# Vulnerability and patch management policy

Source: https://aestech.com.au/policy-templates/#vulnerability-and-patch-management-policy
Markdown URL: https://aestech.com.au/policy-templates/vulnerability-and-patch-management-policy.md

Use for ISO 27001 A.8.8, A.8.19, A.8.32, SOC 2 Security, and PCI DSS requirements 6 and 11.

Frameworks: ISO 27001, SOC 2, PCI DSS

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how technical vulnerabilities are identified, assessed, prioritised and remediated, and how security patches are applied across company systems, in order to reduce the risk of exploitation.

2. Scope
This policy applies to all production and corporate systems, servers, endpoints, cloud services, containers, network devices, applications and third-party software components used by the company.

3. Policy statements
- Vulnerability scanning must be performed regularly on internal and external systems.
- Discovered vulnerabilities must be assigned a severity using a recognised scoring method such as CVSS.
- Remediation timeframes apply from the date a vulnerability is confirmed:
  - Critical: within [7] days.
  - High: within [30] days.
  - Medium: within [90] days.
  - Low: at the next scheduled maintenance.
- Security patches must be tested where practical and applied within the remediation timeframe for their severity.
- Where a vulnerability cannot be remediated in time, a compensating control and a documented, time-bound exception must be approved.
- Internet-facing systems and systems handling regulated data are prioritised.
- Penetration testing must be performed at least annually and after significant changes.
- Software components and dependencies must be tracked, and end-of-life software must be replaced or isolated.

4. Roles and responsibilities
- The [Security Lead] owns the vulnerability management programme and approves exceptions.
- System and application owners remediate vulnerabilities in their systems within the required timeframe.
- IT applies operating system and infrastructure patches.
- Developers update vulnerable application dependencies.

5. Procedures
- Run authenticated vulnerability scans on a [weekly or monthly] cadence and external scans regularly.
- Triage findings, deduplicate, assign severity and create remediation tickets.
- Track remediation to closure against the required timeframes.
- Record and review exceptions with compensating controls.
- Commission annual penetration testing and remediate findings.

6. Evidence and records
Keep scan reports, remediation tickets and timestamps, patch records, penetration test reports, exception approvals, software inventory and end-of-life tracking.

7. Review cadence
This policy is reviewed at least annually and after significant changes to the environment or threat landscape.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md