Add AGENTS.md guidance and expand Security policy library
This commit is contained in:
@@ -0,0 +1,39 @@
|
||||
# Vulnerability & Patch Management Guidance
|
||||
|
||||
**Document owner:** [Owner/Role]
|
||||
**Approved by:** [Steering Committee / CISO]
|
||||
**Effective date:** [YYYY-MM-DD]
|
||||
**Review cadence:** [Annually]
|
||||
|
||||
---
|
||||
|
||||
## 1. Purpose & Scope
|
||||
Implementation guidance for the [Vulnerability & Patch Management Policy](vulnerability_patch_management_policy.md). Applies to IT, security operations, and system owners.
|
||||
|
||||
---
|
||||
|
||||
## 2. Prioritization — Practical Order
|
||||
1. Check the finding against the [CISA KEV catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) first — actively exploited beats a higher CVSS score that's theoretical.
|
||||
2. Cross-reference against kill-chain asset inventory (per [Authentication Policy §2.1](authentication_policy.md)) — same CVE on a kill-chain system jumps the queue.
|
||||
3. Then fall back to CVSS-based SLA table in policy §2.2.
|
||||
|
||||
## 3. Patch Testing Before Rollout
|
||||
- Kill-chain and production-critical systems: patch in a staging/canary group first, even under an accelerated SLA — an emergency patch that breaks production is not a win.
|
||||
- Low-priority systems: standard maintenance window testing is sufficient.
|
||||
|
||||
## 4. Exception Tracking
|
||||
- Every SLA exception needs: system, CVE, compensating control (e.g., network isolation, WAF rule), owner, and review date ≤90 days out.
|
||||
- Review the exception list monthly — an exception with no progress after two review cycles escalates to CISO.
|
||||
|
||||
## 5. Checklist
|
||||
✅ Weekly external / monthly internal scanning running and reviewed.
|
||||
✅ KEV catalog checked against current open findings weekly.
|
||||
✅ Kill-chain systems on continuous scanning where tooling allows.
|
||||
✅ Exception list reviewed monthly, none open past 90 days without CISO sign-off.
|
||||
✅ Emergency patch process tested at least once — don't discover the process during a real zero-day.
|
||||
|
||||
---
|
||||
|
||||
## 6. References
|
||||
- **[NIST SP 800-40 Rev. 4](https://csrc.nist.gov/pubs/sp/800/40/r4/final)**
|
||||
- **[CISA KEV Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)**
|
||||
Reference in New Issue
Block a user