Vulnerability Management
How we detect, assess and remediate vulnerabilities
Detection
We continuously identify vulnerabilities in systems, applications and processes. To do this, we use automated vulnerability scanners and manual analyses, and we evaluate reports from vendors and third parties. We record each vulnerability with a description, the affected systems and a risk assessment.
Assessment
The risk assessment is based on the Common Vulnerability Scoring System (CVSS). We also take into account how many systems are affected and how important they are, what the consequences for operations and data security could be, and what dependencies exist.
Prioritisation
| Priority | Handling |
|---|---|
| Critical | immediate remediation |
| High | short-term remediation |
| Medium | remediation during regular maintenance windows |
| Low | monitoring or long-term remediation |
Remediation and validation
We remediate vulnerabilities with patches, configuration changes or other measures, and we document each measure. We then check that the vulnerability has been closed and that no further risks remain.
If the remediation requires your involvement or affects your environment, we will inform you as soon as possible.
Monitoring and improvement
We continuously monitor open vulnerabilities and regularly produce reports on their status. After critical or complex cases, we record lessons learned and use them to improve our processes.