Vulnerability Remediation SLA Matrix
Document control
| Field | Value |
|---|---|
| Document status | Active policy document |
| Owner | Security / Operations |
| Approver | Management |
| Review frequency | Annual or on material change |
| Classification | Customer-shareable |
Purpose
Define target remediation timelines for vulnerability findings based on severity and risk.
Severity definitions
- Critical: active exploitation, unauthenticated remote compromise, sensitive data exposure, or severe business impact.
- High: likely exploitation, privilege escalation, authentication bypass, or significant data/control impact.
- Medium: exploitable weakness with limited preconditions or contained impact.
- Low: low-impact weakness, hardening gap, or best-practice deviation.
- Informational: observation with no direct exploitable risk but useful for improvement.
Target timelines
| Severity | Target response | Target remediation / mitigation |
|---|---|---|
| Critical | 1 business day | 7 calendar days or emergency mitigation |
| High | 2 business days | 15 calendar days |
| Medium | 5 business days | 30-60 calendar days |
| Low | 10 business days | Next planned hardening cycle |
| Informational | As appropriate | Backlog / improvement cycle |
SLA start and stop
The clock starts when the finding is validated and assigned. It stops when remediation is deployed and retest/validation evidence is available, or when a documented exception is approved.
Exceptions
Exceptions must include reason, affected asset, compensating controls, owner, approval, expiry/review date, and residual risk.
Evidence to maintain
Finding tracker, SLA report, exception register, mitigation evidence, and retest evidence.