Hi community!
I would greatly appreciate some guidance on crafting a vulnerability management program (including policy doc) that extends beyond "run Nessus and do what it recommends." 😊 My current experience is limited to drafting a patch management policy and scheduling cadence meetings to ensure we're doing what we said we would do, but nothing "deeper"/more structured.
Any assistance in this endeavor would be much appreciated!