Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

SIAS v1.0 · Domain 8 of 19

VPM: Vulnerability and patch management

Vulnerabilities in in-scope assets are found promptly, fixed or mitigated in order of risk within defined time limits, and tested for by skilled people as well as tools. Where a fix is late, someone with authority knowingly accepts the risk for a limited time.

About this domain

What this domain covers. Vulnerability scanning and advisory monitoring, remediation time limits, patching and supported software, penetration testing, the applicant's own vulnerability risk acceptances, and intake of vulnerability reports from outside parties. Secure development practices are in the SDC domain, cloud configuration in the CLD domain, and third-party components in SIAS-SDC-05.

Two kinds of severity. This domain uses two scales that must not be confused. The vulnerability rating is the applicant's rating of a vulnerability (Critical, High, Medium, Low), which drives the remediation time limits in SIAS-VPM-02. The finding severity is SecurityInspect's rating of a SIAS finding, which drives the decision gates. A vulnerability SecurityInspect discovers during testing is recorded under SIAS-VPM-02 when it fails a SIAS-VPM-02 pass criterion (for example it is KEV-listed on an internet-facing asset, or past its remediation maximum). Otherwise it is recorded as an Unassigned finding (§5.7), which counts toward gates G2 and G4 but changes no score. SecurityInspect assigns its finding severity using the SIAS severity scale and the global escalation rules, not the applicant's rating. An open vulnerability that leaves a likely path to compromise of in-scope systems or sensitive data is a Critical finding even if the applicant has accepted its risk. Any open, unmitigated vulnerability listed in the CISA Known Exploited Vulnerabilities (KEV) catalog on an internet-facing in-scope asset is a Critical finding. Either kind blocks certification until SecurityInspect has retested it and confirmed the fix.

Applicant risk acceptance is not a SIAS exception. SIAS-VPM-05 tests the applicant's own process for accepting vulnerability risk. That process never resolves a SIAS finding. SIAS exceptions are a separate mechanism, approved only by SecurityInspect's certification decision-maker with quality-reviewer concurrence, and never available for a Critical finding.

Testing safeguards. SecurityInspect scans and tests only the assets declared in the signed scope and named in the rules of engagement (the assessment plan), within agreed windows and rate limits. SecurityInspect's own scans test the applicant's program; they never replace it. Certification is never issued solely from a vulnerability scan.

What the software evaluates and what needs human judgment. SecurityInspect's proprietary security-analysis software must reconcile scan coverage with the asset inventory, run its own external (and, where authorized, authenticated internal) scans, match vulnerabilities with the KEV catalog, compute remediation timeliness from tracker dates, and fingerprint software versions. Analysts decide which automated results are false positives, whether a mitigation actually prevents exploitation, whether a rating adjustment is reasonable, whether a penetration test was deep enough, and whether a risk acceptance's interim safeguards are real. Automated results count toward a rating only after a technical tester confirms or rejects each result that affects it.

Controls in this domain

6 controls, 3 of them mandatory.

Controls in the VPM domain
ControlTitleMandatorySeverityApplies
SIAS-VPM-01Vulnerability identification and scanningYesHighAll scopes
SIAS-VPM-02Risk-based remediation within defined timelinesYesCriticalAll scopes
SIAS-VPM-03Patch and update managementYesHighAll scopes
SIAS-VPM-04Periodic penetration testingNoHighConditional — internet-facing applications or services, or applicant-operated networks, are in scope
SIAS-VPM-05Vulnerability exceptions and risk acceptanceNoMediumAll scopes
SIAS-VPM-06Coordinated vulnerability disclosure intakeNoLowConditional — public-facing websites, applications or APIs are in scope

SIAS-VPM-01 Vulnerability identification and scanning

Mandatory
Yes
Severity
High
Applies
All scopes
SecurityInspect Verified profiles
VP-EXT, VP-APP

Control objective

Vulnerabilities in in-scope assets are found soon after they appear, and no in-scope asset stays outside the applicant's view for long.

