>
		<title>Talk:OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:OWASP_Vulnerability_Management_Guide&amp;diff=243650"/>
				<updated>2018-09-24T02:52:59Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: Created page with &amp;quot;[https://github.com/lizfrenz/owasp-vuln-mngmnt Please leave a comment using GitHub. ]&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[https://github.com/lizfrenz/owasp-vuln-mngmnt Please leave a comment using GitHub. ]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243649</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243649"/>
				<updated>2018-09-24T02:48:47Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: /* Getting Involved */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Vulnerability Management Guide==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Vulnerability management is one of the most effective means of controlling cybersecurity risk.  Yet, as indicated by the wave of massive data breaches and ransomware attacks, all too often organizations are compromised over missing patches and misconfigurations.  Vulnerability management seeks to help organizations identify such weaknesses in its security posture so that they can be rectified before they are exploited by attackers.  The OWASP Vulnerability Management Guide project seeks to establish guidance on the best practices that organizations can use establish a vulnerability management program within their organization.  The guide provides in depth coverage of the full vulnerability management lifecycle including the preparation phase, the vulnerability identification/scanning phase, the reporting phase, and remediation phase.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The vulnerability management guide should help to breakdown vulnerability management process into a manageable repeatable cycles tailored to your organizational needs. Target audience: information security practitioners of all levels, IT professionals, and business leaders.&lt;br /&gt;
&lt;br /&gt;
Vulnerability Management Cycle:&lt;br /&gt;
* DETECTION&lt;br /&gt;
* REPORTING&lt;br /&gt;
* REMEDIATION&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Vulnerability Management project is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
As of '''September 2018''', the highest priorities for the next 8 months are: &lt;br /&gt;
* a “bare bones” list (coming soon); &lt;br /&gt;
* a logical diagram (coming Q4 2018); &lt;br /&gt;
* a Power Point presentation (coming Q4 2018); &lt;br /&gt;
* a DIY guide with notes that reference controls, useful sources, and examples (coming Q1 2019);&lt;br /&gt;
* a DIY guide with the notes, examples, and illustrations (coming Q1 2019).&lt;br /&gt;
&lt;br /&gt;
Subsequent releases will be unscheduled: &lt;br /&gt;
* Bug Fix&lt;br /&gt;
* Internationalization&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Get Involved by:&lt;br /&gt;
* '''Promoting'''. Please spread the word! &lt;br /&gt;
* '''Adopting'''. The best contribution is your adoption! &lt;br /&gt;
* '''Collaborating'''. Please leave a comment using Discussion tab link to GitHub. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Efrenz Elizabeth Frenz]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243645</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243645"/>
				<updated>2018-09-24T02:40:19Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: /* Roadmap */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Vulnerability Management Guide==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Vulnerability management is one of the most effective means of controlling cybersecurity risk.  Yet, as indicated by the wave of massive data breaches and ransomware attacks, all too often organizations are compromised over missing patches and misconfigurations.  Vulnerability management seeks to help organizations identify such weaknesses in its security posture so that they can be rectified before they are exploited by attackers.  The OWASP Vulnerability Management Guide project seeks to establish guidance on the best practices that organizations can use establish a vulnerability management program within their organization.  The guide provides in depth coverage of the full vulnerability management lifecycle including the preparation phase, the vulnerability identification/scanning phase, the reporting phase, and remediation phase.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The vulnerability management guide should help to breakdown vulnerability management process into a manageable repeatable cycles tailored to your organizational needs. Target audience: information security practitioners of all levels, IT professionals, and business leaders.&lt;br /&gt;
&lt;br /&gt;
Vulnerability Management Cycle:&lt;br /&gt;
* DETECTION&lt;br /&gt;
* REPORTING&lt;br /&gt;
* REMEDIATION&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Vulnerability Management project is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
As of '''September 2018''', the highest priorities for the next 8 months are: &lt;br /&gt;
* a “bare bones” list (coming soon); &lt;br /&gt;
* a logical diagram (coming Q4 2018); &lt;br /&gt;
* a Power Point presentation (coming Q4 2018); &lt;br /&gt;
* a DIY guide with notes that reference controls, useful sources, and examples (coming Q1 2019);&lt;br /&gt;
* a DIY guide with the notes, examples, and illustrations (coming Q1 2019).&lt;br /&gt;
&lt;br /&gt;
Subsequent releases will be unscheduled: &lt;br /&gt;
* Bug Fix&lt;br /&gt;
* Internationalization&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Involvement in the development and promotion of the &amp;lt;strong&amp;gt;OWASP Vulnerability Management Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
Spreading awareness of the project&lt;br /&gt;
Translating into a foreign language&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Efrenz Elizabeth Frenz]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243644</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243644"/>
