CONFIDENTIAL — Shared under mutual NDA. Do not distribute outside your organization.

Vulnerability Management Policy

CloudFive  ·  Effective: June 2026  ·  Owner: Todd Densmore  ·  Review: Annual

1. Purpose

This policy defines how CloudFive identifies, prioritizes, remediates, and tracks security vulnerabilities in its systems and the client environments it manages.

2. Scope

Applies to all CloudFive-operated infrastructure, development endpoints, dependencies in client deliverables, and third-party software used in delivery.

3. Vulnerability Sources

4. Severity & Remediation SLAs

Severity (CVSS)ExamplesRemediation target
Critical (9.0–10.0)Log4Shell, active RCE24 hours
High (7.0–8.9)Auth bypass, data exposure7 days
Medium (4.0–6.9)XSS, privilege escalation30 days
Low (0.1–3.9)Minor info disclosure90 days

5. Patching Procedures

6. Exceptions & Risk Acceptance

Where a vulnerability cannot be remediated within SLA (e.g., a vendor has not yet released a patch), CloudFive will:

7. Responsible Disclosure

CloudFive operates a responsible disclosure program. If you discover a vulnerability in a CloudFive system, please report it to todd@cloudfive.net with subject [VULNERABILITY REPORT]. We will acknowledge within 2 business days and provide a remediation timeline. We ask for a 90-day coordinated disclosure window.