Enhanced Vulnerability Management Program (EVMP)

Enhanced Vulnerability Management Program (EVMP)

Pondurance Enhanced Vulnerability Management Program (EVMP) is a managed vulnerability management service that helps organizations identify, analyze, prioritize, and address vulnerabilities across their infrastructure. EVMP combines network-based and agent-based scanning with risk-informed prioritization, ongoing tuning, vulnerability triage, and reporting for both technical and executive audiences.

Why EVMP

Traditional severity ratings can leave security teams with long lists of findings but limited guidance about where to begin. EVMP adds context to vulnerability data so teams can focus remediation efforts on exposures that are more likely to affect important assets or be exploited.

EVMP helps organizations:

  • Improve visibility across internal and external attack surfaces.
  • Find vulnerabilities on network-connected systems and supported assets that may not remain continuously connected to the corporate network.
  • Prioritize work using factors beyond severity alone, including asset criticality and exploit-related context.
  • Receive more timely insight through frequent scanning, Scope dashboards, and recurring reports.
  • Give technical teams actionable vulnerability and remediation information while providing leaders with a clear view of risk, trends, and progress.
  • Reduce the operational burden of maintaining scan configurations and reviewing results.

How the service works

1. Deploy and define coverage

Pondurance works with your team to deploy the required Network Scanner virtual machine and endpoint agent, identify scan targets, recognize critical assets, and establish an appropriate schedule. Network Scanner VM downloads and deployment resources are made available through Scope.

2. Scan internal and external assets

EVMP uses complementary collection methods:

  • Network-based scanning assesses designated internal and external targets.
  • Agent-based scanning provides system-level visibility and supports coverage for assets that are not always connected to the corporate network.

The standard service supports daily agent-based scanning and bi-weekly network-based scanning of internal and external targets, subject to the agreed scope and schedule.

3. Prioritize meaningful risk

Findings are organized using Pondurance prioritization capabilities, which consider vulnerability severity, asset criticality, and exploit-related context. Asset inventory information collected through the service contributes context to the analysis process. This helps teams direct limited remediation resources toward issues with the greatest potential impact instead of relying on severity scores alone.

4. Triage and tune findings

Pondurance reviews and categorizes vulnerabilities based on client feedback, including remediated findings, false positives, and accepted alternative controls. Scan profiles are maintained and tuned to support useful visibility while minimizing operational impact.

5. Monitor and act in Scope

Scope provides a centralized customer workspace for EVMP. Customers can review vulnerabilities, remediation information, and asset inventory; use metrics dashboards to understand exposure and trends; and export findings on demand for further analysis or operational workflows.

6. Report and improve

Detailed vulnerability results are delivered in CSV format monthly or in alignment with the agreed scanning schedule. A monthly Executive Report in Scope summarizes vulnerabilities, trends, recommendations, and remediation activity for decision-makers.

Core features

Feature What it provides Customer value
Network-based scanning Assessment of designated internal and external targets Broad visibility across network-accessible infrastructure
Agent-based scanning Local, system-level visibility on supported assets Deeper insight and coverage for intermittently connected systems
Risk-informed prioritization Context that includes severity, asset criticality, and exploit-related factors Clearer remediation priorities and more effective use of resources
Frequent scanning Daily agent-based and bi-weekly network-based scanning under the standard schedule Faster awareness of changes in the vulnerability landscape
Vulnerability triage Categorization informed by client feedback Cleaner findings and better tracking of remediation decisions
Managed tuning Maintained plugins, scan profiles, schedules, and configuration adjustments Reduced administrative burden and lower operational disruption
Scope vulnerability and remediation views Centralized access to findings and remediation information A clearer path from identification to action
Scope asset inventory A consolidated view of assets observed through the service Better asset visibility and additional context for vulnerability analysis
Scope metrics dashboards Visual summaries of vulnerability exposure, trends, and progress Easier monitoring and communication across technical and leadership teams
On-demand exports The ability to export vulnerability findings from Scope Flexible analysis, sharing, and workflow support
Network Scanner VM downloads Access to Network Scanner deployment resources through Scope A more direct deployment experience
Technical reporting Recurring detailed findings in CSV format Actionable information for security and IT teams
Executive reporting Monthly summary of vulnerabilities, trends, recommendations, and remediation activity Clear communication of risk and progress to leadership