				<updated>2018-09-24T02:36:29Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Vulnerability Management Guide==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Vulnerability management is one of the most effective means of controlling cybersecurity risk.  Yet, as indicated by the wave of massive data breaches and ransomware attacks, all too often organizations are compromised over missing patches and misconfigurations.  Vulnerability management seeks to help organizations identify such weaknesses in its security posture so that they can be rectified before they are exploited by attackers.  The OWASP Vulnerability Management Guide project seeks to establish guidance on the best practices that organizations can use establish a vulnerability management program within their organization.  The guide provides in depth coverage of the full vulnerability management lifecycle including the preparation phase, the vulnerability identification/scanning phase, the reporting phase, and remediation phase.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The vulnerability management guide should help to breakdown vulnerability management process into a manageable repeatable cycles tailored to your organizational needs. Target audience: information security practitioners of all levels, IT professionals, and business leaders.&lt;br /&gt;
&lt;br /&gt;
Vulnerability Management Cycle:&lt;br /&gt;
* DETECTION&lt;br /&gt;
* REPORTING&lt;br /&gt;
* REMEDIATION&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Vulnerability Management project is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The project roadmap includes the development and release of a version 1 of the OWASP Vulnerability Management Guide as a starting point.  Community feedback and other contributions will be used to refine the guide and create future versions.  The project would also be interested in language translations as that will help ensure the project is accessible to as wide an audience as possible. &lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Involvement in the development and promotion of the &amp;lt;strong&amp;gt;OWASP Vulnerability Management Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
Spreading awareness of the project&lt;br /&gt;
Translating into a foreign language&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Efrenz Elizabeth Frenz]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243643</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=243643"/>
				<updated>2018-09-24T02:36:06Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Vulnerability Management Guide==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Vulnerability management is one of the most effective means of controlling cybersecurity risk.  Yet, as indicated by the wave of massive data breaches and ransomware attacks, all too often organizations are compromised over missing patches and misconfigurations.  Vulnerability management seeks to help organizations identify such weaknesses in its security posture so that they can be rectified before they are exploited by attackers.  The OWASP Vulnerability Management Guide project seeks to establish guidance on the best practices that organizations can use establish a vulnerability management program within their organization.  The guide provides in depth coverage of the full vulnerability management lifecycle including the preparation phase, the vulnerability identification/scanning phase, the reporting phase, and remediation phase.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The vulnerability management guide should help to breakdown vulnerability management process into a manageable repeatable cycles tailored to your organizational needs. Target audience: information security practitioners of all levels, IT professionals, and business leaders.&lt;br /&gt;
&lt;br /&gt;
Vulnerability Management Cycle Brief&lt;br /&gt;
* DETECTION&lt;br /&gt;
* REPORTING&lt;br /&gt;
* REMEDIATION&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Vulnerability Management project is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The project roadmap includes the development and release of a version 1 of the OWASP Vulnerability Management Guide as a starting point.  Community feedback and other contributions will be used to refine the guide and create future versions.  The project would also be interested in language translations as that will help ensure the project is accessible to as wide an audience as possible. &lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Involvement in the development and promotion of the &amp;lt;strong&amp;gt;OWASP Vulnerability Management Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
Spreading awareness of the project&lt;br /&gt;
Translating into a foreign language&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Efrenz Elizabeth Frenz]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=242664</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=242664"/>
				<updated>2018-08-20T00:51:32Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Vulnerability Management Guide==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Vulnerability management is one of the most effective means of controlling cybersecurity risk.  Yet, as indicated by the wave of massive data breaches and ransomware attacks, all too often organizations are compromised over missing patches and misconfigurations.  Vulnerability management seeks to help organizations identify such weaknesses in its security posture so that they can be rectified before they are exploited by attackers.  The OWASP Vulnerability Management Guide project seeks to establish guidance on the best practices that organizations can use establish a vulnerability management program within their organization.  The guide provides in depth coverage of the full vulnerability management lifecycle including the preparation phase, the vulnerability identification/scanning phase, the reporting phase, and remediation phase.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The guide will demonstrate a set of best practices that organizations can use to establish an effective and efficient vulnerability management program.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Vulnerability Management project is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The project roadmap includes the development and release of a version 1 of the OWASP Vulnerability Management Guide as a starting point.  Community feedback and other contributions will be used to refine the guide and create future versions.  The project would also be interested in language translations as that will help ensure the project is accessible to as wide an audience as possible. &lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Involvement in the development and promotion of the &amp;lt;strong&amp;gt;OWASP Vulnerability Management Guide&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
Spreading awareness of the project&lt;br /&gt;
