Kean University Vulnerability Management & Remediation SOP


Kean University Vulnerability Management & Remediation Procedure

Table of Contents

About This SOP

This Standard Operating Procedure (SOP) defines how Kean University identifies, assesses, prioritizes, and remediates security vulnerabilities affecting University systems and assets. The objective is to reduce cybersecurity risk through consistent, timely, and auditable remediation practices.

Back to top

Scope

This SOP applies to all University assets that are subject to vulnerability scanning under the Asset Management Policy, including servers, endpoints, applications, and network devices.

Back to top

Key Definitions

  • Vulnerability: A weakness in a system, application, or configuration that could be exploited by a threat actor.
  • SLA (Service Level Agreement): The required timeframe for remediating a vulnerability based on its severity.

Back to top

Roles & Responsibilities

  • Information Security Office: Oversees vulnerability scanning, analysis, and reporting.
  • System Owners: Remediate identified vulnerabilities within defined SLAs.
  • Risk Manager: Oversees escalation of repeat or overdue vulnerabilities.

Back to top

Vulnerability Management Procedures

View step-by-step vulnerability management process

1. Vulnerability Scanning

  • Vulnerability scans are conducted based on asset classification:
  • Critical and Sensitive assets: Monthly scanning
  • General assets: Quarterly scanning
  • Authenticated scans are used where technically feasible.

2. Analysis & Validation

  • Scan results are reviewed for accuracy.
  • False positives are documented and excluded from remediation tracking.

3. Risk Prioritization

  • Validated findings are categorized by severity.
  • Remediation SLAs are applied as follows:
  • Critical: 7 days
  • High: 14 days
  • Medium: 30 days

4. Remediation

  • System owners remediate vulnerabilities within assigned SLAs.
  • Changes follow the Change Management SOP when required.

5. Verification & Closure

  • Rescans are performed to confirm remediation.
  • Findings are closed once remediation is verified.

6. Escalation

  • Repeat or overdue findings are escalated to the Risk Manager.
  • Compensating controls or formal exceptions are documented when necessary.

Back to top

  • KU IT 01 – Asset Management Policy
  • Change Management Policy
  • Risk Management Policy

Back to top

NIST CSF 2.0 Mapping

  • Detect: DE.CM (Continuous Monitoring)
  • Protect: PR.IP (Information Protection Processes)
  • Respond: RS.MI (Mitigation)

Back to top

Metrics & KPIs

View vulnerability management performance measures
  • SLA compliance rate
  • Number of repeat vulnerability findings
  • Mean time to remediate (MTTR)

Back to top

Records & Storage

  • Scan reports: Security scanning tools
  • Remediation tracking: [Scrut.io – link to be provided]

Back to top

Document Control

  • Version: 1.0
  • Author: Information Security Office
  • Approver: Chief Information Security Officer (CISO)
  • Effective Date: February 13, 2026
  • Review Cycle: Annual

Back to top

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.