← All 186 courses
SEC-210 Security

Vulnerability Management at Scale

Turn a scanner firehose into fixed systems. Learners build the asset inventory the whole programme depends on, prove scanning coverage instead of assuming it, and prioritise with EPSS and exploit intelligence rather than raw CVSS severity. Remediation SLAs, a defensible exception workflow and patch orchestration across mixed estates close the loop, with reporting that holds up under audit.

B3Practitioner
6modules
42skill atoms
3role journeys
Curriculum

What this course covers.

6 modules, 42 named skill atoms. Expand any module to see them.

1Asset Inventory Foundations7 skill atoms
authoritative asset register across cloud, endpoint and on-premCMDB reconciliation against agent and network discoveryunmanaged and shadow asset discoveryownership and business criticality taggingephemeral cloud and container asset lifetimessoftware bill of materials and installed package inventoryinventory freshness treated as a measured control
2Scanning Coverage & Blind Spots7 skill atoms
authenticated vs unauthenticated scan fidelityagent-based vs network scanning trade-offscredential failures silently degrading resultscontainer image and registry scanningscan windows, throttling and fragile OT devicescoverage measured against the asset register, not against scan targetsfalse negative classes and how to spot them
3Scoring & Its Limits7 skill atoms
CVSS base, temporal and environmental metricswhy the base score alone misranks real riskCVSS v3.1 vs v4.0 changesvendor severity disagreement and disputed CVEscompensating controls expressed in environmental scoringseverity inflation and analyst fatiguenormalising scores across multiple scanners
4Exploit Intelligence & Prioritisation7 skill atoms
EPSS probability scores and their refresh cadenceCISA KEV as a hard prioritisation signalexploit maturity and public proof-of-concept availabilityinternet exposure and reachability analysisasset criticality as a ranking multipliera risk order that survives challenge from engineeringmeasuring reduction of the exploitable set
5SLAs, Exceptions & Risk Acceptance7 skill atoms
remediation SLAs by severity and asset criticalityclock start on detection vs on disclosureexception workflow with a named owner and hard expirycompensating control evidence behind an accepted riskescalation before an SLA breaches, not afterrisk acceptance signed at the right authority levelexception debt review cadence
6Patch Orchestration & Reporting7 skill atoms
patch rings and canary cohortsmaintenance windows and change advisory interlockimage rebake vs in-place patchingrollback plan for a bad patchthird-party and end-of-life software handlingSLA attainment, mean time to remediate and backlog age metricsaudit-ready evidence drawn from ticket and scan history
Where it fits

SEC-210 in the role journeys.

This course appears in 3 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

Security Engineer

Practitioner stage
SEC-201SEC-210SEC-402

DevSecOps Engineer

Practitioner stage
SEC-302SEC-210CL-309

GRC / Compliance Analyst

Practitioner stage
SEC-104SEC-210SEC-505

Roles this course serves

The capability ladder

This course is authored to band B3.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-210 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free