0Pricing
Secure Coding & OWASP Top 10 for Backend · Lezione

Threat intelligence e gestione delle vulnerabilità

Impari a monitorare le vulnerabilità, a stabilirne la priorità con CVSS e threat intelligence e a gestire un ciclo continuo di remediation in una pipeline DevSecOps.

Threat intelligence e gestione delle vulnerabilità è una lezione Secure Coding & OWASP Top 10 for Backend gratuita su CoddyKit. Questa è la lezione 4 di 4. Puoi leggere la lezione completa qui gratuitamente — poi esercitati direttamente nel browser con un editor di codice integrato e un tutor IA disponibile 24/7. Fa parte del percorso di apprendimento Secure Coding & OWASP Top 10 for Backend, e i tuoi progressi si sincronizzano tra il web e l'app CoddyKit. Il corso Secure Coding & OWASP Top 10 for Backend include 4 lezioni in totale.

Parti di questa lezione non sono ancora state tradotte e vengono mostrate in inglese.

Why Vulnerability Management?

New vulnerabilities appear daily. Vulnerability management is the ongoing process of discovering, prioritizing, and remediating weaknesses before attackers exploit them. It is a continuous loop, not a one-time scan.

The Management Lifecycle

The lifecycle has clear stages:

  • Discover: find vulnerabilities via scans and feeds
  • Prioritize: rank by risk
  • Remediate: patch, mitigate, or accept
  • Verify: confirm the fix
  • Report: track metrics over time

CVE and CVSS

A CVE is a unique identifier for a known vulnerability. CVSS is a 0-10 score describing severity based on factors like attack vector and impact. CVSS gives a baseline, but it is not the whole story.

Reading a CVSS Score

CVSS bands roughly map to urgency. Use them to triage, but always combine with context.

def severity(score):
    if score >= 9.0:
        return 'Critical'
    if score >= 7.0:
        return 'High'
    if score >= 4.0:
        return 'Medium'
    if score > 0.0:
        return 'Low'
    return 'None'

for s in [9.8, 7.5, 4.3, 2.1]:
    print(s, severity(s))

Threat Intelligence

Threat intelligence adds real-world context: Is this CVE being actively exploited? Is there public exploit code? Feeds like CISA KEV and EPSS help you focus on what attackers are actually using right now.

Risk-Based Prioritization

Severity alone is misleading. A medium-CVSS bug under active exploitation on an internet-facing system may outrank a critical bug on an isolated internal tool. Combine severity, exploitability, and asset exposure.

def priority(cvss, exploited, internet_facing):
    score = cvss
    if exploited:
        score += 3
    if internet_facing:
        score += 2
    return round(min(score, 15), 1)

print(priority(5.0, True, True))   # medium CVE but urgent
print(priority(9.0, False, False)) # critical but isolated

Software Bill of Materials

An SBOM lists every component and version in your software. When a new CVE drops, an SBOM lets you instantly answer: are we affected, and where?

Integrating into CI/CD

In DevSecOps, vulnerability scanning runs automatically on every build: dependency scanning, container image scanning, and IaC scanning. Builds can fail when a new critical issue is found, shifting detection left.

Remediation Options

Remediation is not always a patch. Your options are:

  • Patch or upgrade the component
  • Mitigate with a workaround or compensating control
  • Accept the risk formally if impact is low

Track each decision with an owner and a deadline.

SLAs and Metrics

Define remediation SLAs by severity (for example, critical within days, high within weeks). Track metrics like mean time to remediate so the program improves measurably over time.

Feeding Incident Response

Vulnerability data and threat intel inform incident response: knowing which CVEs are exploited helps responders recognize attacks faster and patch the right systems first during an incident.

Quick Check

Test your understanding of vulnerability management.

Recap

You learned the vulnerability management lifecycle, how to read CVSS, and how threat intelligence and SBOMs enable risk-based prioritization. Integrating scanning into CI/CD, setting remediation SLAs, and feeding incident response close the loop in a mature DevSecOps program.

Domande Frequenti

La lezione «Threat intelligence e gestione delle vulnerabilità» è gratuita?

Sì — il testo completo di «Threat intelligence e gestione delle vulnerabilità» è gratuito qui sul web. Per esercitarvi in modo interattivo (un editor di codice integrato e un tutor IA 24/7) e sbloccare il resto del corso Secure Coding & OWASP Top 10 for Backend, passa a CoddyKit PRO. Il corso Secure Coding & OWASP Top 10 for Backend include 4 lezioni in totale.

Cosa imparerò in «Threat intelligence e gestione delle vulnerabilità»?

Impari a monitorare le vulnerabilità, a stabilirne la priorità con CVSS e threat intelligence e a gestire un ciclo continuo di remediation in una pipeline DevSecOps. Eserciti Secure Coding & OWASP Top 10 for Backend con codice pratico che esegui direttamente nel browser, e un tutor IA 24/7 risponde alle tue domande mentre lavori sulla lezione.

Ho bisogno di esperienza per iniziare Secure Coding & OWASP Top 10 for Backend?

Non è richiesta alcuna esperienza precedente. Secure Coding & OWASP Top 10 for Backend su CoddyKit è strutturato per principianti e studenti avanzati, quindi puoi iniziare da qui o dall'inizio e procedere al tuo ritmo. Questa è la lezione 4 di 4.

Quanto tempo richiede la lezione «Threat intelligence e gestione delle vulnerabilità»?

La maggior parte delle lezioni CoddyKit richiede circa 5–10 minuti. Ogni lezione è breve e interattiva, quindi fai progressi costanti e riprendi esattamente da dove hai lasciato su web e app.

Posso scrivere ed eseguire codice in questa lezione Secure Coding & OWASP Top 10 for Backend?

Sì. Ogni lezione Secure Coding & OWASP Top 10 for Backend include un editor di codice integrato, quindi scrivi ed esegui codice reale direttamente nel tuo browser e ricevi feedback istantaneo dall'IA — nessuna configurazione locale necessaria.

Tutte le lezioni di questo corso

  1. Integrazione della sicurezza in CI/CD (DevSecOps)
  2. Security testing (SAST, DAST, IAST)
  3. Risposta agli incidenti e disaster recovery
  4. Threat intelligence e gestione delle vulnerabilità
← Torna a Secure Coding & OWASP Top 10 for Backend