Vulnerability scans
Credentialed vs. non-credentialed
Agent-based/server-based
Criticality ranking
Active vs. passive
Security Content Automation Protocol (SCAP)
Open Vulnerability and Assessment Language (OVAL)
Common Vulnerabilities and Exposures (CVE)
Common Vulnerability Scoring System (CVSS)
Common Configuration Enumeration (CCE)
Self-assessment vs. third-party vendor assessment
Patch management
Advisories
Bulletins
Vendor websites
News reports