A Lifecycle-Oriented Architecture for Vulnerability Management and Security Assessment Planning in CMDB-Driven Environments

Enterprise vulnerability management increasingly relies on heterogeneous security platforms that provide complementary but fragmented views of the organizational security posture. Transforming this information into coordinated security assessment activities requires the integration of vulnerability intelligence, enterprise asset context, organizational policies, historical assessment knowledge, and operational workflows. This paper presents a lifecycle-oriented architecture that addresses this integration problem without replacing the existing security ecosystem. The architecture separates vulnerability intelligence acquisition and consolidation from persistent assessment planning and lifecycle management through two complementary services: the Security Automation Service (SAS) and the Resilience Testing Framework (RTF). The SAS acquires vulnerability information from heterogeneous security platforms, normalizes and correlates the resulting observations, and enriches them with enterprise context retrieved from the Configuration Management Database (CMDB). The RTF combines this contextualized intelligence with organizational policies and persistent assessment knowledge to support assessment prioritization, strategy selection, scheduling, operational synchronization, and lifecycle evolution. A functional prototype was deployed in an enterprise financial market infrastructure environment and observed for approximately one year. The industrial case study covered approximately 1150 assets and eight integrated security platforms, with 756 assessment plans processed during the observation period. Of these, 612 plans were reused, 19 were updated, and 125 were newly created. Manual validation of 50 sampled consolidation cases resulted in 93.5% precision, 96.7% recall, and 95.1% F1-score. A separate load test under the tested conditions resulted in average response times of approximately 3 ms for the SAS and 4 ms for the RTF, with no observed request errors. The results provide evidence of the feasibility and observed operational behaviour of the proposed architecture in the evaluated environment, while the validation of vulnerability consolidation is limited to the sampled cases and the correctness of planning decisions and general scalability remain independently unvalidated.

Authors

Institutions

Publication Details

Journal
Computers
Published
2026-10-07
DOI
https://doi.org/10.3390/computers15100681
Primary Topic
Information and Cyber Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

A Lifecycle-Oriented Architecture for Vulnerability Management and Security Assessment Planning in CMDB-Driven Environments

Luís Nogueira, André Duarte
Computers
Information and Cyber Security
article

A Lifecycle-Oriented Architecture for Vulnerability Management and Security Assessment Planning in CMDB-Driven Environments

Luís Nogueira, André Duarte
article en

Abstract

Enterprise vulnerability management increasingly relies on heterogeneous security platforms that provide complementary but fragmented views of the organizational security posture. Transforming this information into coordinated security assessment activities requires the integration of vulnerability intelligence, enterprise asset context, organizational policies, historical assessment knowledge, and operational workflows. This paper presents a lifecycle-oriented architecture that addresses this integration problem without replacing the existing security ecosystem. The architecture separates vulnerability intelligence acquisition and consolidation from persistent assessment planning and lifecycle management through two complementary services: the Security Automation Service (SAS) and the Resilience Testing Framework (RTF). The SAS acquires vulnerability information from heterogeneous security platforms, normalizes and correlates the resulting observations, and enriches them with enterprise context retrieved from the Configuration Management Database (CMDB). The RTF combines this contextualized intelligence with organizational policies and persistent assessment knowledge to support assessment prioritization, strategy selection, scheduling, operational synchronization, and lifecycle evolution. A functional prototype was deployed in an enterprise financial market infrastructure environment and observed for approximately one year. The industrial case study covered approximately 1150 assets and eight integrated security platforms, with 756 assessment plans processed during the observation period. Of these, 612 plans were reused, 19 were updated, and 125 were newly created. Manual validation of 50 sampled consolidation cases resulted in 93.5% precision, 96.7% recall, and 95.1% F1-score. A separate load test under the tested conditions resulted in average response times of approximately 3 ms for the SAS and 4 ms for the RTF, with no observed request errors. The results provide evidence of the feasibility and observed operational behaviour of the proposed architecture in the evaluated environment, while the validation of vulnerability consolidation is limited to the sampled cases and the correctness of planning decisions and general scalability remain independently unvalidated.

ComputersVol. 15(10)
Universidade do Porto (PT), Centro de Investigação em Sistemas Computacionais Embebidos e de Tempo-Real, Polytechnic Institute of Porto (PT)
Openalex Percentile: Top 5%
Information and Cyber Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.