Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Vulnerability management

Also known as: Vulnerability handling

German: Schwachstellenmanagement

In cybersecurity, vulnerability management is the continuous process of identifying, assessing, prioritizing, treating and verifying vulnerabilities in systems and products. For asset owners it covers installed assets; for product suppliers it includes handling reported vulnerabilities and delivering fixes.

  • OT security

In one sentence

Vulnerability management is the continuous process of identifying, assessing, prioritizing, treating and verifying vulnerabilities in systems and products.

Example

When a new advisory for a switch model arrives, the plant's vulnerability management process matches it to the asset inventory, rates exposure, schedules the firmware update and applies a temporary firewall rule.

Explained in context

Context cards connect this term with others to answer one question. Also in British English and German.

How it applies

  • Operation: Asset owners combine Asset inventory, advisory feeds and scans to find vulnerabilities, then decide per case: patch, mitigate (segmentation, disabling a service), accept with justification, or replace the device. In OT, patching often waits for a maintenance window, so mitigations bridge the gap.
  • Product development: Suppliers need a process to receive reports, analyze and fix vulnerabilities and publish advisories. The Cyber Resilience Act (CRA) makes vulnerability handling an essential requirement for products with digital elements, and IEC 62443-4-1 covers it in its practices.
  • Maintenance: Verification closes the loop: confirm that the fix or mitigation is in place and effective.
  • Documentation: Keep decisions and justifications, especially accepted risks, as records. Product documentation should explain how customers are informed about vulnerabilities and where advisories are published.

Vulnerability management vs. patch management

Patch management handles the deployment of software updates. Vulnerability management is broader and also covers assessment, mitigations without patches and risk acceptance.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Knowledge editorial definition, based on IEC 62443 and Regulation (EU) 2024/2847 (CRA)

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!