Effective: May 12, 2026

Purpose and Scope

This procedure extends the Vulnerability Management Standard in the Data Protection Standards.

Program Management

Vulnerability Management is a Service Component of the Server Security Services Client Service.  The Director of Information Security is the Service Owner and is responsible for service delivery. The Director shall appoint a Service Component Manager and a Vulnerability Manager as defined in this document. A combination of these roles may be held by the same person.

Procedures

The Chief Information Security Officer shall charter a Vulnerability Advisory Board (VAB) to implement the Vulnerability Management Program.  The VAB will be led by the Vulnerability Manager.

The VAB will meet regularly to review and evaluate patch and vulnerability scan data, assign priorities to vulnerabilities, and determine what remediation projects will be assigned and executed for the upcoming days/month(s).

Emergency VAB meetings will take place on an as needed basis to deal with urgent threats.

The VAB creates and assigns remediation projects, reports on progress in remediating vulnerabilities, escalates issues and risks relating to non-remediated vulnerabilities, and authorizes Systems Administration to assign patch and reboot schedules on behalf of unresponsive system owners.

Remediation Target Priorities

The following table defines how remediation priorities will be assigned and the target resolution timeframe for vulnerabilities in each priority rank.  The use of “days” versus “business days” in expressing times is significant – not all vulnerabilities can wait until the start of the next business day.

Priority Rank Definition Initial Assignment Target Resolution
P1 Vulnerability that is remotely exploitable with no compensating controls 1 day 2 days
P2 Vulnerability that is remotely exploitable with compensating controls 2 business days 1 week
P3 Vulnerability that is not remotely exploitable routine patching 45-60 days
P4 Vulnerability that cannot immediately be exploited. routine patching 60 days

 

It may be necessary to further prioritize hosts within the priority rankings above.  Hosts should be prioritized according to Data Classification with hosts containing Restricted Use data remediated first.  Note that some compliance requirements like PCI might dictate shorter resolution time frames. Once Restricted Use systems are secured the remainder should be remediated according to risk, considering the impact of a breach and the likelihood of compromise.  The use of private network addressing, and other compensating controls may be used to prioritize the list.   The VAB may provide additional guidance on a case-by-case basis.

Exceptions

Devices not in compliance with the Vulnerability Management Standard or this procedure must complete the risk acceptance process or be disconnected from the network.

As general rules:

  • Exceptions will be granted as narrowly as possible, and for limited time.
  • Devices that cannot be scanned are not secure enough for connection to the network.
  • Private networking helps reduce exposure but does not remediate vulnerabilities. Use of a private network does not exempt you from the requirements for vulnerability management.

References

Vulnerability Management Service Page

Minimum Security Standards

Cybersecurity Training, Compliance, and Remediation