Certified Information Security Manager (CISM)Information Security Risk ManagementMedium
During a review of an organization's vulnerability management program, the CISO notes that while many vulnerabilities are identified, the mean time to remediate (MTTR) critical findings is consistently high. Which of the following actions should the CISO prioritize to improve this situation?
- AIncrease the frequency of vulnerability scans.
- BImplement a robust patch management process with clear ownership.
- CExpand the scope of vulnerability assessments to include web applications.
- DInvest in an advanced threat intelligence platform.
Show answer & explanationAnswer & explanation
Correct answer: B. Implement a robust patch management process with clear ownership.
A high Mean Time To Remediate (MTTR) indicates a bottleneck in the remediation phase, not the identification phase. A robust patch management process with clear ownership directly addresses the ability to fix vulnerabilities in a timely manner.
Why the other options are wrong
- A. Increasing scan frequency identifies more vulnerabilities but doesn't solve the remediation bottleneck.
- C. Expanding scope identifies more vulnerabilities, but doesn't improve the time to fix existing ones.
- D. Threat intelligence helps prioritize and understand threats, but doesn't directly improve the speed of vulnerability remediation.
Mean Time To Remediate (MTTR)
The average time it takes for an organization to resolve a detected security vulnerability or incident from the point of discovery to full resolution.
- Measures efficiency of remediation processes.
- High MTTR indicates remediation bottlenecks.
- Influenced by patch management and incident response effectiveness.
Memory trick: MTTR means Must Take Timely Remediation.