Vulnerability scanning is the automated process of inspecting systems, networks, and applications to identify known security weaknesses by comparing observed configurations and software versions against databases of disclosed vulnerabilities. It produces prioritised findings that feed remediation and patch-management workflows, and is typically run on a recurring schedule across an organisation’s assets. Scanning is a detective control that complements deeper manual assessment such as penetration testing.
- Vulnerability Scanning is the automated inspection of systems and networks for known weaknesses, a sub-discipline of managing Vulnerability. It uses Automation to enable Security, complements manual Audit, and supports Governance by producing prioritised, repeatable findings.
Overview
- A vulnerability scanner enumerates hosts, services, and software and matches them against catalogues of disclosed weaknesses.
- Scans may be unauthenticated, probing from the network, or authenticated, inspecting configuration from within a host for deeper coverage.
- Findings are scored and prioritised, commonly using severity ratings, and routed into remediation and patching processes.
- Recurring scans track an organisation’s exposure over time and verify that fixes have been applied.
Mechanisms
- Asset discovery: identify hosts, ports, and running services to define scope.
- Signature matching: compare observed versions and settings to vulnerability databases.
- Authenticated checks: log in to inspect patches, configuration, and local weaknesses.
- Reporting and prioritisation: rank findings by severity and feed remediation workflows.
Applications
- Continuous assessment of servers, endpoints, and network devices.
- Compliance evidence for security standards and audits.
- Pre-deployment checks of images and infrastructure as code.
- Tracking remediation progress and verifying patch effectiveness.