Testable requirement

  • The applicant must:
  • 1.scan every internet-facing in-scope asset from outside at least monthly, and after any significant change to it;
  • 2.scan internal in-scope hosts, including cloud workloads, with authenticated (credentialed) scans at least monthly wherever the asset supports them;
  • 3.scan the software dependencies and container images of in-scope applications at build time, and scan deployed images at least monthly;
  • 4.keep scanner vulnerability content up to date, updated before each scheduled scan or automatically;
  • 5.cover 100% of internet-facing in-scope assets and at least 95% of other in-scope assets in the inventory (SIAS-AST-01) in each cycle, reconciling scan targets with the inventory and recording why any asset was not scanned;
  • 6.monitor supplier security advisories and the CISA KEV catalog for in-scope technologies that scanners cannot assess (for example network appliances and managed services);
  • 7.record every identified vulnerability in a tracking system with the asset, an identifier (a CVE ID or another identifier), the rating, the first-detected date and an owner.

Applicability and scope

All scopes. SecurityInspect Verified profiles: VP-EXT (requirements 1 and 4–7 for the declared internet-facing domains, addresses and services); VP-APP (requirements 3, 4, 6 and 7 for the named application, its dependencies and its hosting, plus requirement 1 for its internet-facing endpoints).

Pass criteria

  • 1.Every internet-facing in-scope asset was scanned externally at the required cadence throughout the look-back period, and after each significant change.
  • 2.Authenticated internal scans ran at the required cadence on every asset that supports them.
  • 3.Dependencies and images were scanned at build time, and deployed images at least monthly.
  • 4.The most recent cycle met the coverage thresholds in requirement 5, and no internet-facing asset went unscanned for more than one cycle in the look-back period.
  • 5.A3 found no High or Critical vulnerability missing from the applicant's records where both the vulnerability and the asset were known before the applicant's last scan.
  • 6.Scanner content was current at each scan.
  • 7.Every sampled tracker entry has the required fields.

Severity

High. A KEV-listed vulnerability on an internet-facing asset found during this testing is recorded as a Critical finding under SIAS-VPM-02.

Informative framework mappings

HIPAA Security Rule
No direct mapping
PCI DSS v4.0.1
6.3, 11.3
Trust Services Criteria
CC7.1
ISO/IEC 27001:2022
A.8.8
Theme (SecurityInspect wording)
finding technical vulnerabilities regularly

SIAS-VPM-02 Risk-based remediation within defined timelines

Mandatory
Yes
Severity
Critical
Applies
All scopes
SecurityInspect Verified profiles
VP-EXT, VP-APP

Control objective

Known vulnerabilities are fixed or mitigated in order of risk, within time limits short enough to close likely attack paths.

Testable requirement

  • The applicant must:
  • 1.rate each vulnerability with a documented method that starts from the CVSS base score (version 3.1 or 4.0) or the supplier's rating and adjusts for exposure and known exploitation. Without a documented adjustment, the rating follows the CVSS bands: Critical 9.0–10.0, High 7.0–8.9, Medium 4.0–6.9, Low 0.1–3.9. Any rating lowered below its band needs a recorded rationale approved under SIAS-VPM-05;
  • 2.remediate (patch, upgrade, reconfigure or remove) or mitigate so that the vulnerability can no longer be exploited, within these maximum times from first identification: KEV-listed on an internet-facing asset, 7 days; Critical, 15 days; High, 30 days; Medium, 90 days; Low, 180 days;
  • 3.start the clock on the date the vulnerability is first identified on the asset by any source (scan, advisory, external report or SecurityInspect testing). For a vulnerability added to the KEV catalog later, the 7-day clock starts on the later of first identification and the KEV addition date;
  • 4.where no fix exists, apply a documented mitigation within the same time limit and keep tracking the vulnerability until it is fixed;
  • 5.confirm each remediation by rescanning or retesting, and close the tracker entry only after that confirmation;
  • 6.handle any vulnerability that cannot be remediated or mitigated in time under SIAS-VPM-05, except KEV-listed vulnerabilities on internet-facing assets, which must be remediated, mitigated or removed from internet exposure;
  • 7.report remediation performance (the share closed within time limits, by rating) to the security owner at least monthly.

