This document discusses strategies for improving the effectiveness of vulnerability assessment programs in large organizations. It recommends improving communication about the program, using change and enterprise management processes, strategically placing network assessment tools, tuning vulnerability assessment policies, and automating assessments. It also discusses managing vulnerability assessment data through remediation, reporting, weighing risks, and verification processes. Finally, it reviews several new tools that take a full lifecycle approach to vulnerability management. Implementing these recommendations and tools can help vulnerability assessment programs provide more value by reducing their impact on resources and demonstrating real risk reduction.