## Vulnerability Identification During the first stage in the process, the organisation becomes aware of a vulnerability that exists within their environment. This identification may come from many different sources, including: - Vulnerability scans run by the organisation or outside assessors - Penetration tests of the organisation's environment - Reports from responsible disclosure or bug bounty programs - Results from system and process audits ## Vulnerability Analysis After identifying a possible vulnerability in the organisation's environment, cybersecurity professionals next perform an analysis of that report. This includes several core tasks: - Confirming that the vulnerability exists and it is not the result of a false positive error - Prioritising and categorising the vulnerability using tools such as CVSS and CVE that provide an external assessment of the vulnerability. - Supplementing