This Rules/Policy document is provided to you and your organization as a starting point or maturity checkpoint for existing rules/policies. It is brought to you on behalf of Jim McConnell, Principal Owner, and Ask McConnell, LLC — A Converged Security Services Provider. The content is not meant to cover every circumstance, industry, law, regulation, contractual requirement, threat, environment, or risk, but it provides an easy, defendable, highly accountable starting point for any organization. Please consult with your legal counsel and insurance provider about added requirements. If you know of peers that you think would find value in these resources, please have them contact us. These will be updated on our website regularly. We are not legally protecting these documents; we just ask for credit, shout-outs, and referrals if you find them helpful. If you have recommended updates, we are all ears. And if you need Converged Security Consulting and Training, please reach out, we would be honored to serve you and your organization.
Jim McConnell | info@askmcconnell.com | askmcconnell.com
Converged Security Vulnerability Management Policy
Updated: 8 April 2025
Protecting human lives is the highest requirement of our entire organization, whether they are employees, customers, volunteers, visitors, or part of our supply chain while under some nexus to our organization. Many times things we do online will impact people’s lives physically, financially, and emotionally.
Scope note: This policy primarily addresses physical, cyber, and fraud vulnerabilities. Human vulnerabilities are covered separately.
- I will report security incidents, concerns, vulnerabilities, and threats to my supervisor or the organization’s Ethics Hotline as soon as possible and safe. If they are not available and I feel unsafe, I will contact law enforcement.
- I will not act, produce, or introduce any activity that would create a vulnerability in our facilities or technology environment.
- If a vulnerability is known, introduced, or discovered in an environment I manage, I will eliminate it as soon as safely able to, in coordination with our security or safety teams.
- I will track all physical and technology assets under my management control that are susceptible to vulnerabilities — especially assets that are End of Life (EOL) or End of Service (EOS).
- I will subscribe to and monitor all asset manufacturers’ security notification processes and websites for new vulnerability information and fixes, and integrate mitigations into my overall remediation schedule.
- I will support testing, scanning, and assessing all assets under my management control for vulnerabilities on a schedule based on the impact of a breach — but no less than once per quarter.
- I will not test, scan, or assess assets not under my management control unless enterprise-wide vulnerability management is explicitly under my responsibility.
- I will report any discovered vulnerability to the appropriate asset owner as soon as safely possible — including vulnerabilities affecting assets owned by customers or suppliers.
- I will support Ethics Hotlines, Bug Bounty programs, and other vulnerability reporting mechanisms.
- I will budget yearly for the replacement of EOL and EOS assets, and for assets that are vulnerable and cannot be mitigated.
- I will implement metrics to manage the security and safety aspects of vulnerability management for environments under my management control.
- I will manage or support a State of Vulnerability Management Security Report and Presentation, under Executive Session, at least yearly — covering incidents, vulnerabilities, improvements, and metrics across all security domains.
Signature Note: I am a huge fan of wet signatures on these types of documents for accountability and investigation reasons. You can add the signature lines below to each rule/policy document, or have a collective wet signature with references in the Security Commitment Agreement document available on the One-Pager library page. Organizational preference.
________________________
Print Full Legal Name
________________________
(Blue Ink) Full Legal Signature
Style of signature must closely match Driver’s License
________________________
Date
🖶 To save or print this policy, use your browser’s Print function (Ctrl+P / Cmd+P) and select “Save as PDF” if needed.
