OPS-02Secure Operations

Vulnerability management

Vulnerabilities are discovered, prioritised by risk and remediated within stated timeframes, with exceptions recorded.

Why it exists

Discovery without a clock is a backlog.

What usually proves it

Scan output, remediation SLAs, exception records.

Smaller organizations

Monthly scan, critical fixed in days, documented.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC7.1
  • Fully addressedISO/IEC 27001 Annex A · A.8.8
  • Fully addressedNIST Cybersecurity Framework · ID.RA-01
  • Fully addressedPCI DSS · 11.3
  • Partially addressedHIPAA Security Rule · 164.308(a)(1)(ii)(B) — Through risk management.
  • Partially addressedGDPR · Art. 32(1)(d) — Regular testing of measures.
  • Partially addressedEU AI Act · Art. 15 — Robustness and cybersecurity of the system.
  • Partially addressedNIST AI Risk Management Framework · MEASURE 2.7 — Security and resilience testing.