- Severity
- CRITICAL
- Status
- OPEN
- Owner
- Information Security
- Root cause
- Configuration
- Test failure
- Operating effectiveness (COE)
- Opened
- 2025-12-01
- Due
- 2026-06-15
- Closed
- —
38% of critical patches exceeded SLA; several affected internet-facing infrastructure.
tested 2026-05-10
This issue records a COE failure, shown first.
Control Operating Effectiveness (COE)
Procedures evaluating whether the control operated over the testing period.
- 1.Select 25 critical vulnerabilities disclosed in the period and confirm remediation within 14 days.
- 2.For exceptions, confirm a documented risk acceptance with an approved compensating control.GV.RM-01
- 3.Confirm reopened or recurring vulnerabilities were escalated.
Control Design Assessment (CDA)
Procedures evaluating whether the control is designed adequately.
- 1.Confirm the vulnerability management standard defines the 14-day critical patch SLA and the authoritative severity source.ID.RA-01
- 2.Confirm critical vulnerabilities are identified from a complete asset inventory.ID.AM-01
Related issues
Same root cause or a shared entity
- Prior pen test findings unresolvedCOEMODERATE
- Mobile session timeout inconsistencyCDAMODERATE
- IAM policy guardrails not enforced as codeCDAMODERATE
- Data center access badge exceptionsCOELOW
Score contribution
Issue-pressure points as of 2026-07-01, before the factor is capped at 0–100.
- Mobile Banking App54 of 92 pts
58.7% of this entity’s issue pressure
Annual priority score: 57 · issue pressure carries 10% weight in the active model — one factor among several behind that score.
- CRITICAL severity: 40
- Overdue: +8
- Repeat finding: +6
- Data Center Operations54 of 55.25 pts
97.7% of this entity’s issue pressure
Annual priority score: 35 · issue pressure carries 10% weight in the active model — one factor among several behind that score.
- CRITICAL severity: 40
- Overdue: +8
- Repeat finding: +6
Linked entities
- Mobile Banking App
APPLICATION · CRITICAL
- Data Center Operations
LOCATION · HIGH