Vulnerability Management Policy
Document control
| Field | Value |
|---|---|
| Document status | Active policy document |
| Owner | Security / Operations |
| Approver | Management |
| Review frequency | Annual or on material change |
| Classification | Customer-shareable |
Purpose
Define how vulnerabilities are identified, triaged, remediated, validated, and communicated.
Sources of findings
Findings may come from internal reviews, VAPT/VA, SAST, DAST, software composition analysis, dependency alerts, customer reports, framework advisories, vendor advisories, cloud advisories, incident analysis, and code review.
Triage process
Each finding must be reviewed for reproducibility, affected asset, severity, exploitability, data impact, user impact, ownership, and whether it is application, framework, configuration, infrastructure, vendor, or false-positive related.
Severity and prioritization
Critical and High vulnerabilities affecting exposed or sensitive systems must be prioritized. Medium and Low findings should be tracked and addressed according to the remediation SLA matrix and business risk.
Remediation workflow
- Create a tracked issue/ticket.
- Assign owner and severity.
- Define fix plan or compensating control.
- Implement change through code/configuration/process update.
- Review and test the fix.
- Deploy through change control.
- Retest and attach closure evidence.
Customer communication
Customer-impacting Critical/High risks should be communicated through the agreed support/escalation channel with impact, mitigation, target date, and closure evidence where contractually required.
Evidence to maintain
Vulnerability tracker, scan reports, VAPT reports, remediation tickets, pull/merge requests, deployment evidence, retest evidence, and exception approvals.