Vulnerability Management
A Practitioner’s Field Guide: the complete three-volume set
Each volume stands alone, with its own index. Read in order (Learn, Run, Operate) or take the one you need.
Vulnerability management that ranks by real risk, not raw counts. The three volumes go from finding and ranking what matters, to running the programme, to the templates that keep fixes on time.
Companion to the Vulnerability Management toolkit: the assessment and ready-to-use templates that put this book to work.
From the blog: Your first scan just found 4,000 findings. An essay-length preview of the same ground this set covers, free.
Understanding and Prioritising
Volume 1 of the three-volume Vulnerability Management set: understanding and prioritising. It covers what the work actually is and how to build an asset inventory. It walks the vulnerability lifecycle, the life of a single flaw from find to fix, and the maturity spectrum that shows how a programme grows up. It then works through the relationship with the Product Security Incident Response Team (PSIRT), CVE and CVSS without the folklore, KEV and EPSS, and business context. It closes on severity versus risk and the patching ladder. Volume 2 runs the programme; Volume 3 is the Operator's Workbook. Each volume stands alone. Each is modestly priced in ebook.
Running the Programme
Volume 2 of the three-volume Vulnerability Management set: running the programme. It covers scanner programme design, patch management mechanics, SLA design and enforcement, and exception management. It then works through metrics, what to report to a board, and how the work changes for cloud and SaaS, and for OT and ICS. It closes on third-party work with vendor advisories and SBOMs, regulatory drivers, and annual cadence. Volume 1 covers understanding and prioritising; Volume 3 is the Operator's Workbook. Each volume stands alone. Each is modestly priced in ebook.
The Operator's Workbook
Volume 3 of the three-volume Vulnerability Management set: the Operator's Workbook. It holds asset inventory templates, triage decision trees and scoring matrices, and patch and remediation workflow templates. It also holds how to handle exceptions and how to read vendor advisories. It covers metrics and board reporting, and the specialised-context runbooks for the harder settings. It ends with the template finder, the Vulnerability Management Glossary, and the Maturity Rubric. Each volume stands alone. Each is modestly priced in ebook.
The set at a glance
Swipe sideways to see the full table →
| Volume | Pages | Depth | Price |
|---|---|---|---|
| Volume 1 | 336 | 16 chapters | Paperback $34.99 · Hardcover $44.99 · Ebook $12.99 |
| Volume 2 | 334 | 18 chapters | Paperback $34.99 · Hardcover $44.99 · Ebook $12.99 |
| Volume 3 (Workbook) | 334 | 9 chapters | Paperback $34.99 · Hardcover $44.99 · Ebook $12.99 |
Where to buy
Vulnerability Management will be available in paperback, hardcover, and ebook through print-on-demand retailers, each volume sold separately. The links activate the moment the titles list; until then, email us and we’ll tell you at launch.
Prices shown are our retail list prices; buy links activate when these titles are listed for sale. Books are sold through print-on-demand retailers (KDP, IngramSpark, Amazon, and independent bookstores), not through the Sylvan Assurance toolkit store.
Where a review helps
If this book helped, an honest review on Amazon does more for a small independent press than anything else. We never ask for a rating and never offer anything for one.