I. Purpose
The purpose of the Vulnerability Management security policy is to minimize the risk that Bradley University’s resources are compromised from an attack. Decreasing the time that a resource is vulnerable minimizes the risk of compromise.
Policy Supported
Supports:
- Cybersecurity and Infrastructure Security Agency (CISA) Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk
- National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) ID.RA
- National Institute of Standards and Technology (NIST) Special Publication (SP) 800-40
- National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53
II. Description
All hosts (servers, computers, and network devices) that are listening on or have open IP ports accessible from the Internet must be scanned for vulnerabilities monthly.
If any vulnerabilities known by the scanner at the time of scan are found, the host’s administrator will be responsible for remediating the vulnerabilities on their host(s). Vulnerabilities must be remediated within the time listed in the Remediation Timelines table after initial detection. If the vulnerabilities are not remediated within the specified time, either an exception at the Vice Presidential level must be approved, or the host will be blocked from the Internet
Before any request for a firewall security policy is configured, the internal host must be scanned, vulnerabilities remediated, and added to the list of hosts that are scanned automatically.
| Publicly Exposed? | In CISA’s Known Exploited Vulnerabilities (KEV) Catalog | Automatable by Adversary? | Technical Impact | Timeline (Calendar Days) for Remediation | |
| 1 | Yes | Yes | Yes | Total Control | 3 days |
| 2 | Yes | Yes | Yes | Partial Control | 3 days |
| 3 | Yes | Yes | No | Total Control | 3 days |
| 4 | Yes | Yes | No | Partial Control | 14 days |
| 5 | Yes | No | Yes | Total Control | 3 days |
| 6 | Yes | No | Yes | Partial Control | 14 days |
| 7 | Yes | No | No | Total Control | 14 days |
| 8 | Yes | No | No | Partial Control | 60 days |
| 9 | No | Yes | Yes | Total Control | 3 days |
| 10 | No | Yes | Yes | Partial Control | 14 days |
| 11 | No | Yes | No | Total Control | 14 days |
| 12 | No | Yes | No | Partial Control | 14 days |
| 13 | No | No | Yes | Total Control | 60 days |
| 14 | No | No | Yes | Partial Control | 60 days |
| 15 | No | No | No | Total Control | Fix on system upgrade |
| 16 | No | No | No | Partial Control | Fix on system upgrade |
III. Scope
This policy pertains to all hosts (servers, computers, and network devices) on Bradley’s network that are listening on or have open IP ports accessible from the Internet.
| Date Approved | |||
|---|---|---|---|
| 1/29/2010 |
| Dates Revised | |||
|---|---|---|---|
| 6/17/2019 | 7/9/2026 | 7/17/2026 |
| Dates Reviewed | |||
|---|---|---|---|
| 7/9/2026 |