Open kit · free to use
The VM Program Kit
A complete, risk-based vulnerability management program in ten editable files: the policy, the prioritization model, the runbook, the exception register and the reporting that goes with them. Free to use and adapt inside your organization.
What's in it
| Type | File | Get it |
|---|---|---|
| Start here What each file is, the order to adopt them, and what to customize before you deploy. | Download 134 KB | |
| PPTX | Program overview deck The whole program on 11 editable slides, with speaker notes. Rebrand it and present it to your leadership. | Download 285 KB |
| DOCX | VM policy and standard Scope, roles, asset tiering, the prioritization method, the deadline matrix, exceptions and governance. | Download 15 KB |
| XLSX | Prioritization model The engine. Paste a scanner export and map its columns once. It applies both stages of the method, assigns deadlines, tracks open and closed dates, and runs the dashboard. Wired for 2,000 findings. | Download 585 KB |
| DOCX | Triage and remediation runbook The operating procedure from intake through close, with escalation paths and a worked example. | Download 13 KB |
| XLSX | Exception register The risk-acceptance register the policy requires: approver set by priority, and an expiry that turns into a missed deadline. | Download 42 KB |
| DOCX | Scanner onboarding notes Bringing a scanner into the program: required fields, authenticated coverage and tuning, with notes for Tenable, Qualys, Rapid7, Wiz and Snyk. | Download 15 KB |
| DOCX | Executive report template The one-page leadership summary that answers whether you are exposed and whether it is improving. | Download 11 KB |
| XLSX | Framework crosswalk Every program element mapped to NIST CSF 2.0, PCI DSS v4, ISO 27001:2022 and SOC 2, with the evidence each produces. | Download 15 KB |
| DOCX | Maturity model and 90-day roadmap Six dimensions by five levels, scored like the free assessment, plus what to fix first at each level. | Download 16 KB |
Start with the START-HERE guide and the overview deck. Then adopt the policy, wire up the prioritization model, and run the work through the runbook and the exception register. The files reference each other, so they work as one program.
What you can do with it
That is a summary. The license page has the terms, and a copy travels with the files as LICENSE.txt.
Commercial license
$399 per firm, one time. One firm, all of its people, unlimited clients. You may adapt the Kit and deliver the documents and workbooks to clients under your own name. Later versions are included, and the 30-day refund policy applies.
Why it's free
This is the program I built and ran across more than 5,000 applications, written down. A prioritization method is only useful to the field if people can read it, check it and change it, so the method is published in full and the Kit that implements it is open. If you adopt it and change something, I'd like to hear what and why: support@flintscope.com.
Nick Strupp, CISSP. 15+ years in security. US Patent 11,106,801. The Kit is general information, not professional advice; see the disclaimer.