Manajemen Kerentanan & Mitigasi
Kerentanan harus dinilai sebelum dieksploitasi (SY0-701 2.3): - Aplikasi: injection, race condition, memory leak - Sistem: unpatched OS, default credential, port terbuka - Web: OWASP Top 10 (2021) — broken access control, cryptographic failures, injection, misconfiguration Alur mitigasi:
1. Scan (Nessus, OpenVAS) -> 2. Prioritaskan (CVSS, CISA KEV)
3. Patch / kontrol kompensasi -> 4. Verifikasi (rescan, audit)
CVSS 4.0 menambahkan metrik threat & environmental. Skor tinggi tanpa exploit publik bisa kurang mendesak dibanding skor sedang yang sudah dipakai aktif. Patch management: window terjadwal, uji di staging, rollback plan.