Skip to content
Review

Transition from Periodic Security Assessments to Continuous Vulnerability Management Frameworks

Aug 2026 · International Research Journal of Advanced Engineering and Technology · 0 citations

TL;DR

The article examines the transition from scheduled security assessments to continuous vulnerability management frameworks in enterprise environments with unstable external exposure and explains why periodic assessment loses completeness when asset states change between review cycles.

Abstract

The article examines the transition from scheduled security assessments to continuous vulnerability management frameworks in enterprise environments with unstable external exposure. Cloud services, SaaS use, short-lived assets, and unmanaged public interfaces reduce the decision value of annual or project-based testing. The novelty of the study lies in combining external attack surface management, continuous penetration testing, vulnerability intelligence, and remediation verification into a single operating model. The aim is to explain why periodic assessment loses completeness when asset states change between review cycles. The method combines source analysis, comparative analysis, conceptual synthesis, and typological classification. The source base covers academic papers, public vulnerability intelligence instruments, official guidance, and industry definitions of external attack surface management. The study identifies three shifts: from snapshot testing to continuous discovery, from severity ranking to exploitation-aware prioritisation, and from automated scanning to expert-verified remediation. The model helps engineering and security teams design measurable programs to reduce exposure.

View source

Similar papers

Preprint Sep 2026

Measuring the Security of the Evolving Software Supply Chain: a Research Agenda

Software supply chain security has become increasingly critical due to the widespread reliance on third-party dependencies and the growing attack surface of modern software ecosystems. However, existing quantitative, measurement-based analysis and vulnerability management approaches remain largely fragmented and ecosys...

Sarah Meriem Ourari · 0 citations
Review Open access Jul 2026

Penetration Testing in System Security

This review's results show that penetration testing is an important part of improving cybersecurity because it helps identify weaknesses before they become problems and reduces risk.

Shruti Agarwal, S. Sharma · 1 citation
Preprint Aug 2026

Orchestrated Vulnerability Management for Heterogeneous Networks: Adaptive Two-Stage Vulnerability Assessment, Context-Aware Risk Prioritization, and Automated Mitigation

Heterogeneous networks pose significant security challenges due to device diversity, fragile operating conditions, and heterogeneous firmware and service configurations. Traditional vulnerability management often relies on static scanning and severity-based prioritization, overlooking exploitation likelihood and asset...

R. Lopes, José Moura, R. Marinheiro · 0 citations
Review Open access Sep 2026

Advanced study of Security Management in actual European Aviation

This paper develops a technical-scientific study of modern European aviation security management and complements the policy review with a numerical simulation framework in MATLAB. The simulation is not a classified or operational attack model; it is a decision-support model for comparing security management strategies...

Unknown authors · 0 citations
Open access Aug 2026

Comparative Effectiveness of OWASP WSTG and Top Ten in Web Security Audits

The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework, which enhances audit consistency, precision, and efficiency in evaluating modern web environments.

Moch Wahyu Sampurno Utomo, H. Wahanani, Achmad Junaidi · 0 citations
Aug 2026

ARAMIS: A unified and scalable methodology for industrial cyber security risk assessment

The paper details the five-module structure of ARAMIS, its unique multilayered modelling of operational scenarios and its algorithmic approach to calculating security levels target (SL-T), and discusses the implementation of the methodology within the Fence risk management tool to ensure seamless reproducibility and kn...

Serge Benoliel, Florence Foudrain · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.