Prioritisation

Rank by KEV (exploited in the wild) > EPSS (likelihood) > CVSS (severity), then by asset

criticality and exposure. A medium CVSS on a KEV-listed, internet-facing asset outranks a

high CVSS on an isolated host.

Patch SLAs

SeverityRemediation window
Critical7 days
High30 days
Medium90 days
Low365 days
KEV matchAutomatic uplift (treat as Critical)

See the vulnerability SLA article.

The workflow

  1. Discover - authenticated + unauthenticated scans, SBOM, agent telemetry.
  2. Triage - dedupe, enrich (CVSS/EPSS/KEV), assign owner.
  3. Remediate - patch, mitigate, or formally accept/except.
  4. Verify - rescan; confirm the finding is gone.
  5. Report - track SLA attainment; escalate breaches.

Kernel & reboot hygiene

Kernel updates require a reboot to take effect. A host that installs but does not reboot

remains vulnerable. Always verify the running kernel matches the installed one, and monitor

reboot-required fleet-wide.

silently expire - exceptions must be explicit, owned, and time-boxed.

← Administrator Guide  ·  All guidelines