OPS-02Secure Operations
Vulnerability management
Vulnerabilities are discovered, prioritised by risk and remediated within stated timeframes, with exceptions recorded.
Why it exists
Discovery without a clock is a backlog.
What usually proves it
Scan output, remediation SLAs, exception records.
Smaller organizations
Monthly scan, critical fixed in days, documented.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC7.1
- Fully addressedISO/IEC 27001 Annex A · A.8.8
- Fully addressedNIST Cybersecurity Framework · ID.RA-01
- Fully addressedPCI DSS · 11.3
- Partially addressedHIPAA Security Rule · 164.308(a)(1)(ii)(B) — Through risk management.
- Partially addressedGDPR · Art. 32(1)(d) — Regular testing of measures.
- Partially addressedEU AI Act · Art. 15 — Robustness and cybersecurity of the system.
- Partially addressedNIST AI Risk Management Framework · MEASURE 2.7 — Security and resilience testing.