Vulnerability Management: RBVM, E...
Vulnerability Management: RBVM, EPSS, CISA KEV, CVSS, Asset Discovery
Sec Guy by Sec Guy
S4 · E7
Sep 17, 2026
05:35
Episode notes

A deep dive into the vulnerability lifecycle. We cover authenticated vs. agent-based scanning, the shift from CVSS severity to EPSS probability, and how to build a Risk-Based Vulnerability Management (RBVM) program.

New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide

Timestamps:

00:00 – Intro: The Maintenance of the Fortress

01:15 – Asset Discovery: The "Step Zero"

02:30 – Scanning: Authenticated, Unauthenticated, and Agent-based

04:00 – CVSS Explained: Base, Temporal, and Environmental

05:30 – Prioritization: EPSS and the CISA KEV Catalog

07:15 – The Patch Lifecycle and Regression Testing

08:45 – Vulnerability Disclosure Programs (VDP)

10:00 – Outro and Labs (secguy.org)

Original ... 

Keywords
Comptia
SecGuy
Infosec
Cybersecurity Training
IT Certification
Cyber
Tech Podcast
Security+ SY0-701