- Identify vulnerabilities through regular scans or assessments through ASICS managed toolsets Qualys, Crowd Strike, Identity and Bit Sight Prioritize vulnerabilities based on priority and criticality
- Exclusion of false positives Conduct the assessment to validate vulnerabilities
- Understand the context and potential risks associated with each vulnerability
- Coordinate with system owners, IT teams, and management
- Follow-up on changes to mitigate found vulnerabilities Changes for remediation for assets within Fujitsus existing scope of services Verify that the remediation actions were resolved by responsible teams
- If needed, Conduct post-remediation scans or assessments
- Monthly standard service report including the management summary
- Conduct a post-mortem analysis of the vulnerability management process