Skip to main content
Course

Professional Certificate in Vulnerability Management

Run the vulnerability lifecycle end to end: asset discovery, scanning, prioritization that goes beyond raw scores, remediation and the metrics leaders trust.

Beginner

Level

6

Modules

30

Lessons

6

Graded quizzes

1

Assignments

15 hours

Estimated time

What you will be able to do

  • Run the vulnerability management lifecycle from discovery to verified fix
  • Build an asset inventory and prove scan coverage
  • Scan safely with credentials without disrupting operations
  • Prioritize by real exploitability and business impact, not raw score
  • Report risk reduction to engineers and executives with credible metrics

What is inside

6 modules, 30 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    The Vulnerability Management Discipline

    What vulnerability management actually is, what it is not, and why organizations fund it. Covers the end to end lifecycle from asset discovery to verified closure, the precise difference between vulnerability, threat, risk, and exposure, the working vocabulary of Common Vulnerabilities and Exposures (CVE), Common Weakness Enumeration (CWE), the Common Vulnerability Scoring System (CVSS), the Exploit Prediction Scoring System (EPSS), and the Known Exploited Vulnerabilities catalog published by the Cybersecurity and Infrastructure Security Agency (CISA), how the discipline differs from penetration testing and red teaming, and who does what. Taught through Harbor Point Financial, a fictional 1,200 employee regional bank with a mixed on-premises and cloud estate.

    5 lessons · 15 quiz questions

  2. 02

    Asset Discovery and Attack Surface

    Why every vulnerability management program is capped by the quality of its asset inventory, how the configuration management database (CMDB) relates to what your scanners actually see, the four discovery techniques and what each one misses, how to classify and tag assets by criticality and data sensitivity, how to assign ownership so findings actually get fixed, and how to measure and prove coverage. Taught through Harbor Point Financial, a 1,200-employee regional bank running a mixed on-premises and cloud estate.

    5 lessons · 15 quiz questions

  3. 03

    Scanning and Assessment

    How weaknesses actually get found: the five scanner families and how each one is architected, why credentials turn a scan from educated guesswork into an inventory-grade assessment, how to handle scanning credentials without turning your scanner into the most valuable target in the building, how to schedule scans through change control without breaking anything, and how to prove your coverage is real and read a finding properly. Taught through Harbor Point Financial, a 1,200-employee regional bank with a mixed on-premises and cloud estate.

    5 lessons · 15 quiz questions

  4. 04

    Prioritization and Risk Scoring

    How to decide what gets fixed first when the scanner returns more findings than any team can remediate. Covers the Common Vulnerability Scoring System base, threat and environmental metrics, why sorting by raw score misleads, the Exploit Prediction Scoring System, the Known Exploited Vulnerabilities catalog, asset criticality and business context, threat intelligence inputs, and how to build a defensible prioritization model with service level agreements teams can actually meet. Taught through Harbor Point Financial, a 1,200-employee regional bank with a mixed on-premises and cloud estate.

    5 lessons · 15 quiz questions

  5. 05

    Remediation, Exceptions and Verification

    How a vulnerability finding travels from detection to verified closure: naming owners, setting remediation clocks, partnering with information technology operations and developers instead of throwing tickets over the wall, choosing between patching, mitigating and accepting, moving work through change management and maintenance windows, running a rigorous exception process with real compensating controls, and proving the fix with verification, evidence and calm dispute handling. Taught through Harbor Point Financial, a 1,200-employee regional bank with a mixed on-premises and cloud estate.

    5 lessons · 15 quiz questions

  6. 06

    Metrics, Reporting and Program Maturity

    How to measure a vulnerability management program so the numbers change decisions instead of decorating slides. You will build mean time to remediate, service level agreement compliance, scan coverage, recurrence rate and risk reduction over time, learn to spot the vanity metrics and gaming patterns that quietly corrupt a program, design separate dashboards for engineers, service owners and the board, map the work onto Payment Card Industry Data Security Standard scanning duties, System and Organization Controls 2 audits and Federal Risk and Authorization Management Program continuous monitoring, and assess maturity honestly enough to build a funded improvement roadmap. Taught through Harbor Point Financial, a 1,200-employee regional bank with a mixed on-premises and cloud estate. This module carries the course capstone.

    5 lessons · 15 quiz questions · assignment