Control · VUL-01

Vulnerabilities are scanned and remediated within SLA

Security OperationsSOC 2 · ISO 27001 · RBIRisk Medium

Requirement to validation

What should be true

Production workloads and the Customer Portal are scanned continuously; critical vulnerabilities are remediated within 15 days and high within 30 days.

Requirements
ISO-A.8.8 A.8.8 · Management of technical vulnerabilities
RBI-CSF-NBFC-Annex-1-2 RBI-CSF-NBFC Annex 1 §2 · Cyber security — SOC monitoring, vulnerability management, incident reporting (RBI Cyber Security Framework for NBFCs (IT Framework for the NBFC Sector))
RBI-ITGRCA-2023-7.4 RBI-ITGRCA-2023 §7.4 · Change and patch management — documented, approved and tested changes (RBI Master Direction on IT Governance, Risk, Controls and Assurance Practices, 2023)
SOC2-CC7.1 CC7.1 · Detection and monitoring of configuration changes and vulnerabilities
Third parties
—
Testing procedure
AWS Inspector, Dependabot, quarterly external VAPT. Tests: Amazon Web Services (ap-south-1): Inspector critical findings within SLA; GitHub Enterprise Cloud: Dependabot critical alerts within SLA. Frequency continuous.

Findings (1)

Open list →
FindingObservationControlApplicationsSeverityStatusOwnerActionValidation
F-IAQ2-VUL-01Critical vulnerabilities past remediation SLAVUL-01Amazon Web Services (ap-south-1), GitHub Enterprise CloudHighClosedAnanya RaoREM-F-IAQ2-VUL-01 · ClosedPending

Evidence (2)

Open list →
EvidenceTitleControlSource systemCollectedStatus
Q2-EV-022Amazon Web Services (ap-south-1) · configuration report (Q2)VUL-01Amazon Web Services (ap-south-1)17 Jun 2026Rejected
Q2-EV-023GitHub Enterprise Cloud · ticket sample (Q2)VUL-01GitHub Enterprise Cloud22 Jun 2026Rejected

Tests (1)

Open list →
TestControlCycleTestedByResultConfidence
TST-Q2-VUL-01VUL-01 · Vulnerabilities are scanned and remediated within SLAQ2 2026 Unified Program Review18 Jun 2026Farah Khan, Vikram Mehta · Meridian Internal AuditFailHigh