Scope and EVMP

Scope is the primary customer-facing workspace for interacting with EVMP information and resources. Within Scope, customers can:

  • Review vulnerabilities identified across in-scope assets.
  • View remediation information that helps teams understand and manage follow-up work.
  • Review the asset inventory used to add context to vulnerability analysis.
  • Monitor vulnerability metrics and trends through dashboards.
  • Export vulnerability findings on demand.
  • Download the Network Scanner VM and related deployment resources.
  • Access recurring technical and executive reporting.

Together, EVMP and Scope connect vulnerability discovery, risk context, remediation visibility, and reporting in one experience.

Deployment options

EVMP supports a blended deployment model:

  • Virtual Network Scanner: A Pondurance-provided virtual machine is deployed to assess the network targets defined in scope. The VM download is available through Scope.
  • Endpoint agent: An installation package or script is used on supported assets for local scanning and added visibility.
  • Combined deployment: Network and agent-based scanning can be used together to improve coverage across traditional infrastructure, remote systems, and intermittently connected assets.

Pondurance assists with deployment and validates installation. Your organization provides the required infrastructure, connectivity, target information, and applicable change approvals.

Shared responsibilities

Pondurance responsibilities

  • Provide the Network Scanner virtual machine and agent installation resources.
  • Assist with deployment and validate scanner installation.
  • Configure targets and schedules based on client input.
  • Maintain scan profiles, plugins, and configurations.
  • Prioritize, review, categorize, and report vulnerability findings.
  • Tune scan profiles based on feedback and operational needs.
  • Make EVMP findings, dashboards, exports, asset information, and reports available through Scope.

Client responsibilities

  • Provision the Network Scanner and deploy agents as needed for the agreed scope.
  • Allow required connectivity between scanners, agents, and Pondurance management gateways.
  • Identify targets and critical assets and collaborate on the scan schedule.
  • Complete required network and change-control activities.
  • Review findings and communicate remediation, false-positive, or alternative-control decisions.

Frequently asked questions

What is EVMP?

EVMP is Pondurance’s Enhanced Vulnerability Management Program. It is a managed service that combines network and agent-based scanning, risk-informed prioritization, triage, tuning, Scope-based visibility, and recurring reporting to help organizations reduce vulnerability-related risk.

Who is EVMP designed for?

EVMP is designed for organizations that need broader visibility, more frequent scanning, deeper prioritization, and actionable reporting but may not have the time or specialized resources to manage the entire vulnerability lifecycle alone.

What value does EVMP provide beyond a vulnerability scanner?

A scanner identifies technical findings. EVMP adds managed deployment support, configuration, scheduling, maintenance, contextual prioritization, vulnerability triage, Scope dashboards, asset and remediation visibility, on-demand exports, and reporting. The result is a program focused on helping teams decide what to address first and communicate progress over time.

How is EVMP different from Pondurance’s foundational Vulnerability Management Program?

EVMP builds on the foundational service with agent-based scanning, more frequent scanning, enhanced prioritization, Scope-based visibility, and executive reporting. It is intended for organizations seeking a more comprehensive and proactive vulnerability management approach.

What does EVMP scan?

EVMP scans the internal and external assets included in the agreed service scope. Network scanners assess reachable targets, while agents provide local visibility on supported assets, including systems that may not stay continuously connected to the corporate network.

Does EVMP use agents, network scanners, or both?

Both. The service blends network-based and agent-based scanning. The appropriate mix depends on the environment, asset types, connectivity, and agreed coverage.

How are Network Scanners deployed?

Pondurance provides a virtual machine version of the Network Scanner through Scope and assists with deployment and validation. The client provisions the required environment and network connectivity.

How are agents deployed?

Pondurance provides the applicable agent installation resources and assists with deployment. The client installs the agent on supported in-scope assets using its normal software deployment and change-management processes.

