# Keep finding and fixing vulnerabilities

Taiga Learning · Worksheet
https://taiga.training/en/lessons/vulnerability-management/

Use fictional or approved information. Do not put secrets in this worksheet.

## Learning objectives
- Explain why unchanged software needs continuing security review.
- Match different scan types to their coverage and limitations.
- Track a finding through prioritization, correction, deployment, and verification.

## Exercise
Use the fictional timeline in this lesson. Identify where the team could incorrectly declare success. Define the scan triggers, failure alert, remediation owner, release verification, and temporary-exception expiry.

## Your response
- Scenario and scope:
- Assumptions and open questions:
- Proposed answer or decision, with reasons:

## Verify your response
| Claim or criterion | Evidence or test | Result or gap | Owner |
| --- | --- | --- | --- |
| | | | |
| | | | |
| | | | |

## Next action
- Action, owner, and date:
- When will you review this response?

## Principle to retain
A scan is a dated observation. Security maintenance needs an owner and a complete correction process for every supported production version.

## Sources
- [NIST: Secure Software Development Framework](https://csrc.nist.gov/pubs/sp/800/218/final)
- [CISA: Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [Taiga docs: Maintaining](https://docs.tai.ga/operate/maintaining/)

This worksheet supports learning. Completing it does not itself authorize a production change.
