Policy & standards
VM policy, operating standard, scope and asset-coverage definition, roles & RACI.
Vulnerability Management Program Kit
A complete program built by a practitioner: policy, prioritization model, SLAs, workflows, metrics, and executive reporting. Findings are ranked by real exploitability rather than raw CVSS scores.
| Finding | CVSS | EPSS | KEV | Asset · Exposure | Priority |
|---|
Most teams build VM from scratch. They stitch a policy together from blog posts, sort findings by severity, and chase "criticals" nobody is exploiting while the vulnerability on CISA's Known-Exploited list waits in the backlog.
The kit fixes the ranking first. A two-stage model puts exploitation status and business exposure ahead of raw score, so the work queue reflects real risk and you can defend every decision to an auditor or a board.
What's inside
VM policy, operating standard, scope and asset-coverage definition, roles & RACI.
Paste a scanner export and map the columns once; the worksheet scores every finding (KEV · EPSS · criticality · exposure), assigns priority and SLA, and carries the methodology to defend it.
The enginePriority-to-SLA mapping, tunable to your risk appetite.
Vulnerability lifecycle, triage runbook, exception & risk-acceptance process with register.
A tool-agnostic onboarding playbook covering the fields the program needs, coverage validation, and tuning, with notes for Tenable, Qualys, Rapid7, Wiz, and Snyk.
A live dashboard inside the model (MTTR, SLA attainment, backlog and aging, known-exploited exposure) plus the one-page executive report.
Five-level maturity model matched to the free self-assessment, plus a 90-day program roadmap.
Mapped to NIST CSF, PCI DSS (req 6 & 11), ISO 27001, and SOC 2.
Start-here implementation guide, the kickoff deck with speaker notes, and escalation paths.
See inside
No mystery box. This is the full manifest, plus two excerpts from the real documents: the SLA matrix out of the policy, and the lifecycle the runbook and overview deck walk through. Download all ten, free →
Excerpt · VM Policy §8
| P1 | Critical / active threat Exploited and internet-facing, or top composite | 72 hours 24h if exploited & internet-facing |
| P2 | High Severe + exposed or exploited | 30 days |
| P3 | Medium Moderate composite | 90 days |
| P4 | Low Limited exposure / criticality | 180 days or formally risk-accepted |
Thresholds are tunable in the Prioritization Model and ratified against your own risk appetite.
Excerpt · Program Overview, slides 3 & 6
Stage 1, the threat gate. A finding that is exploited (on CISA KEV, known to be actively exploited, or EPSS ≥ 0.90) and internet-facing goes to P1, regardless of CVSS.
Stage 2, the composite. Everything else scores Severity × Exploit likelihood × Asset criticality × Exposure, mapping to P1 through P4. KEV or active exploitation sets exploit likelihood to its maximum, so an exploited finding on a segmented, low-value host still ranks by exposure and asset value like everything else.
A documented compensating control may lower priority by one tier at most. Every input is recorded, so the decision is auditable.
The differentiator
A high that's on the Known-Exploited list, internet-facing, on a crown-jewel asset is a fire. A critical with near-zero exploit probability, sitting internal and segmented on a non-prod box, is a scheduled ticket.
The model encodes exactly that: a threat gate for findings that are exploited and internet-facing, then a composite score across severity, exploit likelihood, asset criticality, and exposure. Flip the demo above. That reshuffle is the daily reality CVSS-only programs get wrong.
Free · no email required to start
The fastest way to trust a method is to use it. These are free and stand on their own: the full method, a tool that checks your CVE list against KEV and EPSS, a five-minute game about fix order, a short course for owners, and plain-English basics. Share them with your team. That's the point.
Paste a list of CVE IDs, a scanner export or a ticket. Get each one's CISA KEV status, EPSS score and threat-gate result. Your list is never uploaded.
What joined CISA's Known Exploited Vulnerabilities catalog, and what EPSS said about each flaw the day before it was listed. Computed from the two public feeds.
Thirty security problems, budget to fix five a quarter, and hidden dice deciding which of the rest get used against you. At the end you see what your order cost, and what six other orders would have cost with the same luck.
A free course for owners with no security staff. Module 1: what to fix first, how fast, and what to accept in writing. Module 2: a plain inventory of your accounts, apps, devices and vendors. Each lesson ends with part of a real file you keep.
Eight questions that place your program on a five-level scale and tell you the first things to fix. No sales call at the end.
Drop in a finding, answer three yes/no questions, get FIX NOW / FIX SOON / STANDARD QUEUE. The thesis, demonstrable in thirty seconds.
The first piece of data to add to your queue and what to do with it once it's there, in four steps you can adopt this week. One lookup against a free feed.
Six free security steps, in plain English, that a business with no security team can finish this week. They stop the scams that actually hit small businesses.
Running a real program? The VM Program Kit is free too. No security team? The Security Starter is the plain-English version.
Built by an operator
I'm Nick Strupp. At Accenture I built and scaled an application-security and vulnerability-management program from 12 people to 60, covering more than 5,000 applications, running the same risk-based prioritization this kit ships with. The kit is that program, written down, minus the years of trial and error.
Free and paid
For the security lead standing up a defensible, risk-based program inside their own organization.
For consultants, vCISOs, MSPs and MSSPs who use the Kit in paid client work.
For a business with no security team: the owner, the office manager, whoever's "good with computers."
Questions
No. The prioritization model and SLA logic are the operating decisions; the documents are the easy part. The model is the part you can't write from a blog post, and it is why the files work as one program.
Yes. It's tool-agnostic, with onboarding notes for the major scanners: Tenable, Qualys, Rapid7, Wiz, and Snyk.
Yes. The framework crosswalk maps every program element to NIST CSF 2.0, PCI DSS v4, ISO 27001:2022, and SOC 2, with the evidence each produces, and the policy's methodology section explains every scoring decision. It's a defensible starting point; your assessor has the final say.
Ten editable Word, Excel and PowerPoint files, free to download with no sign-up. You adapt every document to your own organization and tooling. New versions are posted on the Kit page.
A method nobody can read can't be checked or adopted. The Kit is the program I ran, written down, and it does more good open than behind a checkout. The method is published in full for the same reason.
Only if you use the Kit in paid work for clients, sell it, or build it into a product. Using and adapting it inside your own organization is free, at any size. The terms are on the license page.
Free
Take the VM Maturity Self-Assessment, a quick scorecard across coverage, prioritization, remediation, and metrics. We'll send your results.
Something went wrong. Please try again, or email us directly.