Vulnerabilities can stem from software bugs, misconfiguration, outdated components, or design flaws. Vulnerability management, identifying, assessing, prioritizing, and remediating vulnerabilities, is a critical complement to detection and response operations. The relationship between known vulnerabilities in an environment and active threats detected by the SOC is increasingly important: a CVE being actively exploited in the wild on a crown jewel asset is fundamentally different in priority from one on an isolated system.