Effective: May 12, 2026
Purpose and Scope
This procedure extends the Vulnerability Management Standard in the Data Protection Standards.
Program Management
Vulnerability Management is a Service Component of the Server Security Services Client Service. The Director of Information Security is the Service Owner and is responsible for service delivery. The Director shall appoint a Service Component Manager and a Vulnerability Manager as defined in this document. A combination of these roles may be held by the same person.
Procedures
The Chief Information Security Officer shall charter a Vulnerability Advisory Board (VAB) to implement the Vulnerability Management Program. The VAB will be led by the Vulnerability Manager.
The VAB will meet regularly to review and evaluate patch and vulnerability scan data, assign priorities to vulnerabilities, and determine what remediation projects will be assigned and executed for the upcoming days/month(s).
Emergency VAB meetings will take place on an as needed basis to deal with urgent threats.
The VAB creates and assigns remediation projects, reports on progress in remediating vulnerabilities, escalates issues and risks relating to non-remediated vulnerabilities, and authorizes Systems Administration to assign patch and reboot schedules on behalf of unresponsive system owners.
Remediation Target Priorities
The following table defines how remediation priorities will be assigned and the target resolution timeframe for vulnerabilities in each priority rank. The use of “days” versus “business days” in expressing times is significant – not all vulnerabilities can wait until the start of the next business day.
| Priority Rank | Definition | Initial Assignment | Target Resolution | |||
| P1 | Vulnerability that is remotely exploitable with no compensating controls | 1 day | 2 days | |||
| P2 | Vulnerability that is remotely exploitable with compensating controls | 2 business days | 1 week | |||
| P3 | Vulnerability that is not remotely exploitable | routine patching | 45-60 days | |||
| P4 | Vulnerability that cannot immediately be exploited. | routine patching | 60 days | |||
It may be necessary to further prioritize hosts within the priority rankings above. Hosts should be prioritized according to Data Classification with hosts containing Restricted Use data remediated first. Note that some compliance requirements like PCI might dictate shorter resolution time frames. Once Restricted Use systems are secured the remainder should be remediated according to risk, considering the impact of a breach and the likelihood of compromise. The use of private network addressing, and other compensating controls may be used to prioritize the list. The VAB may provide additional guidance on a case-by-case basis.
Exceptions
Devices not in compliance with the Vulnerability Management Standard or this procedure must complete the risk acceptance process or be disconnected from the network.
As general rules:
- Exceptions will be granted as narrowly as possible, and for limited time.
- Devices that cannot be scanned are not secure enough for connection to the network.
- Private networking helps reduce exposure but does not remediate vulnerabilities. Use of a private network does not exempt you from the requirements for vulnerability management.
