NIST SP 800-30 Guide for Conducting Risk Assessments 3.11 3.11.1 Risk Assessment
This NIST Special Publication provides guidance for conducting risk assessments.
This NIST Special Publication provides guidance for conducting risk assessments.
Open Web Application Security Project (OWASP) provides a list of commercial and free vulnerability scanning tools for various platforms.
This SANS provided policy discusses performing periodic information security risk assessments.
This SANS whitepaper examines the role of project management in building a successful vulnerability management program.
This SANS whitepaper looks at how a vulnerability management process could be designed and implemented within an organization.
This SANS whitepaper discusses the benefits and pitfalls of Vulnerability Scanning suggests an approach suitable for small and medium-sized businesses.
The following is an example from the state of Alabama of a vulnerability scanning policy.
In this article from Tripwire, they discuss the four stages of a vulnerability management program
In this article from Wiz, they discuss the 11 essential vulnerability management best practices organizations should start with.