Cybersecurity and Infrastructure Security Agency – Free Cybersecurity Services and Tools
3.11 3.11.2 Risk Assessment
https://www.cisa.gov/resources-tools/resources/free-cybersecurity-services-and-tools
CISA has curated a database of free cybersecurity services and tools as part of our continuing mission to reduce cybersecurity risk across U.S. critical infrastructure partners and state, local, tribal, and territorial governments.
https://www.ibm.com/think/topics/vulnerability-scanning
This article addresses the importance of vulnerability scanning, how the process works, and types of vulnerability scanners.
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf
This NIST Special Publication is a guide to the basic technical aspects of conducting information security assessments.
Open Web Application Security Project (OWASP) – Vulnerability Scanning Tools
3.11 3.11.2 Risk Assessment
https://owasp.org/www-community/Vulnerability_Scanning_Tools
Open Web Application Security Project (OWASP) provides a list of commercial and free vulnerability scanning tools for various platforms.
https://www.sprocketsecurity.com/blog/vulnerability-management-best-practices
This article from Sprocket Security highlights the challenges of vulnerability management and how to establish an effective vulnerability management program.
https://its.ny.gov/system/files/documents/2024/02/nys-s15-002-vulnerability-management.pdf
The following is an example from the state of New York of a vulnerability scanning policy.
Tripwire – Vulnerability Management Program Best Practices
3.11 3.11.2 Risk Assessment
https://www.tripwire.com/state-of-security/vulnerability-management-best-practice
In this article from Tripwire, they discuss the four stages of a vulnerability management program
Wiz.io – 11 Vulnerability Management Best Practices
3.11 3.11.2 Risk Assessment
https://www.wiz.io/academy/vulnerability-management-best-practices
In this article from Wiz, they discuss the 11 essential vulnerability management best practices organizations should start with.