## Vulnerability Identification
During the first stage in the process, the organisation becomes aware of a vulnerability that exists within their environment. This identification may come from many different sources, including:
- Vulnerability scans run by the organisation or outside assessors
- Penetration tests of the organisation's environment
- Reports from responsible disclosure or bug bounty programs
- Results from system and process audits
## Vulnerability Analysis
After identifying a possible vulnerability in the organisation's environment, cybersecurity professionals next perform an analysis of that report. This includes several core tasks:
- Confirming that the vulnerability exists and it is not the result of a false positive error
- Prioritising and categorising the vulnerability using tools such as CVSS and CVE that provide an external assessment of the vulnerability.
- Supplementing