55AA-021 · This is 55AA-021, week 11, session 2. It focuses on "Vulnerability management and exception workflow" and turns the weekly plan into discussable, practicable, and reviewable class artifacts.

Back to course

Vulnerability management and exception workflow: Lab, Review, and Transfer

This is 55AA-021, week 11, session 2. It focuses on "Vulnerability management and exception workflow" and turns the weekly plan into discussable, practicable, and reviewable class artifacts.

Learning Objectives

  • Explain where "Vulnerability management and exception workflow" fits in this course and what core problem it addresses.
  • Analyze a case or system related to "Vulnerability management and exception workflow" using today's method.
  • Connect the session task to the course outcome: Decompose security requirements into testable controls.
  • Complete the questions, notes, and synthesis required by workshop, exercise, and review.

Prerequisites

  • Software engineering and system-security fundamentals.
  • Have read the weekly task: Create priority, SLA, and risk-acceptance records.
  • Be able to record assumptions, evidence, risks, and questions to validate in class.

Preparation

  • Open the 55AA-021 course repository, readings, and this week's task brief.
  • Write two true/false claims or open questions about "Vulnerability management and exception workflow" before class.
  • Be ready to show questions, lab notes, or project fragments from the previous meeting.

Class Flow

0-8
Review previous conclusions

Quickly review the concept framework and unresolved questions for "Vulnerability management and exception workflow".

review
Question

When judging "Vulnerability management and exception workflow", what fact should be confirmed first?

Expected answer: First confirm the object, boundary, attacker or user capability, observable evidence, and evaluation criteria.

Follow-up: If that fact is not directly observable, what minimal experiment would you design?

Script

Opening

Today's session focuses on "Vulnerability management and exception workflow". We will not treat it as an isolated topic. We place it in the course workflow: define the object and boundary, gather evidence, and turn the result into engineering action.

Demo / Exercise

Vulnerability management and exception workflow class demo

Open the example, data, or project fragment related to "Vulnerability management and exception workflow".

Slides
Open slides placeholder
Slide 1Vulnerability management and exception workflow: Session Question
Slide 2Concept Framework
Slide 3Case Path
Video Media
Video placeholder link

Vulnerability management and exception workflow: lecture video

8-18
Lab goal and acceptance criteria

Define today's deliverable, evaluation criteria, and minimum completion line.

setup
Question

When judging "Vulnerability management and exception workflow", what fact should be confirmed first?

Expected answer: First confirm the object, boundary, attacker or user capability, observable evidence, and evaluation criteria.

Follow-up: If that fact is not directly observable, what minimal experiment would you design?

Script

Review

Return to the previous discussion. State one important conclusion in a sentence, then state one remaining uncertainty. We will carry those uncertainties into today's analysis.

Demo / Exercise

Vulnerability management and exception workflow class demo

For the weekly task "Create priority, SLA, and risk-acceptance records.", write the object, boundary, evidence, risk, and next action.

Slides
Open slides placeholder
Slide 2Concept Framework
Slide 3Case Path
Slide 4Workshop, exercise, and review
Video Media
Video placeholder link

Vulnerability management and exception workflow: lecture video

18-35
Instructor demo

Demonstrate how to turn the method into reproducible steps or a project fragment.

demo
Question

Where is the weekly task "Create priority, SLA, and risk-acceptance records." most likely to fail?

Expected answer: Common failures include unclear goals, insufficient evidence, unreproducible environment, and conclusions without process.

Follow-up: What checklist item would reveal this failure early?

Script

Guided question

Here is the first judgment question: if we know only the conclusion but not the environment, inputs, or evidence, can that conclusion guide engineering decisions? Answer yes or no first, then name your assumptions.

Demo / Exercise

Vulnerability management and exception workflow class demo

Open the example, data, or project fragment related to "Vulnerability management and exception workflow".

Slides
Open slides placeholder
Slide 3Case Path
Slide 4Workshop, exercise, and review
Slide 5After-class Deliverable
Video Media
Video placeholder link

Vulnerability management and exception workflow: lecture video

35-58
Group lab

Students execute the weekly task, record evidence, and mark failure points.

lab
Question

Where is the weekly task "Create priority, SLA, and risk-acceptance records." most likely to fail?

