Vulnerability management is the process of addressing vulnerabilities. Vulnerabilities can be addressed in a number of ways. They can be remediated, mandated, or accepted. A vulnerability management program specifies how to address the vulnerabilities, in what order, and in what timeline.
Vulnerabilities are weaknesses in the system that can allow for exploitation. A good vulnerability management plan can help ensure that the vulnerabilities are addressed before they are exploited.
A copy of the vulnerability management plan may be requested to show that there is a program. Reports from vulnerability scanners, change requests, or other documents showing that vulnerabilities are being detected and addressed may be requested to show that the plan is being followed and is effective.