Applicability and scope

All scopes. SecurityInspect Verified profiles: VP-EXT (vulnerabilities on the declared internet-facing assets); VP-APP (vulnerabilities in the named application, its dependencies and its hosting).

Pass criteria

  • 1.The documented time limits are no longer than the maxima in requirement 2, and the rating method meets requirement 1.
  • 2.At the time of testing, no in-scope vulnerability is past its deadline unless a SIAS-VPM-05 risk acceptance covers it. A risk acceptance keeps this criterion from failing; it does not stop SecurityInspect from recording the vulnerability itself as a finding under the SIAS severity scale.
  • 3.No KEV-listed vulnerability on an internet-facing asset is open and unmitigated at the time of testing, in either the applicant's records or SecurityInspect's testing.
  • 4.Over the look-back period, at least 90% of Critical and High vulnerabilities combined were remediated or mitigated within their deadlines.
  • 5.Every sampled closure was confirmed by rescan or retest, and A4 confirms each fix.
  • 6.Every mitigation tested in M2 prevents exploitation.

Severity

Critical. Any KEV-listed vulnerability on an internet-facing in-scope asset that is open and unmitigated is a Critical finding regardless of age, and blocks certification until SecurityInspect retests it. A finding may be lowered to High only for a partial failure (for example no overdue items at the time of testing, but an on-time rate below the pass criterion over the look-back period), with written rationale, quality-reviewer concurrence and approval by the second independent reviewer.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(1)(ii)(B)
PCI DSS v4.0.1
6.3, 11.3
Trust Services Criteria
CC7.1
ISO/IEC 27001:2022
A.8.8
Theme (SecurityInspect wording)
fixing vulnerabilities in priority order, on time

SIAS-VPM-03 Patch and update management

Mandatory
Yes
Severity
High
Applies
All scopes
SecurityInspect Verified profiles
VP-EXT

Control objective

Operating systems, firmware, applications and libraries run versions that still receive security updates, and updates are applied through a controlled, timely process.

Testable requirement

  • The applicant must:
  • 1.run only operating systems, firmware, software and libraries that receive security updates from their supplier or from a contracted extended-support provider;
  • 2.keep a register of end-of-support dates for in-scope technologies and plan each replacement before its end of support;
  • 3.apply security updates through a defined process that includes testing proportionate to risk, a rollback method and an emergency path for urgent fixes (time limits under SIAS-VPM-02);
  • 4.enable automatic security updates on in-scope endpoints;
  • 5.rebuild container images on current base images at least monthly, and when a base-image vulnerability rated High or above is published;
  • 6.measure patch coverage and keep at least 95% of in-scope endpoints and servers at their current security patch level, measured against the SIAS-VPM-02 time limits. The applicant should enable automatic security updates on servers and managed services wherever operationally safe, and record why it has not where it has not.

Applicability and scope

All scopes. SecurityInspect Verified profile: VP-EXT (software on the declared internet-facing services, whose versions and support status SecurityInspect identifies from outside and confirms with the applicant).

Pass criteria

  • 1.No end-of-support technology is in scope unless a compensating control accepted under this control covers it.
  • 2.Patch coverage is at least 95% in the most recent measurement, and A6 confirms it for the sample.
  • 3.Sampled patches show testing, a rollback method and, where used, the emergency path.
  • 4.Automatic security updates are enabled on in-scope endpoints.
  • 5.Container images are within the age limit in requirement 5.
  • 6.The end-of-support register lists every in-scope technology with its dates.

