A Lifecycle-Oriented Architecture for Vulnerability Management and Security Assessment Planning in CMDB-Driven Environments
Enterprise vulnerability management increasingly relies on heterogeneous security platforms that provide complementary but fragmented views of the organizational security posture. Transforming this information into coordinated security assessment activities requires the integration of vulnerability intelligence, enterprise asset context, organizational policies, historical assessment knowledge, and operational workflows. This paper presents a lifecycle-oriented architecture that addresses this integration problem without replacing the existing security ecosystem. The architecture separates vulnerability intelligence acquisition and consolidation from persistent assessment planning and lifecycle management through two complementary services: the Security Automation Service (SAS) and the Resilience Testing Framework (RTF). The SAS acquires vulnerability information from heterogeneous security platforms, normalizes and correlates the resulting observations, and enriches them with enterprise context retrieved from the Configuration Management Database (CMDB). The RTF combines this contextualized intelligence with organizational policies and persistent assessment knowledge to support assessment prioritization, strategy selection, scheduling, operational synchronization, and lifecycle evolution. A functional prototype was deployed in an enterprise financial market infrastructure environment and observed for approximately one year. The industrial case study covered approximately 1150 assets and eight integrated security platforms, with 756 assessment plans processed during the observation period. Of these, 612 plans were reused, 19 were updated, and 125 were newly created. Manual validation of 50 sampled consolidation cases resulted in 93.5% precision, 96.7% recall, and 95.1% F1-score. A separate load test under the tested conditions resulted in average response times of approximately 3 ms for the SAS and 4 ms for the RTF, with no observed request errors. The results provide evidence of the feasibility and observed operational behaviour of the proposed architecture in the evaluated environment, while the validation of vulnerability consolidation is limited to the sampled cases and the correctness of planning decisions and general scalability remain independently unvalidated.
Authors
- Luís Nogueira (ORCID: https://orcid.org/0000-0002-7094-0458)
- André Duarte (ORCID: https://orcid.org/0009-0003-1468-4212)
Institutions
- Universidade do Porto (PT)
- Centro de Investigação em Sistemas Computacionais Embebidos e de Tempo-Real
- Polytechnic Institute of Porto (PT)
Publication Details
- Journal
- Computers
- Published
- 2026-10-07
- DOI
- https://doi.org/10.3390/computers15100681
- Primary Topic
- Information and Cyber Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00