Policy 05 PRIORITY
Vulnerability Management Policy
PCI DSS Req 6.3, 11.3 · the rule Revique must follow
← All 21 policies
This page is the rule, not the implementation. It states what Revique
must do, at or above the PCI DSS minimum. How Revique actually does it today — the real AWS configuration, the current values, and where an auditor logs in to verify them — is in
Procedure 05. Values shown as [X] are placeholders still to be set.
Purpose
To ensure that security vulnerabilities across Revique's systems, applications, and dependencies are proactively identified, ranked by risk, and remediated within defined timeframes.
Scope
Applies to all Revique systems, applications, containers, dependencies, and infrastructure in all environments.
Policy statements
Each statement below is mandatory. The bolded must marks the obligation.
1Vulnerability scanning must be performed on a regular, defined schedule and after significant changes.
2All identified vulnerabilities must be ranked by risk (e.g. critical / high / medium / low).
3Critical and high-risk vulnerabilities must be remediated within [X] days of identification.
4A defined process must exist to identify new security vulnerabilities from reputable sources.
5Software dependencies and container images must be scanned for known vulnerabilities before deployment.
6Remediation actions and timelines must be documented and tracked to closure.
Roles & responsibilities
| Role | Responsibility |
|---|
| Security Officer | Own the vulnerability management process and track remediation. |
| Engineering / DevOps | Remediate vulnerabilities within defined timeframes. |
Enforcement
This policy is issued under the authority of Policy 01 — Information Security Policy and is mandatory for everyone in scope. Compliance is verified through the controls and evidence described in the linked procedure. Failure to comply may result in withdrawal of access and disciplinary action. This policy is reviewed at least annually, or sooner on significant change.
⚙️See the Procedure for this policyHow Revique implements this rule today, the current values, the gaps, and the auditor verification path→