CYB-220Cybersecurity & Threat

Vulnerability Management Governance: SLAs, Exceptions and Evidence

Vulnerability SLAs only work if exceptions expire. Set remediation deadlines engineering can meet, manage exceptions, and have the evidence ready when auditors ask.

6 lessons About 3 hours 2 ALCs Certificate on completion

Prepares you for: Security+ · PenTest+ · AWS Certified Security – Specialty

What you'll be able to do

  • Set remediation SLAs by severity that engineering can meet
  • Run an exception process where every exception has an owner and an end date
  • Report on SLA performance without gaming the numbers
  • Produce the evidence auditors ask for in minutes
You finish with

Vulnerability SLAs and an exception process

What's in it. Remediation SLAs by severity, an exception process with expiry and the evidence auditors ask for.

You build it lesson by lesson, using your own organization, and submit it for your certificate. It's yours to keep and adapt.

Who it's for

Vulnerability management leads, security managers and IT operations teams.

What's inside

  1. Part 1Where the requirement comes from 16 min
  2. Part 2How small teams and enterprises meet it 14 min
  3. Part 3The method, step by step 20 min
  4. Part 4Hands-on lab: small team choose one 90 min
  5. Part 5Hands-on lab: enterprise choose one 120 min
  6. Part 6Finish and submit your deliverable 20 min

Built for your size

The requirement is the same everywhere. How you meet it depends on who you have. You pick the lab that matches your organization.

Small team or early-stagePatch and prove it.
EnterpriseRisk-based prioritisation and exception governance.

How you earn the certificate

Submit your finished deliverable, which is scored against a published rubric, and pass a short scenario quiz. Your certificate goes to your wallet and can be checked by anyone on the public register.

Ready to build vulnerability SLAs and an exception process?6 lessons, about 3 hours. Start whenever you're ready.
Join and enroll