UHUBS POLICY

Threat & Vulnerability Management Policy

Last reviewed on 30 October 2025
This Threat & Vulnerability Management Policy outlines continuous assessments and monitoring, timely mitigation strategies, a collaborative response framework, and a 'Pre-Mortems' and 'Post-Mortems' framework. It emphasizes regular vulnerability scans, integration of external threat intelligence sources, clear threat severity classification, defined response timeframes, mitigation measures, incident communication plan, stakeholder responsibilities, tabletop exercises, 'pre-mortems' to predict future risks, 'post-mortems' to learn from incidents, and continuous improvement.

1. Continuous Assessments and Monitoring:

1.1 Regular Vulnerability Scans:

Uhubs conducts regular vulnerability scans on its infrastructure and applications, utilising industry-standard tools. Scans are scheduled at least monthly, with immediate scans triggered for any significant changes to the environment.

1.2 External Threat Intelligence Sources:

Integration of external threat intelligence sources to stay informed about emerging threats. Regular monitoring of these sources ensures timely awareness of potential risks.

2. Timely Mitigation Strategies:

2.1 Threat Severity Classification:

Define a clear classification system for threat severity, considering factors such as exploitability, potential impact, and affected assets.

2.2 Mitigation Response Timeframes:

Establish specific response timeframes based on threat severity levels:

  • Critical: Immediate response within hours.
  • High: Response within days.
  • Medium: Response within weeks.
  • Low: Response within a reasonable timeframe.

2.3 Mitigation Measures:

Clearly defined measures for mitigating identified vulnerabilities, ranging from software patches and configuration changes to temporary workarounds.

3. Collaborative Response Framework:

3.1 Incident Communication Plan:

Develop a detailed incident communication plan outlining:

  • Points of contact.
  • Communication channels.
  • Escalation procedures.

3.2 Stakeholder Responsibilities:

Clearly define roles and responsibilities for stakeholders during a security incident. This includes communication responsibilities, technical response actions, and managerial oversight.

3.3 Tabletop Exercises:

Conduct regular tabletop exercises to simulate security incidents. This collaborative approach helps identify gaps in the response framework and ensures effective communication among stakeholders.

4. 'Pre-Mortems' and 'Post-Mortems' Framework:

4.1 Pre-Mortems - Predicting Future Risks:

Hold 'pre-mortems' before major releases or changes to predict potential security risks. This involves scenario-based discussions and risk identification to proactively address vulnerabilities.

4.2 Post-Mortems - Learning from Incidents:

Following any security incident, conduct a comprehensive 'post-mortem' analysis. This includes:

  • Root cause identification.
  • Assessment of incident response effectiveness.
  • Documentation of lessons learned.
  • Implementation of corrective measures to prevent recurrence.

4.3 Continuous Improvement:

Implement an iterative approach to threat and vulnerability management, incorporating insights from 'pre-mortems' and 'post-mortems' into future risk assessments and response strategies.

5. Regular Policy Review and Updates:

Uhubs places a strong emphasis on the regular review and update of the policy. An annual review process will be in place to assess the plan's alignment with the evolving environment. This commitment ensures that the policy remains current, adaptable, and effective in addressing emerging challenges and maintaining adherence.

No items found.