How often are scans performed?

The standard service provides daily agent-based scanning and bi-weekly network-based scanning of internal and external targets. Actual schedules are confirmed during onboarding and may be adjusted according to the agreed scope and operational requirements.

What is Scope?

Scope is Pondurance’s customer-facing workspace for EVMP. It brings together vulnerabilities, remediation information, asset inventory, metrics dashboards, exports, reports, and Network Scanner VM downloads.

What vulnerability information is available in Scope?

Scope provides access to vulnerabilities identified through EVMP so customers can review findings and use the available risk context to guide investigation and remediation priorities.

How does Scope support remediation?

Scope provides remediation information alongside vulnerability data, helping customers understand follow-up work and track the decisions and activity that inform their current vulnerability posture. The client remains responsible for implementing changes in its environment.

Does Scope include an asset inventory?

Yes. Scope provides visibility into assets observed through the service. This inventory helps customers understand which assets are represented in EVMP and provides context used during vulnerability analysis.

What do the Scope dashboards show?

Scope metrics dashboards provide visual summaries of vulnerability exposure, trends, and remediation progress. They help technical teams monitor the program and give leaders a clearer view of risk over time.

Can findings be exported from Scope?

Yes. Vulnerability findings can be exported from Scope on demand for analysis, sharing, and use in customer workflows.

Can customers download the Network Scanner VM from Scope?

Yes. Scope provides access to the Network Scanner VM download and related resources needed for deployment.

How does EVMP prioritize vulnerabilities?

EVMP uses Pondurance prioritization capabilities to look beyond severity alone. The service considers factors such as asset criticality and exploit-related context so teams can focus on vulnerabilities with greater potential business impact.

Does the prioritization score replace professional judgment?

No. The score is a prioritization aid. It helps teams organize work, while business context, operational constraints, compensating controls, and expert review remain important to remediation decisions.

Does EVMP provide remediation guidance?

Yes. Scope and EVMP reports provide vulnerability and remediation information intended to support remediation planning. The client remains responsible for implementing changes in its environment.

How are false positives and accepted risks handled?

Pondurance reviews and categorizes findings based on client feedback, including false positives, remediated issues, and alternative controls. This helps keep reporting aligned with the client’s current risk posture.

What reports are included?

EVMP provides detailed vulnerability results in CSV format on a monthly basis or in alignment with the agreed scanning schedule. A monthly Executive Report is posted to Scope with an overview of vulnerabilities, trends, recommendations, and remediation activity.

Who are the reports intended for?

Detailed reports support security and IT teams responsible for investigation and remediation. The Executive Report gives leaders a higher-level view of exposure, priorities, trends, and progress.

Where are reports delivered?

Reports are posted to Scope. Detailed results are provided in CSV format, and the Executive Report is delivered monthly as a PDF.

What does Pondurance manage after deployment?

Pondurance manages scan configuration and scheduling, profile and plugin updates, prioritization, reporting, tuning, and vulnerability triage within the agreed service scope.

What does the client need to provide?

The client provides the scanner environment, required network access, target and critical-asset information, change approvals, agent deployment support, and feedback on findings and remediation status.

How does EVMP minimize disruption to operations?

Pondurance configures schedules and tunes scan profiles with client input. Clients identify operational constraints and complete required change controls so scans can be performed with appropriate coverage and minimal impact.

Can the service change as our environment changes?

Yes. Scan targets, schedules, and profiles can be adjusted through collaboration with Pondurance as the covered environment and operational needs evolve, subject to the service scope.

Is EVMP a compliance certification or attestation?

No. EVMP provides vulnerability visibility, prioritization, and reporting that may support security and compliance activities, but it is not itself a certification, attestation, or guarantee that all vulnerabilities will be identified or eliminated.

How do we get started?

Onboarding begins by confirming scope, identifying internal and external targets and critical assets, planning Network Scanner and agent deployment, establishing connectivity, and defining scan schedules. Pondurance then assists with deployment, validates installation, and configures the service.