What happened

CISA announced on Thursday that it will stop publishing its weekly Vulnerability Bulletin at the end of September, closing a roundup that has run since early 2004. Each bulletin listed vulnerabilities disclosed in the period with their CVE identifiers, severity scores and short descriptions.

The agency described the decision as part of a shift from severity based vulnerability management to a modern, risk based approach. In July it issued new vulnerability remediation guidelines for other federal agencies that set deadlines using criteria such as whether the targeted asset is internet accessible and whether exploitation can be automated. The guidelines bind federal agencies only, but CISA has urged organisations outside government to apply the same logic to their own exposure.

CISA will keep issuing advisories on specific vulnerabilities and will keep adding to its Known Exploited Vulnerabilities catalog, one of the criteria named in the July prioritisation guidance. The agency has also been promoting Stakeholder Specific Vulnerability Categorization, or SSVC, as a more nuanced alternative to relying on CVSS scores alone. Chris Butera, CISA's acting executive assistant director for cybersecurity, said the agency has been discussing SSVC with vendors that sell vulnerability management software, some of which are building that prioritisation into their tooling.

The underlying argument was put plainly by Lindsey Cerkovnik, CISA's branch chief for vulnerability response and coordination: not all vulnerabilities matter, and not all of those that do matter at the same level for every organisation.

Why this is a GRC story

Vulnerability management has quietly become a compliance ritual, and CISA has just retired the artifact that ritual was built around. For two decades, the practical definition of doing the work was pulling a list, filtering by score, and fixing from the top down. That list no longer arrives. What replaces it is a requirement to decide, for your own environment, what actually deserves attention first.

That is a governance decision, not a tooling one. Risk based prioritisation needs somebody to own the inputs: which assets face the internet, which hold regulated data, which are reachable from a phished account, which sit behind a control that already reduces the chance of exploitation. Where that context is missing, the honest result is that decisions get made by whoever is holding the scanner.

There is an evidence problem too. An auditor can test a cadence. They can ask for the ticket that shows a critical patch closed inside the policy window. Testing why a CVSS 7.1 was patched within a week while a 9.8 sat open for sixty days is harder, and it needs a written rationale on the deferral. Most programmes do not produce that artifact today.

What to watch

Watch the Known Exploited Vulnerabilities catalog become the de facto threshold in remediation policy. If exploit evidence is the strongest signal regulators and vendors both recognise, a policy that sets patch windows by CVSS band alone will start to look outdated on its face.

Watch whether the July deadline structure gets adopted outside federal agencies, and whether the vendors embedding SSVC make it easy to export your reasoning.

A simple test for a security or risk lead this quarter: take the five oldest high severity findings in your register and write down why each is still open. If the answer is that it never reached the top of a score sorted list, this change will expose that gap.

Attribution: Analysis based on Cybersecurity Dive and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News