Severity

High. The global escalation rules apply; exploitable vulnerabilities in end-of-support software on internet-facing assets are handled as findings under SIAS-VPM-02.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(1)(ii)(B)
PCI DSS v4.0.1
6.3
Trust Services Criteria
CC7.1
ISO/IEC 27001:2022
A.8.8, A.8.19
Theme (SecurityInspect wording)
applying security updates to operational systems

SIAS-VPM-04 Periodic penetration testing

Mandatory
No
Severity
High
Applies
Conditional — internet-facing applications or services, or applicant-operated networks, are in scope
SecurityInspect Verified profiles
None

Control objective

Skilled people periodically try to break in, finding weaknesses that automated scanning misses, and what they find is fixed.

Testable requirement

  • The applicant must:
  • 1.commission or perform a penetration test of in-scope internet-facing applications and services, and of applicant-operated networks, at least every 12 months and after each significant change to them;
  • 2.use testers who are qualified by documented experience or recognized professional credentials, and who are independent of the design, build and operation of the systems they test (internal or external);
  • 3.define the scope and rules of engagement in writing, covering application-layer and network-layer testing, authenticated testing of applications, and checks of segmentation wherever segmentation is used to limit scope;
  • 4.use a documented method that goes beyond automated scanning, including manual exploitation attempts and testing of business logic;
  • 5.enter findings into the SIAS-VPM-02 process with its time limits, and retest remediated High and Critical findings;
  • 6.keep the report, the scope and the retest evidence.

Applicability and scope

Conditional — internet-facing applications or services, or applicant-operated networks, are in scope. Marking it not applicable needs a written rationale approved by the quality reviewer. SecurityInspect's manual technical testing during a SIAS assessment does not fulfill this control, because the control tests the applicant's own ongoing program. A penetration test previously performed for the applicant by SecurityInspect may be accepted as evidence only if none of its testers or advisers serve on the SIAS assessment team, the quality review or the certification decision. Not part of any SecurityInspect Verified profile.

Pass criteria

  • 1.A test completed within the last 12 months covered every in-scope internet-facing application and service and every applicant-operated network.
  • 2.Each significant change since that test was followed by a test, or a documented reason why none was needed.
  • 3.The testers were qualified and independent of the tested systems.
  • 4.The method included manual testing beyond automated scanning.
  • 5.High and Critical findings were remediated within the SIAS-VPM-02 time limits and retested.
  • 6.SecurityInspect's sample retest confirms the fixes.

Severity

High. A previously reported test finding that SecurityInspect confirms is still exploitable, and that meets a global escalation trigger (for example an authentication bypass on an internet-facing system), is a Critical finding.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(8)
PCI DSS v4.0.1
11.4
Trust Services Criteria
CC4.1
ISO/IEC 27001:2022
A.8.8
Theme (SecurityInspect wording)
periodic independent attack simulation

SIAS-VPM-05 Vulnerability exceptions and risk acceptance

Mandatory
No
Severity
Medium
Applies
All scopes
SecurityInspect Verified profiles
None

Control objective

A vulnerability that is not fixed on time is knowingly accepted by someone with authority, for a limited time, with interim safeguards in place.

Testable requirement

  • The applicant must:
  • 1.record a risk acceptance, before the deadline passes, for every vulnerability not remediated within its SIAS-VPM-02 time limit and for every rating lowered below its CVSS band;
  • 2.state in each acceptance the vulnerability, the affected assets, the reason, the risk, the interim safeguards, the owner, the approver, the approval date and the expiry date;
  • 3.for vulnerabilities rated Critical or High, have the acceptance approved by a person with authority for that level of risk under the applicant's risk process (SIAS-RSK-02) who is not the asset owner requesting it;
  • 4.set an expiry no later than 12 months after approval, with a fresh review for any renewal;
  • 5.never accept the risk of a KEV-listed vulnerability on an internet-facing asset;
  • 6.review open acceptances at least every 3 months.

Applicability and scope

All scopes. An applicant's risk acceptance never resolves a SIAS finding, and it is separate from a SIAS exception. Not part of any SecurityInspect Verified profile.

