756 B
756 B
Vulnerability Management Procedure
Version: 1.1 | Owner: AppSec | Classification: Internal
SLAs
| Severity | Remediation SLA | Exceptions |
|---|---|---|
| Critical (CVSS 9–10) | 24 hours | CISO approval required |
| High (CVSS 7–8.9) | 7 days | Manager approval |
| Medium (CVSS 4–6.9) | 30 days | Standard process |
| Low (CVSS 0–3.9) | 90 days | Best effort |
Scanning schedule
- External attack surface: daily (automated, Qualys)
- Internal network: weekly
- Container images: on every CI build
- Dependencies: on every PR (Dependabot)
Exception process
Exceptions require:
- Business justification
- Compensating controls documented
- Sign-off from CISO
- Re-review in 30 days