Skip to content
BCN-T2-PRC-001Tier 2 · RegulatoryProcessing Protection

Vulnerability Management Process Gaps

No defined scanning cadence, remediation SLA, or exception process — or incomplete asset coverage.

Remediation SLA
30 days
Tier
2 · Regulatory
Domain
Processing
Escalation
Security manager review at 14 days

What this finding is

The vulnerability management programme lacks a defined element: a documented scanning cadence, remediation timeframes by severity, a formal risk-acceptance path, or complete asset coverage. Incomplete coverage is the most common form — scanning that reaches servers but not containers, cloud-native services, or network appliances.

Why it is Tier 2

Every major framework mandates a vulnerability management programme with specific cadence and timeframes, and assessors test the process as well as its output. PCI DSS names quarterly external scanning by an approved vendor and remediation windows by severity. It is Tier 2 because the process gap is not itself an exposure, but it is the mechanism by which Tier 1 findings go undetected — an unscanned asset class produces no findings and therefore appears clean.

Most common misclassification

Individual unpatched vulnerabilities are frequently recorded against this finding. Those belong to BCN-T1-PRC-001 or their own entries; this finding is about the process, and closing it should not require patching every host.

How to detect it

  1. 1Reconcile the scanned asset inventory against the authoritative asset inventory; the difference is the coverage gap.
  2. 2Check for asset classes structurally excluded from scanning — containers, serverless functions, appliances, and OT are the usual omissions.
  3. 3Measure actual time-to-remediate against the stated SLA by severity; a stated SLA with no measurement is not a control.
  4. 4Ask for the risk-acceptance register and confirm exceptions carry an owner, an expiry, and a compensating control.

How to remediate it

Steps are ordered. The first step is the one that reduces exposure fastest, which is not always the one that closes the finding.

  1. 1Document the programme: scope, cadence, severity definitions, remediation timeframes, and the exception path.
  2. 2Extend coverage to every asset class, using image scanning for containers and posture management for cloud-native services.
  3. 3Instrument SLA measurement and report attainment, since assessors ask for the metric rather than the policy.
  4. 4Formalise risk acceptance with named approver, expiry, and compensating control — perpetual undocumented exceptions are a finding in themselves.
  5. 5Route findings into the same ticketing system engineering already uses, rather than a security-only tool nobody opens.

How to verify the fix

Scan coverage reconciles to the asset inventory with documented exclusions, SLA attainment is reported by severity for the current period, and every open exception carries an owner and a future expiry.

Mappings

Attacker techniques

  • T1190Exploit Public-Facing Application

Compliance mappings

  • PCI DSS v4.0
    11.3 — internal and external vulnerability scanning
  • SOC 2
    CC7.1 — vulnerability identification and management
  • ISO/IEC 27001:2022
    A.8.8 — technical vulnerabilities
  • NIST CSF 2.0
    ID.RA-01 / RS.MI-03

Tools that surface this

NessusQualysTrivyPROWLER