{"id":162714,"date":"2026-08-14T10:23:47","date_gmt":"2026-08-14T14:23:47","guid":{"rendered":"https:\/\/www.bu.edu\/tech\/?page_id=162714"},"modified":"2026-08-14T10:35:48","modified_gmt":"2026-08-14T14:35:48","slug":"vulnerability-management-procedure","status":"publish","type":"page","link":"https:\/\/www.bu.edu\/tech\/about\/policies\/vulnerability-management-procedure\/","title":{"rendered":"Vulnerability Management Procedure"},"content":{"rendered":"<p>Effective: May 12, 2026<\/p>\n<h2><a name=\"_Toc507588572\"><\/a>Purpose and Scope<\/h2>\n<p>This procedure extends the Vulnerability Management Standard in the Data Protection Standards.<\/p>\n<h2><a name=\"_Toc507588573\"><\/a><a name=\"_Toc507588574\"><\/a>Program Management<\/h2>\n<p>Vulnerability\u00a0Management is a\u00a0Service Component\u00a0of\u00a0the\u00a0Server Security\u00a0Services\u00a0Client Service.\u00a0 The Director\u00a0of Information Security is the Service\u00a0Owner\u00a0and\u00a0is\u00a0responsible for service delivery. The Director\u00a0shall\u00a0appoint a Service Component Manager and a Vulnerability Manager as defined in this document. A combination of these roles may be held by the same person.<\/p>\n<h2><a name=\"_Toc507588575\"><\/a><a name=\"_Toc507588576\"><\/a>Procedures<\/h2>\n<p>The Chief Information Security Officer shall charter a Vulnerability Advisory Board (VAB) to implement the Vulnerability Management Program.\u00a0 The VAB will be led by the Vulnerability Manager.<\/p>\n<p>The VAB will meet regularly to review and evaluate patch and vulnerability scan data, assign priorities to vulnerabilities, and determine what remediation projects will be assigned and executed for the upcoming days\/month(s).<\/p>\n<p>Emergency VAB meetings will take place on an as needed basis to deal with urgent threats.<\/p>\n<p>The VAB creates and assigns remediation projects, reports on progress in remediating vulnerabilities, escalates issues and risks relating to non-remediated vulnerabilities, and authorizes Systems Administration to assign patch and reboot schedules on behalf of unresponsive system owners.<\/p>\n<h3><a name=\"_Toc507588577\"><\/a>Remediation Target Priorities<\/h3>\n<p>The following table defines how remediation priorities will be assigned and the target resolution timeframe for vulnerabilities in each priority\u00a0rank.\u00a0 The use of \u201cdays\u201d versus \u201cbusiness days\u201d in expressing times is significant \u2013 not all vulnerabilities can wait until the start of the next business day.<\/p>\n<table width=\"749\">\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"127\"><u>Priority Rank<\/u><\/td>\n<td width=\"167\"><u>Definition<\/u><\/td>\n<td colspan=\"2\" width=\"178\"><u>Initial Assignment<\/u><\/td>\n<td colspan=\"2\" width=\"177\"><u>Target Resolution<\/u><\/td>\n<\/tr>\n<tr>\n<td width=\"108\">P1<\/td>\n<td colspan=\"3\" width=\"203\">Vulnerability that is remotely exploitable with no compensating controls<\/td>\n<td colspan=\"2\" width=\"177\">1 day<\/td>\n<td width=\"161\">2 days<\/td>\n<\/tr>\n<tr>\n<td width=\"108\">P2<\/td>\n<td colspan=\"3\" width=\"203\">Vulnerability that is remotely exploitable with compensating controls<\/td>\n<td colspan=\"2\" width=\"177\">2 business days<\/td>\n<td width=\"161\">1 week<\/td>\n<\/tr>\n<tr>\n<td width=\"108\">P3<\/td>\n<td colspan=\"3\" width=\"203\">Vulnerability that is not remotely exploitable<\/td>\n<td colspan=\"2\" width=\"177\">routine patching<\/td>\n<td width=\"161\">45-60 days<\/td>\n<\/tr>\n<tr>\n<td width=\"108\">P4<\/td>\n<td colspan=\"3\" width=\"203\">Vulnerability that cannot immediately be exploited.<\/td>\n<td colspan=\"2\" width=\"177\">routine patching<\/td>\n<td width=\"161\">60 days<\/td>\n<\/tr>\n<tr>\n<td width=\"125\"><\/td>\n<td width=\"22\"><\/td>\n<td width=\"193\"><\/td>\n<td width=\"20\"><\/td>\n<td width=\"186\"><\/td>\n<td width=\"18\"><\/td>\n<td width=\"186\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>It may be necessary to further prioritize hosts within\u00a0the\u00a0priority\u00a0rankings above. \u00a0Hosts should be prioritized according to Data Classification with hosts containing Restricted Use data remediated first. \u00a0Note that some compliance\u00a0requirements like PCI\u00a0might dictate shorter resolution time frames.\u00a0Once Restricted Use systems are secured the remainder should be remediated according to risk, considering the impact of a breach and the likelihood of compromise. \u00a0The use of private network\u00a0addressing,\u00a0and other compensating controls\u00a0may\u00a0be used to prioritize the list. \u00a0 The VAB may provide additional guidance on a case-by-case basis.<\/p>\n<h3>Exceptions<\/h3>\n<p>Devices not in compliance with the Vulnerability Management Standard or this procedure must complete the risk acceptance process or be disconnected from the network.<\/p>\n<p>As general rules:<\/p>\n<ul>\n<li>Exceptions will be granted as narrowly as possible, and for limited time.<\/li>\n<li>Devices that cannot be scanned are not secure enough for connection to the network.<\/li>\n<li>Private networking helps reduce exposure but does not remediate vulnerabilities. Use of a private network does not exempt you from the requirements for vulnerability management.<a name=\"_Toc507588578\"><\/a><a name=\"_Toc507588579\"><\/a><\/li>\n<\/ul>\n<h2><a name=\"_Toc507588580\"><\/a>References<\/h2>\n<p><a href=\"https:\/\/www.bu.edu\/tech\/services\/security\/server\/vulnerability-management\/\">Vulnerability Management Service Page<\/a><\/p>\n<p><a href=\"https:\/\/www.bu.edu\/policies\/minimum-security-standards\/\">Minimum Security Standards<\/a><\/p>\n<p><a href=\"https:\/\/www.bu.edu\/policies\/cybersecurity-training-compliance-and-remediation\/\">Cybersecurity Training, Compliance, and Remediation<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Effective: May 12, 2026 Purpose and Scope This procedure extends the Vulnerability Management Standard in the Data Protection Standards. Program Management Vulnerability\u00a0Management is a\u00a0Service Component\u00a0of\u00a0the\u00a0Server Security\u00a0Services\u00a0Client Service.\u00a0 The Director\u00a0of Information Security is the Service\u00a0Owner\u00a0and\u00a0is\u00a0responsible for service delivery. The Director\u00a0shall\u00a0appoint a Service Component Manager and a Vulnerability Manager as defined in this document. A combination of&#8230;<\/p>\n","protected":false},"author":4352,"featured_media":0,"parent":21310,"menu_order":1,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/162714"}],"collection":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/users\/4352"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/comments?post=162714"}],"version-history":[{"count":2,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/162714\/revisions"}],"predecessor-version":[{"id":162716,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/162714\/revisions\/162716"}],"up":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/21310"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/media?parent=162714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}