SITEY Blog

Security insights & guides

How to Write a Patch Management Policy Auditors Accept

Learn what auditors check in a patch management policy: scope, severity tiers, SLAs, approval rules, exceptions, and evidence. Includes a one-page skeleton.

The Vulnerability Management Lifecycle: 6 Stages Explained

A stage-by-stage walkthrough of the vulnerability management lifecycle: discovery, validation, prioritization, assignment, remediation, and verification.

External Attack Surface Management: What It Really Covers

External attack surface management explained: the asset classes it covers, where discovery data comes from, and why delta tracking beats quarterly audits.

ISO 27001 Annex A 8.8: Vulnerability Management Requirements

ISO 27001 Annex A 8.8 explained: control intent, required evidence, remediation SLAs, and how auditors escalate findings to nonconformities.

Credentialed vs Uncredentialed Scans: What You Miss

Credentialed vs uncredentialed vulnerability scanning compared: detection gaps, false-positive causes, per-platform credential needs, and a coverage formula.

Windows Server Hardening Checklist for 2022 and 2025

A role-based Windows Server hardening checklist for 2022 and 2025: identity, SMB, RDP, audit policy subcategories, GPO rollout and drift checks.

CVSS 4.0 vs CVSS 3.1: What Actually Changed for Triage

CVSS 4.0 vs 3.1 explained: Attack Requirements, the User Interaction split, Scope's retirement, VC/VI/VA vs SC/SI/SA, and what to fix in triage…

Vulnerability Remediation MTTR: How to Measure It Honestly

MTTR in vulnerability management hides four different clocks. Learn to define, measure, and report remediation time honestly without gaming the average.

Cloud Vulnerability Management vs Traditional VM Programs

Why static asset lists fail in the cloud, who owns CVE fixes when app teams own the image, and the metrics that…

How AI Triage Works for Security Findings: A Primer

How AI security triage turns 40,000 raw scanner findings into a ranked, evidence-backed queue: classification, correlation, and verdict logic explained.