Vulnerability Management Policy

POLICY #: CR 26-5

DATE OF BOARD OF TRUSTEES APPROVAL: 9/28/2026

RESOLUTION #: 26-5

Purpose:

The purpose of this policy is to protect the College’s Information Technology (IT) Resources by establishing a systematic approach to identifying, assessing, prioritizing, and remediating security vulnerabilities.

Scope:

This policy and all policies referenced herein, shall apply to all members of the College community, including employees, students, alumni, authorized guests, and independent vendors who use, access, or otherwise employ, locally or remotely, the College’s IT Resources, whether individually controlled, shared, stand-alone, or networked.

Definitions:

  • Compensating Control: A data security measure that is designed to satisfy the requirement or some other security measure that is deemed too difficult or impractical to implement.
  • IT Resources: Includes computing, networking, communications, application, and telecommunications systems and infrastructure; hardware and software; data and databases; personnel; procedures; physical facilities; cloud-based and Software as a Service (SaaS) vendors; and other related materials, services, and resources.
  • Patch: A software update that modifies or replaces code within an existing software application or executable program. Patches are typically used to address specific issues or make incremental changes between major software releases. Patches may include, but are not limited to:
    • Updating or improving software functionality.
    • Correcting software bugs or defects.
    • Installing or updating device drivers.
    • Implementing or strengthening security controls.
    • Addressing newly identified security vulnerabilities.
    • Resolving software stability, reliability, or performance issues.
  • Patch Management Cycle: A component of IT lifecycle management that establishes a systematic process for identifying, evaluating, prioritizing, testing, scheduling, deploying, and verifying patches for College IT Resources.
  • Remediation: The process of resolving, mitigating, or otherwise reducing the risk associated with an identified vulnerability.
  • System Owner: The individual or group responsible for the procurement, development, integration, modification, operation, maintenance, and retirement of the servers, operating systems, infrastructure, or other technology components that support an application owner in delivering services. The system owner is responsible for ensuring the technical infrastructure supports appropriate system state management and data retention, including backups. When these services are provided by a third party, the system owner is responsible for managing the relationship with the third-party service provider and ensuring that applicable requirements are met.
  • Vulnerability Management: The ongoing process of identifying, assessing, classifying, prioritizing, remediating, and mitigating vulnerabilities in College IT Resources to reduce security risk.

Patch Management Cycle as Applied to Vulnerability and Remediation Activities:

The College’s patch management cycle shall support vulnerability management by ensuring that identified vulnerabilities are assessed, prioritized, and remediated in a timely and consistent manner.

  • The Director of IT / Chief Information Security Officer (CISO) shall establish and approve standard tools, procedures, and methodologies for conducting vulnerability assessments.
  • All College IT Resources must be included in a patch management cycle in accordance with the Patch Management Policy.
  • Application owners and system owners are responsible for assessing and remediating vulnerabilities affecting the IT Resources under their management or supervision.
  • When a vulnerability cannot be remediated through an available or practical solution, the Director of IT / CISO must approve any compensating or mitigating controls. A documented risk assessment must be conducted to evaluate and formally accept the associated risk.
  • Application owners and system owners must maintain written, documented, and auditable procedures for addressing and remediating identified vulnerabilities, including applicable remediation steps, timelines, and verification of completion.

Risk Rating and Patch Service Levels:

Table 1 establishes the risk rating for College information systems based on the potential impact to confidentiality, integrity, and availability (CIA), combined with the system’s network exposure and connectivity to production data. The resulting risk rating is used to determine the required timeframe for applying patches, firmware upgrades, and configuration changes.

Table 1: Risk Rating

Impact (Confidentiality, Integrity, Availability) Exposure
Systems with no network connectivity to production data Systems with network connectivity to production data (not internet facing) System that are publicly accessible from the internet
High Moderate High High
Moderate Low Moderate High
Low Low Low High

All patches, firmware upgrades, and configuration changes must be deployed to College-owned or College-managed IT Resources within the timeframes specified in Table 2.

Table 2: Patch SLA in Calendar Days

Risk Rating (from Table 1) Vulnerability Severity
Critical (CVSS score 9.0-10.0) High (CVSS score 7.0-8.9) Moderate (CVSS score 4.0-6.9) Low (CVSS score 0.1-3.9)
High 15 30 90 At the discretion of the CISO / designated security representative
Moderate 30 90 180
Low 120 180 At the discretion of the CISO / designated security representative