Security & Compliance
Vulnerability Management Policy
How Skoolfly identifies, prioritises and remediates security vulnerabilities.
1. Policy Statement
Skoolfly proactively identifies, triages and remediates security weaknesses in its systems, applications and dependencies. This policy defines the vulnerability management process, severity levels and remediation expectations.
2. Purpose
The purpose of this policy is to reduce organisational risk by addressing vulnerabilities before they can be exploited, and to include vulnerabilities found by researchers, scanners and incident activity in a single management process.
3. Scope
This policy applies to Skoolfly infrastructure, applications, endpoints, dependencies and third-party services within Skoolfly's control, including publicly exposed assets and internal systems.
4. Vulnerability Management Process
Discover: vulnerabilities are identified through scanning, dependency checks, testing and reports.
Prioritise: vulnerabilities are classified by severity, exploitability and affected data exposure.
Remediate: fixes are implemented within defined timeframes.
Verify: remediation is confirmed through re-scanning or verification.
Report: material findings and progress are tracked and escalated.
5. Scanning and Discovery
Publicly exposed infrastructure and applications are scanned on a regular basis.
Dependencies and libraries are checked continuously against known-vulnerability data.
Automated and manual security testing from the Secure Development Policy supplement scanning.
Findings from incident response and external responsible-disclosure reports are included.
6. Severity Classification
7. Remediation Timelines
8. Patch Management
Security patches for operating systems, middleware and dependencies are applied based on severity and exposure.
Patches are tested where necessary and deployed through a controlled process.
Where an immediate patch is not available, compensating controls are implemented.
9. Reporting and Escalation
Unresolved or high-priority vulnerabilities are tracked and escalated to leadership. Risk acceptance for unavoidable residual findings is documented with justification and an owner, and reviewed periodically.
10. Roles and Responsibilities
11. Review
This policy and the remediation timeframes are reviewed at least annually, or when threat information warrants a change.
