VULNERABILITY MANAGEMENT
Vulnerability management
A risk-based approach to identifying, assessing, prioritising and remediating security vulnerabilities.
Purpose
This policy establishes a consistent and risk-based approach to identifying, assessing, prioritising and remediating vulnerabilities across MedTalk's technology environment, supporting the protection of sensitive information, including healthcare-related data, and the continued security and availability of MedTalk systems and services.
- Identify vulnerabilities across all systems in a timely manner
- Assess and prioritise risks based on business impact and exposure
- Remediate vulnerabilities within defined timeframes
- Reduce the likelihood of successful cyber attacks
- Maintain visibility of security risks across the organisation
- Support regulatory compliance and audit requirements
Scope
Technology and systems
- Cloud infrastructure and hosted services
- Servers, endpoints and mobile devices
- Applications and APIs
- Databases and storage systems
- Network infrastructure
- Development and testing environments
Vulnerability types
- Software vulnerabilities
- Misconfigurations
- Weak authentication controls
- Outdated or unsupported systems
- Exposed services or data
- Third-party or vendor-related vulnerabilities
Governance and regulatory alignment
- Chief Information Security Officer: owns the vulnerability management framework, defines standards and remediation expectations, approves risk acceptances and exceptions, and reports on vulnerability risks and trends to executive stakeholders.
- System and application owners: maintain awareness of vulnerabilities affecting their systems, ensure timely remediation or mitigation, assess business impact and risk exposure, and support audits and reporting.
This policy aligns with the Australian Privacy Act 1988, the Notifiable Data Breaches (NDB) Scheme, the ACSC Essential Eight, and ISO/IEC 27001 Information Security Management. Where MedTalk operates internationally, additional regulatory requirements may apply.
Vulnerability management framework
- Identification: vulnerabilities are identified through automated scanning tools, security monitoring systems, vendor advisories and threat intelligence, penetration testing and security reviews, and internal reporting. All systems are included in identification processes.
- Assessment and prioritisation: identified vulnerabilities are assessed based on severity, exploitability and threat activity, exposure (such as internet-facing systems), sensitivity of data involved, and business criticality, using a risk-based approach to prioritise remediation.
Remediation timeframes
| Severity | Description | Remediation timeframe |
|---|---|---|
| Critical | Actively exploited or high-impact vulnerabilities | 48 hours |
| High | Significant risk to systems or data | 14 days |
| Medium | Moderate risk | 60 days |
| Low | Low risk or informational findings | Addressed as part of routine maintenance |
Medium and Low severity vulnerabilities are remediated during a designated monthly maintenance window, held on the first Saturday of the month, with sufficient operational capacity allocated for deployment, pre-production testing, and post-remediation verification. Critical and High-severity vulnerabilities require out-of-band remediation that takes precedence over scheduled windows to meet the 48-hour and 14-day timelines. Where remediation is not immediately feasible, compensating controls are implemented to reduce risk.
Verification, closure and continuous monitoring
All remediation actions are verified prior to closure, through rescanning systems, testing patches or fixes, or reviewing system configurations, and unresolved vulnerabilities remain tracked until formally addressed or accepted.
- Regular vulnerability scanning
- Monitoring for new threats
- Tracking remediation progress
- Identifying recurring issues
Secure development and third-party risk
Security considerations are integrated into system and application development, including regular updates and patching, secure configuration practices, use of supported software versions, and identification and remediation of vulnerabilities during development, aligned with MedTalk's secure development standards.
Third-party providers must maintain appropriate vulnerability management practices. MedTalk assesses vendor security practices during onboarding, defines vulnerability management expectations in contracts, and monitors vendor risk where appropriate. Third-party vulnerabilities that impact MedTalk are addressed in accordance with this policy.
Exceptions, monitoring and review
Where a vulnerability cannot be remediated within its defined timeframe, an exception must be raised with business justification, a risk assessment, compensating controls and a defined expiry date, approved by the Chief Information Security Officer and tracked until resolved.
Vulnerability management performance is measured and reported through metrics including remediation rates against defined timeframes, the number of outstanding vulnerabilities, average time to remediate, and trends in vulnerability findings, reported regularly to executive stakeholders and governance forums.
This policy is reviewed at least annually, following major security incidents, and after significant changes to technology or regulatory requirements.
Contact
Security & Compliance: support@medtalk.co
Legal / compliance: legal@medtalk.co