ISO/IEC 27001:2022 Annex A · Control 8.8
Management of Technical Vulnerabilities: A Practical Implementation Guide
Find, prioritize and remediate exploitable weaknesses according to asset exposure and business risk.
This control concerns obtaining vulnerability information, assessing exposure and taking appropriate measures.
What should the control achieve?
- Relevant vulnerability sources and assets are covered.
- Findings are risk prioritized.
- Remediation and exceptions have owners and deadlines.
- Closure is verified.
Step-by-step implementation
Establish asset coverage
Map operating systems, applications, cloud, network, devices and dependencies.
Collect intelligence
Use vendor advisories, scanning, testing, SBOMs and threat information.
Prioritize contextually
Consider exposure, exploit activity, privilege, data, criticality and compensating controls.
Assign remediation
Create owner, action, target date and service-impact plan.
Manage exceptions
Document risk, safeguards, approver and expiry.
Verify closure
Rescan, retest or confirm fixed version and monitor metrics.
What this could look like in practice
An internet-facing vulnerability with active exploitation is matched to the asset inventory. The service owner applies emergency patching within 24 hours, Security rescans and change records retain evidence.
| Activity | Practical implementation | Evidence |
|---|---|---|
| Discovery | Authenticated scan identifies missing patch. | Scan finding |
| Prioritization | Exposure and exploit evidence raise urgency. | Risk decision |
| Remediation | Change deploys patch or mitigation. | Change ticket |
| Verification | Rescan confirms closure. | Validation result |
Implementation evidence
- Vulnerability procedure
- Asset coverage
- Advisory sources
- Scan reports
- Risk prioritization
- Remediation tickets
- Exception register
- Closure validation
Useful metrics
- Critical vulnerabilities past SLA
- Asset scan coverage
- Mean remediation time
- Expired exceptions
Common mistakes
- Prioritizing only by CVSS.
- Scanning without asset owners.
- Closing on ticket status alone.
- Ignoring unsupported products and dependencies.
- Permanent risk acceptance.
Questions an auditor may ask
- How is asset coverage known?
- How is risk prioritized?
- Show an exception and expiry.
- How is remediation verified?
Continue through Annex A
Explore the growing library of practical guides for all 93 Annex A controls.
Open the ISO 27001 Annex A Control LibraryThis independent educational guide paraphrases the practical intent of the control and does not replace the official ISO standards, professional advice or an organization-specific risk assessment. It is not affiliated with or endorsed by ISO.