Security & Compliance

Vulnerability Management Policy

How Skoolfly identifies, prioritises and remediates security vulnerabilities.

1. Policy Statement

Skoolfly proactively identifies, triages and remediates security weaknesses in its systems, applications and dependencies. This policy defines the vulnerability management process, severity levels and remediation expectations.

2. Purpose

The purpose of this policy is to reduce organisational risk by addressing vulnerabilities before they can be exploited, and to include vulnerabilities found by researchers, scanners and incident activity in a single management process.

3. Scope

This policy applies to Skoolfly infrastructure, applications, endpoints, dependencies and third-party services within Skoolfly's control, including publicly exposed assets and internal systems.

4. Vulnerability Management Process

Discover: vulnerabilities are identified through scanning, dependency checks, testing and reports.

Prioritise: vulnerabilities are classified by severity, exploitability and affected data exposure.

Remediate: fixes are implemented within defined timeframes.

Verify: remediation is confirmed through re-scanning or verification.

Report: material findings and progress are tracked and escalated.

5. Scanning and Discovery

Publicly exposed infrastructure and applications are scanned on a regular basis.

Dependencies and libraries are checked continuously against known-vulnerability data.

Automated and manual security testing from the Secure Development Policy supplement scanning.

Findings from incident response and external responsible-disclosure reports are included.

6. Severity Classification

CriticalPublicly exploitable, high impact, or affects data confidentiality or integrity; immediate attention.
HighLikely exploitable with significant impact.
MediumExploitable in limited circumstances or with moderate impact.
LowLimited impact or significant preconditions required.

7. Remediation Timelines

CriticalImmediate remediation, typically within a short window and no longer than as documented in the risk register.
HighUrgent remediation, typically within a defined number of days.
MediumRemediation within a reasonable period and coordinated with releases.
LowRemediation scheduled with planned maintenance or releases.

8. Patch Management

Security patches for operating systems, middleware and dependencies are applied based on severity and exposure.

Patches are tested where necessary and deployed through a controlled process.

Where an immediate patch is not available, compensating controls are implemented.

9. Reporting and Escalation

Unresolved or high-priority vulnerabilities are tracked and escalated to leadership. Risk acceptance for unavoidable residual findings is documented with justification and an owner, and reviewed periodically.

10. Roles and Responsibilities

Security ownerOversees the vulnerability management program and prioritisation.
Engineering / DevOpsRemediate vulnerabilities and apply patches.
InfrastructureMaintain scanning and dependency-check tooling.
ManagementReview escalated findings and risk acceptance.

11. Review

This policy and the remediation timeframes are reviewed at least annually, or when threat information warrants a change.