Âé¶¹ÊÓÆµ¹ÙÍø

Search Menu Button Menu Button
[wpdreams_ajaxsearchpro id=2]

I. Purpose

The purpose of the Vulnerability Management security policy is to minimize the risk that Âé¶¹ÊÓÆµ¹ÙÍø’s resources are compromised from an attack. Decreasing the time that a resource is vulnerable minimizes the risk of compromise.

Policy Supported

Supports:

  • Cybersecurity and Infrastructure Security Agency (CISA) Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk
  • National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) ID.RA
  • National Institute of Standards and Technology (NIST) Special Publication (SP) 800-40
  • National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53

II. Description

All hosts (servers, computers, and network devices) that are listening on or have open IP ports accessible from the Internet must be scanned for vulnerabilities monthly.

If any vulnerabilities known by the scanner at the time of scan are found, the host’s administrator will be responsible for remediating the vulnerabilities on their host(s). Vulnerabilities must be remediated within the time listed in the Remediation Timelines table after initial detection. If the vulnerabilities are not remediated within the specified time, either an exception at the Vice Presidential level must be approved, or the host will be blocked from the Internet

Before any request for a firewall security policy is configured, the internal host must be scanned, vulnerabilities remediated, and added to the list of hosts that are scanned automatically.

Publicly Exposed?In CISA’s Known Exploited Vulnerabilities (KEV) CatalogAutomatable by Adversary?Technical ImpactTimeline (Calendar Days) for Remediation
1YesYesYesTotal Control3 days
2YesYesYesPartial Control3 days
3YesYesNoTotal Control3 days
4YesYesNoPartial Control14 days
5YesNoYesTotal Control3 days
6YesNoYesPartial Control14 days
7YesNoNoTotal Control14 days
8YesNoNoPartial Control60 days
9NoYesYesTotal Control3 days
10NoYesYesPartial Control14 days
11NoYesNoTotal Control14 days
12NoYesNoPartial Control14 days
13NoNoYesTotal Control60 days
14NoNoYesPartial Control60 days
15NoNoNoTotal ControlFix on system upgrade
16NoNoNoPartial ControlFix on system upgrade

III. Scope

This policy pertains to all hosts (servers, computers, and network devices) on Âé¶¹ÊÓÆµ¹ÙÍø’s network that are listening on or have open IP ports accessible from the Internet.

Date Approved   
1/29/2010   
Dates Revised   
6/17/2019 7/9/2026 7/17/2026 
Dates Reviewed   
 7/9/2026