# Vulnerability Management for Federal Systems Course (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/courses/vulnerability-management-for-federal-systems-course-self-paced>

## Overview

Most vulnerability management training teaches how to run a scanner. This course explains why federal programs patch and scan the way they do, so learners understand the reasoning behind the requirements.

Learners study asset visibility under BOD 23-01 and CDM, prioritization with the KEV catalog, BOD 26-04 timelines, and patch planning under NIST SP 800-40. The course closes with reporting vulnerability posture in terms leadership can act on.

## What you'll learn

- Explain why a risk-based vulnerability management program reduces exposure faster than a patch-everything approach.
- Describe the asset visibility requirements CISA Binding Operational Directive 23-01 places on federal agencies.
- Explain the Continuous Diagnostics and Mitigation program's role in continuous asset and vulnerability awareness.
- Prioritize remediation using the CISA Known Exploited Vulnerabilities catalog.
- Apply CISA Binding Operational Directive 26-04 tiers and timelines to a remediation schedule.
- Plan an enterprise patch management lifecycle following NIST SP 800-40 guidance.
- Document patch exceptions for legacy systems and compensating controls.
- Distinguish among vulnerability scan types and set appropriate scope and cadence.
- Read and interpret a vulnerability scan report.
- Build a Plan of Action and Milestones to track remediation.
- Translate technical vulnerability data into a leadership-ready risk report.
- Identify the roles, from ISSO to CISO, responsible for vulnerability management decisions.

## Curriculum

#### Module 1: Why Vulnerability Management Runs the Program

- Lessons: 
  - The Cost of Unpatched Systems
  - From Vulnerability to Exploit: How Adversaries Operate
  - The Federal Vulnerability Management Mandate Landscape
  - Program Ownership: Roles from ISSO to CISO

- Applied activity: Learners walk through a case study timeline from vulnerability disclosure to exploitation to organizational impact, and identify the point where a faster patching decision would have changed the outcome.

#### Module 2: Asset Visibility and the CDM Program

- Lessons: 
  - Why You Cannot Patch What You Cannot See
  - BOD 23-01: Asset Visibility and Vulnerability Detection Requirements
  - The Continuous Diagnostics and Mitigation Program
  - Building and Maintaining an Asset Inventory

- Applied activity: Given a sample asset list with known gaps, learners identify which systems are missing from inventory and what BOD 23-01 would require the agency to do next.

#### Module 3: The KEV Catalog and Exploitation-Based Prioritization

- Lessons: 
  - Severity Scores Are Not Enough: The Limits of CVSS Alone
  - Inside the CISA Known Exploited Vulnerabilities Catalog
  - Building a Risk-Based Remediation Priority List
  - Case Walkthrough: Tracing a KEV Entry to a Remediation Deadline

- Applied activity: Given a short list of vulnerabilities with CVSS scores, learners cross-reference which ones appear on the KEV catalog and re-order the remediation priority list accordingly.

#### Module 4: BOD 26-04 Tiers and Remediation Timelines

- Lessons: 
  - What a Binding Operational Directive Requires
  - BOD 26-04 Tiering Structure Explained
  - Remediation Timelines and Compliance Reporting
  - Common Compliance Gaps and How Programs Close Them

- Applied activity: Given a discovered vulnerability's characteristics, learners determine which BOD 26-04 tier it falls into and calculate the remediation deadline.

#### Module 5: Patch Management Planning per NIST SP 800-40

- Lessons: 
  - The Enterprise Patch Management Lifecycle
  - Planning, Testing and Staging Patches
  - Patch Prioritization Strategies from SP 800-40
  - Handling Exceptions, Legacy Systems and Compensating Controls

- Applied activity: Learners draft a patch management plan outline for a hypothetical system, including testing and staging steps and one legacy-system exception.

#### Module 6: Vulnerability Scanning Programs and Scan Cadence

- Lessons: 
  - Types of Vulnerability Scans and What Each One Reveals
  - Setting Scan Scope, Cadence and Credentials Policy
  - Reading a Scan Report Without Running One
  - Where Scanning Fits in the Larger Program

- Applied activity: Learners review a sample scan report excerpt and identify scan type, scope, and what follow-up action the findings require, without running a scanner.

#### Module 7: Reporting Vulnerability Posture to Leadership

- Lessons: 
  - Metrics That Matter to Executives
  - Building a POA&M and Tracking Remediation
  - Communicating Risk Without Jargon
  - Briefing Leadership: A Model Vulnerability Posture Report

- Applied activity: Learners convert a set of technical scan and remediation results into a two-paragraph leadership brief and a one-page POA&M excerpt.

## Pricing

**Tuition:** $1049
