Skip to content

Velinor AI Ltd · Company 15700539 · Reviewed October 2026

← Field notesMethod · 29 Sep 2026

Your remediation policy is the standard you will be assessed against.

Under Def Stan 05-138 you are assessed against your own remediation policy. So write one you can meet.

Control 2402 says vulnerabilities should be addressed in accordance with the Supplier's internal remediation timelines. A policy that promises seven days for every critical and then misses it is weak evidence.

How to do it.

Set the timeline by what the finding is, not only by its CVSS score. Four tiers cover most organisations.

  1. On the KEV list and reachable from the internet.
  2. On the KEV list, internal only.
  3. Critical or high, not on the KEV list.
  4. Everything else.

Then.

  1. Test the timelines against the last six months of your own data. If you closed 60% of highs inside thirty days, a fourteen day target is a policy you fail on day one.
  2. Say what happens when you cannot patch. Mitigate, isolate or formally accept, with a named owner and a review date.
  3. Name when the clock starts. When the finding is first seen, not when a ticket is raised.
  4. Get it signed by someone who owns the business risk.

Based on my experience running vulnerability management within the MOD, I assess that the policy which holds up to scrutiny is rarely the most aggressive one. It is the one with evidence behind every line.

Source: Def Stan 05-138 Issue 4, control 2402 Vulnerability management, read at source. CISA Known Exploited Vulnerabilities catalogue.

Written by Ben Brand, Velinor. The method behind these notes runs as Picket by Velinor.

More notes