Open Access

Transition from Periodic Security Assessments to Continuous Vulnerability Management Frameworks

4 SoftLine PJSC Almaty, Kazakhstan

Abstract

The article examines the transition from scheduled security assessments to continuous vulnerability management frameworks in enterprise environments with unstable external exposure. Cloud services, SaaS use, short-lived assets, and unmanaged public interfaces reduce the decision value of annual or project-based testing. The novelty of the study lies in combining external attack surface management, continuous penetration testing, vulnerability intelligence, and remediation verification into a single operating model. The aim is to explain why periodic assessment loses completeness when asset states change between review cycles. The method combines source analysis, comparative analysis, conceptual synthesis, and typological classification. The source base covers academic papers, public vulnerability intelligence instruments, official guidance, and industry definitions of external attack surface management. The study identifies three shifts: from snapshot testing to continuous discovery, from severity ranking to exploitation-aware prioritisation, and from automated scanning to expert-verified remediation. The model helps engineering and security teams design measurable programs to reduce exposure.

Keywords

References

Cybersecurity and Infrastructure Security Agency. (2021, November 3). Binding Operational Directive 22-01: Reducing the significant risk of known exploited vulnerabilities. https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities
Forum of Incident Response and Security Teams. (n.d.). Exploit Prediction Scoring System (EPSS). Retrieved May 4, 2026, from https://www.first.org/epss/
Gartner Peer Insights. (2026). External Attack Surface Management reviews and ratings. Retrieved May 4, 2026, from https://www.gartner.com/reviews/market/external-attack-surface-management
Jacobs, J., Romanosky, S., Suciu, O., Edwards, B., & Sarabi, A. (2023). Enhancing vulnerability prioritization: Data-driven exploit predictions with community-driven insights. 2023 IEEE European Symposium on Security and Privacy Workshops, 194-206. https://doi.org/10.1109/EuroSPW59978.2023.00027
Lazarov, W., Seda, P., Martinasek, Z., & Kummel, R. (2025). Penterep: Comprehensive penetration testing with adaptable interactive checklists. Computers & Security, 154, Article 104399. https://doi.org/10.1016/j.cose.2025.104399
Liu, H., Liu, C., Wu, X., Qu, Y., & Liu, H. (2024). An automated penetration testing framework based on hierarchical reinforcement learning. Electronics, 13(21), Article 4311. https://doi.org/10.3390/electronics13214311
Mell, P., & Spring, J. M. (2025). Likely exploited vulnerabilities: A proposed metric for vulnerability exploitation probability (NIST CSWP 41). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.CSWP.41
MITRE. (2026). MITRE ATT&CK version history and Enterprise Matrix. Retrieved May 4, 2026, from https://attack.mitre.org/resources/versions/
Skandylas, C., & Asplund, M. (2025). Automated penetration testing: Formalization and realization. Computers & Security, 155, Article 104454. https://doi.org/10.1016/j.cose.2025.104454
Souppaya, M., & Scarfone, K. (2022). Guide to enterprise patch management planning: Preventive maintenance for technology (NIST SP 800-40 Rev. 4). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-40r4

Most read articles by the same author(s)

Similar Articles

11-20 of 28

You may also start an advanced similarity search for this article.