Pass criteria

  • 1.Every overdue or re-rated item has an acceptance approved before its deadline.
  • 2.Every acceptance has all the required fields.
  • 3.Approvers of Critical and High acceptances had the required authority and were not the requester.
  • 4.No expired acceptance is still relied on.
  • 5.No acceptance covers a KEV-listed vulnerability on an internet-facing asset.
  • 6.Open acceptances were reviewed at the required interval.
  • 7.The interim safeguards in the sample are in place.

Severity

Medium. The global escalation rules apply. An overdue vulnerability without an acceptance is also a finding under SIAS-VPM-02.

Informative framework mappings

HIPAA Security Rule
§164.308(a)(1)(ii)(B)
PCI DSS v4.0.1
6.3, 12.3
Trust Services Criteria
CC3.2
ISO/IEC 27001:2022
6.1.3; A.8.8
Theme (SecurityInspect wording)
documented, time-limited treatment of residual risk

SIAS-VPM-06 Coordinated vulnerability disclosure intake

Mandatory
No
Severity
Low
Applies
Conditional — public-facing websites, applications or APIs are in scope
SecurityInspect Verified profiles
VP-EXT

Control objective

People outside the organization who find a vulnerability can report it easily, and each report reaches someone who acts on it.

Testable requirement

  • The applicant must:
  • 1.publish a way to report security vulnerabilities for each public-facing in-scope domain: a security.txt file at /.well-known/security.txt in the format defined by RFC 9116, a vulnerability disclosure policy page linked from the site, or both;
  • 2.monitor the published contact and acknowledge each report within 5 business days;
  • 3.route valid reports into the vulnerability tracker (SIAS-VPM-01) and the remediation process (SIAS-VPM-02);
  • 4.keep the reporting route current: a security.txt expiry date in the future, and a contact that works;
  • 5.tell reporters what to expect: how to send details, which systems are covered and when they will hear back. The applicant should publish security.txt even where a policy page exists. SIAS does not require a bug bounty or payments to reporters. Any legal assurance offered to reporters is a matter for the applicant's own counsel; SIAS does not assess it.

Applicability and scope

Conditional — public-facing websites, applications or APIs are in scope. Marking it not applicable needs a written rationale approved by the quality reviewer. SecurityInspect Verified profile: VP-EXT (the declared public-facing domains).

Pass criteria

  • 1.Every public-facing in-scope domain publishes a reporting route.
  • 2.Where security.txt is used, it is valid and unexpired.
  • 3.The A3 test report was acknowledged within 5 business days.
  • 4.Every sampled real report was acknowledged within 5 business days and entered into the tracker where valid.

Severity

Low. The global escalation rules apply.

Informative framework mappings

HIPAA Security Rule
No direct mapping
PCI DSS v4.0.1
6.3
Trust Services Criteria
CC2.3
ISO/IEC 27001:2022
A.8.8
Theme (SecurityInspect wording)
receiving vulnerability reports from outside parties

Framework mappings in this domain

The mappings above are informative cross-references by identifier only. They don’t reproduce any framework’s text, and meeting a SIAS control doesn’t mean any framework requirement is met.

What framework mappings mean

SecurityInspect certification is a proprietary, scope-limited assessment against the SecurityInspect Assurance Standard. Framework mappings indicate thematic alignment only. Certification does not constitute an HHS-recognized HIPAA certification, PCI DSS validation, a SOC 2 examination or report, or accredited ISO/IEC 27001 certification.

How SIAS relates to other security frameworks

Where our work stops

Security Inspect is not a law firm or a CPA firm and does not provide legal opinions or issue SOC 2 reports. ISO/IEC 27001 certification is performed independently by an accredited certification body. CMMC organization-level assessment authority depends on an active C3PAO listing. Specific PCI services depend on the company’s active PCI SSC program listing and scope.

Talk to us about a SIAS assessment

Tell us what you want assessed, and we’ll start with the scope.