operationsVersion 1SOC2ISO27001NIST800-171
Vulnerability Management Policy
Discovery, triage, remediation SLAs, and coordinated disclosure process.
Vulnerability Management Policy
1. Purpose
Ensures vulnerabilities in Rex Black systems, code, and dependencies are found, prioritized, and remediated on a predictable schedule.
2. Discovery sources
- Dependency scanning: Dependabot +
npm auditon every PR and weekly scheduled scans. - Static analysis: ESLint security plugin + custom rules in CI.
- Secret scanning: Gitleaks on every push; history included.
- Infrastructure scanning: Checkov / Pulumi CrossGuard on IaC changes.
- Runtime: AWS GuardDuty, AWS Inspector, AWS Config.
- External: annual penetration test; public disclosure intake
at
security@rexblack.com. - Internal: engineers file findings as incidents when discovered in review or production.
3. Severity
Use CVSS v3.1 as the default score. Where a vendor advisory provides a more specific rating, use the higher of the two.
4. SLAs
Measured from the time a finding is confirmed.
| Severity (CVSS) | Fix SLA | Exceptions |
|---|---|---|
| Critical (9.0+) | 7 calendar days | Require CEO approval |
| High (7.0–8.9) | 30 calendar days | Require Security Officer approval |
| Medium (4.0–6.9) | 90 calendar days | Routine schedule |
| Low (<4.0) | Backlog, revisited | , |
For Rex Black-hosted internet-facing components with a Critical CVE and a known public exploit ("kill chain"), the fix SLA tightens to 48 hours.
5. Process
- Triage within 1 business day; assign severity and owner.
- Mitigation planned; compensating controls if immediate patch is impossible (WAF rule, config change, feature flag off).
- Remediation via PR referencing the finding.
- Verification, scanner re-run or manual validation confirms the fix.
- Finding closed in the Vulnerability Register
(
registers/vulnerabilities.md).
6. Exceptions
- An exception is created with: the finding, justification, business impact of immediate fix, compensating control, and an expiry date not exceeding 90 days.
- Exceptions are reviewed quarterly. Renewals require fresh justification.
7. Coordinated disclosure
- Security researchers report via
security@rexblack.com(PGP key published on the trust page). - Acknowledge receipt within 5 business days.
- Triage and communicate expected remediation timeline within 10 business days.
- Researchers are asked not to publish details before a fix is shipped; Rex Black commits to not pursuing legal action against good-faith research under our safe-harbor statement.
8. Patch management
- OS and endpoint patching per
025-endpoint-security-policy.md. - Lambda / Next.js runtime versions tracked; upgraded before runtime deprecation.
- Container and base-image versions (if any) updated monthly.
9. Roles & responsibilities
| Role | Responsibility |
|---|---|
| Security Officer | Owns triage, SLA tracking, disclosures. |
| Engineering | Implements fixes; provides mitigations. |
10. References
007-change-management-policy.md016-secure-software-development-policy.mdregisters/vulnerabilities.md
11. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.