
Practical Vulnerability Management
A Strategic Approach to Managing Cyber Risk
A working security engineer's guide to building a vulnerability management program from open-source tools on a real budget, covering scanning, prioritization, automation, and reporting end to end.
As an Amazon Associate we earn from qualifying purchases. The link above is sponsored.
- Authors
- Andrew Magnusson
- Published
- 2020
- Publisher
- No Starch Press
- Pages
- 192
- Language
- English
Read this if
Security engineers and small-team leads who need to stand up a vulnerability management practice without an enterprise tooling budget. Magnusson writes from inside real SOC2-compliance and firewall-to-consulting experience, not from a vendor's playbook.
Skip this if
Readers at organizations with mature, well-staffed vulnerability management already in place, or who want deep technical exploitation detail; this is program and process design, not an exploitation manual.
Key takeaways
- Treats vulnerability management as a program to run, not a scan to schedule — intelligence, prioritization, and reporting matter as much as the scanner.
- Built entirely around free and open-source tooling, so the advice works on a startup or small-team budget, not just an enterprise one.
- Prioritization gets real treatment: not every finding deserves the same response, and the book gives a concrete framework for triage.
Notes
A practical complement to this catalog's broader defensive titles (Security Engineering, Building Secure and Reliable Systems) — narrower in scope but immediately actionable for a team standing up its first real vulnerability management process. Pairs well with Practical IoT Hacking or any of the offensive-technique books for understanding what the scanner is actually looking for.
What to read before
What to read before Practical Vulnerability Management →Beginner · 2019
Foundations of Information Security
Jason Andress' compact tour of the field: confidentiality / integrity / availability, identification and authentication, network and OS controls, written for newcomers and adjacent disciplines.
Beginner · 2021
How Cybersecurity Really Works
Sam Grubb's gentle, exercise-driven introduction for non-specialists who need a working mental model of attacker behaviour and basic defence.
Intermediate · 2022
Cybersécurité
Solange Ghernaouti's broad academic survey of cybersecurity — risk analysis, governance, technical and legal dimensions — the standard French university reference, now in its 7th edition.
What to read next
What to read after Practical Vulnerability Management →Advanced · 2013
Sécurité informatique
A principles-first treatment of information security for DSI, RSSI and sysadmins — architecture, cryptography, network defence and security policy — from two veteran French practitioners.
Advanced · 2015
Sécurité informatique
A rigorous academic course on the foundations of security — cryptography, authentication, access control — with corrected exercises, from a team of well-known French and Swiss cryptographers.
Advanced · 2023
Exercices et problèmes de cryptographie
A rigorous problem book for learning cryptography — over 150 corrected exercises with course summaries, for L3/master/engineering students — by a French academic cryptographer.
Explore similar books
Alternatives to Practical Vulnerability Management →Beginner · 2021
How Cybersecurity Really Works
Sam Grubb's gentle, exercise-driven introduction for non-specialists who need a working mental model of attacker behaviour and basic defence.
Beginner · 2019
Foundations of Information Security
Jason Andress' compact tour of the field: confidentiality / integrity / availability, identification and authentication, network and OS controls, written for newcomers and adjacent disciplines.
Intermediate · 2022
Cybersécurité
Solange Ghernaouti's broad academic survey of cybersecurity — risk analysis, governance, technical and legal dimensions — the standard French university reference, now in its 7th edition.