Tutorials/Vulnerability Remediation SLA Matrix

Vulnerability Remediation SLA Matrix

Document control

Field Value
Document status Active policy document
Owner Security / Operations
Approver Management
Review frequency Annual or on material change
Classification Customer-shareable

Purpose

Define target remediation timelines for vulnerability findings based on severity and risk.

Severity definitions

  • Critical: active exploitation, unauthenticated remote compromise, sensitive data exposure, or severe business impact.
  • High: likely exploitation, privilege escalation, authentication bypass, or significant data/control impact.
  • Medium: exploitable weakness with limited preconditions or contained impact.
  • Low: low-impact weakness, hardening gap, or best-practice deviation.
  • Informational: observation with no direct exploitable risk but useful for improvement.

Target timelines

Severity Target response Target remediation / mitigation
Critical 1 business day 7 calendar days or emergency mitigation
High 2 business days 15 calendar days
Medium 5 business days 30-60 calendar days
Low 10 business days Next planned hardening cycle
Informational As appropriate Backlog / improvement cycle

SLA start and stop

The clock starts when the finding is validated and assigned. It stops when remediation is deployed and retest/validation evidence is available, or when a documented exception is approved.

Exceptions

Exceptions must include reason, affected asset, compensating controls, owner, approval, expiry/review date, and residual risk.

Evidence to maintain

Finding tracker, SLA report, exception register, mitigation evidence, and retest evidence.

Need help with your workflow setup?

If you're stuck or want help applying these guides to your setup, our team can assist with configuration, customization, and workflow implementation.