Skip to main content

SID-OPS-04 — Vulnerability Management

PropertyValue
Statusto_do
Ownerplatform
Categoryprocess
CSF Functiondetect
GroupOperational Controls

Description

Formal vulnerability management process: intake, triage, SLAs, patching, and disclosure policy. SBOM monitoring for third-party dependencies. Automated dependency scanning (Dependabot/Snyk) in CI/CD. Management of technical vulnerabilities per defined remediation timelines.

Operator Responsibility

Establish vulnerability management process with SLAs, deploy endpoint protection, and manage production configuration scanning.

Source References

Audit Findings

FindingSeverityStatus
EN-S-3 — Partial SDLC, change management and vulnerability scanningmediumin progress
ISO-O-12 — Partial supply chain securitymediumopen
ISO-T-6 — Partial vulnerability and malware protectionmediumopen