ctl-014
Critical vulnerabilities are patched within 14 days of disclosure.
- Type
- CORRECTIVE
- Automation
- SEMI_AUTOMATED
- Frequency
- CONTINUOUS
- Owner
- Information Security
Control Design Assessment (CDA)
Procedures evaluating whether the control is designed adequately.
- 1.Confirm the vulnerability management standard defines the 14-day critical patch SLA and the authoritative severity source.ID.RA-01
- 2.Confirm critical vulnerabilities are identified from a complete asset inventory.ID.AM-01
Control Operating Effectiveness (COE)
Procedures evaluating whether the control operated over the testing period.
- 1.Select 25 critical vulnerabilities disclosed in the period and confirm remediation within 14 days.
- 2.For exceptions, confirm a documented risk acceptance with an approved compensating control.GV.RM-01
- 3.Confirm reopened or recurring vulnerabilities were escalated.
Linked risks
- Ransomware disruptionmitigation 2
- Third-party software vulnerabilitymitigation 3
Framework mappings & latest test
TVM-03TVM-08
Latest test:FAIL2026-05-10