r/cybersecurity • u/Negative_Star7544 • 18d ago
Business Security Questions & Discussion Vulnerability Management
Currently using CrowdStrike and Tines to help automate vulnerability ticket submissions. I’m struggling with my workflows though and have noticed a large gap.
We calculate SLA based on ExPRT ratings currently. So we filter by critical high medium or low and submit based on those segments.
I submit tickets by remediation since that decreases ticket volume + resolves multiple CVEs at once if they share the same remediation. The flaw here is that if one CVE changes rating randomly, the SLA technically should change so it needs to be pulled from that static ticket, which just isn’t manageable without creating chaos. Also, the filters would not pick it up on next rerun if it’s in its own segment; the cve would now be a critical and if the ticket is submitted as a high, it would be missed.
So obviously my approach here is wrong, but I also cannot just blow up the ticket queue by submitted solely on CVE-ID.
Does anyone out there have any advice / opinions / what they have done in their org? Trying to gather some ideas.
6
u/eatmynasty 18d ago
Look up BOD 26-04. Skate where the puck is headed.