Skip to content
PRC9 finding classes

Processing Protection

Is the compute that runs the business trustworthy and available?

The Processing domain covers the integrity and availability of compute: patch currency, workload and container hardening, build-pipeline trust, and resilience against disruption. It is where software supply chain and known-exploited vulnerabilities land.

What this domain covers

  • Patch currency, especially known-exploited vulnerabilities
  • Management, orchestration, and administrative interface exposure
  • Container, image, and workload hardening
  • Build pipeline and infrastructure-as-code integrity
  • Availability protection and rate limiting

Distribution across tiers

Tier 1 · Critical3 · 24–72 hours
Tier 2 · Regulatory3 · 30 days
Tier 3 · Best Practices3 · 90 days

Typically owned by Platform engineering / SRE.

Tier 1 · CriticalCould an external attacker use this to gain access, escalate privilege, or take data — today, without an insider and without a chain of unlikely events?
Tier 2 · RegulatoryWould a named auditor, regulator, or contractual counterparty record this as a deficiency?
Tier 3 · Best PracticesDoes fixing this reduce the number or severity of future Tier 1 and Tier 2 findings?

Other domains