Expected answer: Common failures include unclear goals, insufficient evidence, unreproducible environment, and conclusions without process.

Follow-up: What checklist item would reveal this failure early?

Script

Explanation

For "Vulnerability management and exception workflow", the key is not memorizing definitions but following an analysis order: define the object, list boundaries, state who can do what, find observable evidence, and turn the conclusion into a task or test.

Demo / Exercise

Vulnerability management and exception workflow class demo

For the weekly task "Create priority, SLA, and risk-acceptance records.", write the object, boundary, evidence, risk, and next action.

Slides
Open slides placeholder
Slide 4Workshop, exercise, and review
Slide 5After-class Deliverable
Video Media
Video placeholder link

Vulnerability management and exception workflow: demo and review video

58-70
Peer review

Exchange results and check reproducibility, explanation quality, and missed risks.

review
Question

What makes a lab result reviewable by someone else?

Expected answer: It needs environment, commands, inputs, outputs, failure conditions, screenshots or logs, and explanations for anomalous results.

Follow-up: How would you write this requirement into homework or project acceptance criteria?

Script

Practice transition

Now apply that order to the weekly task: Create priority, SLA, and risk-acceptance records. Do not write only the final answer; preserve how you ruled out alternatives.

Demo / Exercise

Vulnerability management and exception workflow class demo

Open the example, data, or project fragment related to "Vulnerability management and exception workflow".

Slides
Open slides placeholder
Slide 5After-class Deliverable
Video Media
Video placeholder link

Vulnerability management and exception workflow: demo and review video

70-80
In-class revision

Revise notes, code, configuration, models, or report structure based on review feedback.

fix
Question

What makes a lab result reviewable by someone else?

Expected answer: It needs environment, commands, inputs, outputs, failure conditions, screenshots or logs, and explanations for anomalous results.

Follow-up: How would you write this requirement into homework or project acceptance criteria?

Script

Summary

Today's deliverable is not polished prose. It is a set of reviewable judgments. After class, complete the required evidence, commands, screenshots, logs, or review notes.

Demo / Exercise

Vulnerability management and exception workflow class demo

For the weekly task "Create priority, SLA, and risk-acceptance records.", write the object, boundary, evidence, risk, and next action.

Slides
Open slides placeholder
Slide 6After-class Deliverable
Video Media
Video placeholder link

Vulnerability management and exception workflow: demo and review video

80-87
Selected sharing

Select two or three groups to explain findings, tradeoffs, and next steps.

share
Question

What makes a lab result reviewable by someone else?

Expected answer: It needs environment, commands, inputs, outputs, failure conditions, screenshots or logs, and explanations for anomalous results.

Follow-up: How would you write this requirement into homework or project acceptance criteria?

Script

Summary

Today's deliverable is not polished prose. It is a set of reviewable judgments. After class, complete the required evidence, commands, screenshots, logs, or review notes.

Demo / Exercise

Vulnerability management and exception workflow class demo

Open the example, data, or project fragment related to "Vulnerability management and exception workflow".

Slides
Open slides placeholder
Slide 7After-class Deliverable
Video Media
Video placeholder link

Vulnerability management and exception workflow: demo and review video

87-90
Submission check

Confirm homework, naming conventions, evidence artifacts, and deadline.

summary
Question

What makes a lab result reviewable by someone else?

Expected answer: It needs environment, commands, inputs, outputs, failure conditions, screenshots or logs, and explanations for anomalous results.

Follow-up: How would you write this requirement into homework or project acceptance criteria?

Script

Summary

Today's deliverable is not polished prose. It is a set of reviewable judgments. After class, complete the required evidence, commands, screenshots, logs, or review notes.

Demo / Exercise

Vulnerability management and exception workflow class demo

For the weekly task "Create priority, SLA, and risk-acceptance records.", write the object, boundary, evidence, risk, and next action.

Slides
Open slides placeholder
Slide 8After-class Deliverable
Video Media
Video placeholder link

Vulnerability management and exception workflow: demo and review video

Homework

Create priority, SLA, and risk-acceptance records. Submit lab notes, review feedback, and the next improvement plan.