Translating into a foreign language&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Efrenz Elizabeth Frenz]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=242663</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=242663"/>
				<updated>2018-08-20T00:50:24Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: Created page from template&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Vulnerability Management Guide==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Vulnerability management is one of the most effective means of controlling cybersecurity risk.  Yet, as indicated by the wave of massive data breaches and ransomware attacks, all too often organizations are compromised over missing patches and misconfigurations.  Vulnerability management seeks to help organizations identify such weaknesses in its security posture so that they can be rectified before they are exploited by attackers.  The OWASP Vulnerability Management Guide project seeks to establish guidance on the best practices that organizations can use establish a vulnerability management program within their organization.  The guide provides in depth coverage of the full vulnerability management lifecycle including the preparation phase, the vulnerability identification/scanning phase, the reporting phase, and remediation phase.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The guide will demonstrate a set of best practices that organizations can use to establish an effective and efficient vulnerability management program.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Vulnerability Management project is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
The project roadmap includes the development and release of a version 1 of the OWASP Vulnerability Management Guide as a starting point.  Community feedback and other contributions will be used to refine the guide and create future versions.  The project would also be interested in language translations as that will help ensure the project is accessible to as wide an audience as possible. &lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Documentation Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
Spreading awareness of the project&lt;br /&gt;
Translating into a foreign language&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Efrenz Elizabeth Frenz]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Document]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=242662</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=242662"/>
				<updated>2018-08-20T00:12:48Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: /* Related Projects */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Documentation Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Documentation Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Documentation Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Documentation project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Documentation Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Tool Project Template&lt;br /&gt;
* Get other people to review the Tool Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Tool Project Template&lt;br /&gt;
* Finalize the Documentation Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Documentation Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
	Elizabeth Frenz is a highly experienced information security professional that specializes in taking risk based approaches to improving the security and quality of software products.  She works as Information Security Analyst for DOE DIIT. Previously in her career she led the vulnerability management program for a Fortune 500 company that builds software solutions for the pharmaceutical industry.  Elizabeth also has extensive experience in the identity and access management arena and was one of the contributors to an IEEE standard for using biometrics for identity and access management.  She is an active member in the NY information security scene and serves as chapter leader of the NYC OWASP chapter.  Elizabeth holds an MS degree in Systems Management from NYU.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
	No related OWASP projects yet. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Tool_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=242661</id>
		<title>OWASP Vulnerability Management Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerability_Management_Guide&amp;diff=242661"/>
				<updated>2018-08-20T00:11:08Z</updated>
		
		<summary type="html">&lt;p&gt;Efrenz: /* Project Leader */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
==Project About==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP Documentation Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Documentation Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Documentation Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Documentation project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Documentation Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Tool Project Template&lt;br /&gt;
* Get other people to review the Tool Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Tool Project Template&lt;br /&gt;
* Finalize the Documentation Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Documentation Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#000000&amp;quot;&amp;gt;&lt;br /&gt;
	Elizabeth Frenz is a highly experienced information security professional that specializes in taking risk based approaches to improving the security and quality of software products.  She works as Information Security Analyst for DOE DIIT. Previously in her career she led the vulnerability management program for a Fortune 500 company that builds software solutions for the pharmaceutical industry.  Elizabeth also has extensive experience in the identity and access management arena and was one of the contributors to an IEEE standard for using biometrics for identity and access management.  She is an active member in the NY information security scene and serves as chapter leader of the NYC OWASP chapter.  Elizabeth holds an MS degree in Systems Management from NYU.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Tool_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[Image:Creative%20Commons.png| 90px | link=https://creativecommons.org/licenses/by-sa/3.0/| Creative Commons Attribution ShareAlike 3.0 License]]&lt;br /&gt;
   |}&lt;br /&gt;
|}&lt;br /&gt;
 &lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]] [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Efrenz</name></author>	</entry>

	</feed>