Skip to main content

operationsVersion 1SOC2ISO27001NIST800-171

Vulnerability Management Policy

Discovery, triage, remediation SLAs, and coordinated disclosure process.

Download PDFSHA-256 d439fbaf197303c3…

Vulnerability Management Policy

1. Purpose

Ensures vulnerabilities in Rex Black systems, code, and dependencies are found, prioritized, and remediated on a predictable schedule.

2. Discovery sources

  1. Dependency scanning: Dependabot + npm audit on every PR and weekly scheduled scans.
  2. Static analysis: ESLint security plugin + custom rules in CI.
  3. Secret scanning: Gitleaks on every push; history included.
  4. Infrastructure scanning: Checkov / Pulumi CrossGuard on IaC changes.
  5. Runtime: AWS GuardDuty, AWS Inspector, AWS Config.
  6. External: annual penetration test; public disclosure intake at security@rexblack.com.
  7. Internal: engineers file findings as incidents when discovered in review or production.

3. Severity

Use CVSS v3.1 as the default score. Where a vendor advisory provides a more specific rating, use the higher of the two.

4. SLAs

Measured from the time a finding is confirmed.

Severity (CVSS) Fix SLA Exceptions
Critical (9.0+) 7 calendar days Require CEO approval
High (7.0–8.9) 30 calendar days Require Security Officer approval
Medium (4.0–6.9) 90 calendar days Routine schedule
Low (<4.0) Backlog, revisited ,

For Rex Black-hosted internet-facing components with a Critical CVE and a known public exploit ("kill chain"), the fix SLA tightens to 48 hours.

5. Process

  1. Triage within 1 business day; assign severity and owner.
  2. Mitigation planned; compensating controls if immediate patch is impossible (WAF rule, config change, feature flag off).
  3. Remediation via PR referencing the finding.
  4. Verification, scanner re-run or manual validation confirms the fix.
  5. Finding closed in the Vulnerability Register (registers/vulnerabilities.md).

6. Exceptions

  1. An exception is created with: the finding, justification, business impact of immediate fix, compensating control, and an expiry date not exceeding 90 days.
  2. Exceptions are reviewed quarterly. Renewals require fresh justification.

7. Coordinated disclosure

  1. Security researchers report via security@rexblack.com (PGP key published on the trust page).
  2. Acknowledge receipt within 5 business days.
  3. Triage and communicate expected remediation timeline within 10 business days.
  4. Researchers are asked not to publish details before a fix is shipped; Rex Black commits to not pursuing legal action against good-faith research under our safe-harbor statement.

8. Patch management

  1. OS and endpoint patching per 025-endpoint-security-policy.md.
  2. Lambda / Next.js runtime versions tracked; upgraded before runtime deprecation.
  3. Container and base-image versions (if any) updated monthly.

9. Roles & responsibilities

Role Responsibility
Security Officer Owns triage, SLA tracking, disclosures.
Engineering Implements fixes; provides mitigations.

10. References

  • 007-change-management-policy.md
  • 016-secure-software-development-policy.md
  • registers/vulnerabilities.md

11. Revision history

Version Date Author Approver Change
1.0 2026-04-17 S.O. CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center