Vulnerability assessment and management is one of the essential functions of any enterprise security program. The mere existence of a vulnerability doesn’t constitute risk; risk is the combination of vulnerability, access to that vulnerability, the ability to exploit it and, most importantly, something of value that could be extracted. Risk management puts the vulnerability in context within the IT environment and helps security professionals understand if a particular risk is really something they should prioritize over other issues. To implement an effective risk management approach, IT teams must first have an accurate and efficient vulnerability assessment tool.”]
Source: https://securityintelligence.com/vulnerability-management-do-you-know-your-risks/

