Test · TST-Q2-VUL-01
VUL-01 · Vulnerabilities are scanned and remediated within SLA
FailQ2 2026 Unified Program ReviewTested 18 Jun 2026 by Farah Khan, Vikram Mehta · Meridian Internal Audit
Requirement to validation
Requirement
ISO-A.8.8 · RBI-CSF-NBFC-Annex-1-2 · RBI-ITGRCA-2023-7.4 · SOC2-CC7.1
mapped
Policy
Logging & Security Monitoring Standard
pol-logging
Control
VUL-01
Vulnerabilities are scanned and remediated within SLA
Application
Amazon Web Services (ap-south-1) · GitHub Enterprise Cloud
mapped
Evidence · Q3
0 items
0 approved · 0 pending · 0 rejected
Test · Q3
Not tested
Finding
F-IAQ2-VUL-01 · High
Closed
Action
Ananya Rao
REM-F-IAQ2-VUL-01 · Closed
Validation
Pending
as recorded
Procedure and result
- Procedure
- AWS Inspector, Dependabot, quarterly external VAPT. Tests: Amazon Web Services (ap-south-1): Inspector critical findings within SLA; GitHub Enterprise Cloud: Dependabot critical alerts within SLA. Frequency continuous.
- Sample
- 25 items sampled (Q2 baseline)
- Expected
- Production workloads and the Customer Portal are scanned continuously; critical vulnerabilities are remediated within 15 days and high within 30 days.
- Observed
- 11 critical findings on internet-facing AWS workloads were open beyond the 15-day SLA at the end of May.
- Confidence
- High