01Introduction
Tens of thousands of new CVEs are published every year, on top of the flaws in your own code and configuration. Vulnerability management is the discipline of deciding which ones matter to you and making sure those get fixed.
02What is Vulnerability management?
Vulnerability management is the continuous process of identifying, assessing, prioritizing, remediating and verifying security weaknesses across an organization's software, infrastructure and cloud. It is a program, not a single scan.
It is required in some form by nearly every framework, including PCI DSS, ISO 27001, SOC 2 and FedRAMP. Its modern variants, risk-based vulnerability management and CTEM, change how the prioritization step works. Parameter runs the scanning step as managed vulnerability scanning.
03How Vulnerability management works
The program runs as a loop.
- 1.
Discover
Inventory assets and scan them: hosts, containers, dependencies, cloud resources and applications. See managed vulnerability scanning.
- 2.
Assess
Score each finding for severity, usually with CVSS (try the CVSS calculator), and add business context.
- 3.
Remediate
Patch, reconfigure or apply a compensating control, tracked against a service-level target per severity. See patch management.
- 4.
Verify
Rescan or retest to confirm the fix worked, then report trends.
04Threats and risks
Most programs fail on prioritization, not discovery.
Backlogs that never shrink
Scanners find far more issues than any team can fix, so the backlog becomes permanent.
Severity is not risk
A CVSS 9.8 on an unreachable library can matter less than a CVSS 6 on an internet-facing API.
Scanner blind spots
Business logic and authorization flaws don't match a signature, so scanners miss them. Penetration testing finds them.
Unverified fixes
Tickets are closed on a code change without anyone confirming the exploit no longer works.
05How Parameter helps
Parameter replaces 'possible issues' with proven ones, so the queue is short and real.
Proof for every finding
The pentesting agents reproduce each issue with a working exploit, so false positives are dropped before they reach you.
Reachability for dependencies
Supply Chain flags a vulnerable package only when your code can reach the vulnerable path.
Automatic retest
When a fix ships, the agents test again and close the finding on evidence.

