Identification should state that each vulnerability will have its own unique set of preventions and protections, and should include, but not be limited to, the following:
- Network protection is often the initial line of defense (e.g., authentication, firewalls, end point protection software, intrusion detection system [IDS]/intrusion prevention system [IPS], vulnerability scanners).
- Operating systems and applications are critical to reducing vulnerabilities. Identification of systems maintenance measures that assist in system protection include, but should not be limited to, system updates and audits.
- User training will make the users aware of the potential threats due to their actions.
- Cyber hygiene includes user training to make users aware of potential threats due to their actions and includes strong and not-reused passwords, regular software updates, etc.