Home/Documentation/Programme-level documentation

Vulnerability & Patch Management Programme

A vulnerability management policy, SLA-driven remediation standard, scanning and patching procedures, and secure baseline configuration standards for common platforms.

What this set does

Patching is where most organisations fail Cyber Essentials, PCI DSS and 800-171 assessments, not because they do not patch but because they cannot show the rule they patch against. This programme defines remediation timelines by severity and exposure, and gives you the exception process for when you cannot meet them.

What's inside

  • Vulnerability management policy and remediation SLA standard
  • Scanning procedure (authenticated, external, web application)
  • Patch management procedure with maintenance windows and rollback
  • Exception and risk-acceptance procedure with register
  • Secure baseline configuration standards: Windows, Linux, macOS, network devices, cloud (AWS, Azure, Microsoft 365)
  • Monthly vulnerability report template

Who it is for

IT and security teams that need documented timelines and a defensible exception process.

How the documents are structured

Every document opens with its purpose, scope and owner, then the substantive content, then a control cross-reference showing which framework requirements it satisfies. Standards state requirements in testable language ("must", with the parameter). Procedures follow one format: trigger, roles, steps, frequency, records produced. Placeholders are limited to things only you can know: organisation name (which we fill in), system names, role titles, tool names and timelines. There are no "[insert policy here]" sections.

Tailoring effort

Expect to spend a few hours on a policies-and-standards set and longer on procedures, because procedures describe how your team actually works. The document register in each set lists every file with a suggested owner so you can split the work.

Included in these bundles

Licence

One purchase covers one organisation for internal use, with unlimited users and unlimited edits. Consultancies and MSPs tailoring documents for clients need the multi-client licence; see the terms or ask us.

Related products

Policies & Standards — ISO/IEC 27001:2022

A complete policy and standards set structured to the 93 Annex A controls of ISO/IEC 27002:2022, plus the clause 4–10 management-system requirements.

£495 · 41 documents

Policies & Standards — NIST CSF 2.0

Policies and standards organised by the six CSF 2.0 functions, with standards written at the subcategory level so each one is auditable.

£445 · 36 documents

Policies & Standards — NIST SP 800-53 R5 (Moderate)

Family-by-family policies and control-level standards for the moderate baseline, written to satisfy the -1 policy-and-procedure control in each family.

£695 · 48 documents