Last updated: April 29, 2026
Module 13 (DevSecOps) covered triage. This module is the program around it.
Programme components
- Asset inventory — what to scan; tagged with owner, criticality
- Scanning cadence — Tenable / Qualys / Rapid7 weekly for infrastructure; daily for cloud (CSPM)
- Triage process — EPSS + KEV + reachability
- Patch SLAs — by criticality and exposure
- Exception process — risk acceptance with sign-off
- Metrics — SLA compliance, MTTR, top recurring
The patch SLA matrix
| Internet-exposed | Internal | |
|---|---|---|
| KEV | 72h | 7d |
| Critical | 14d | 30d |
| High | 30d | 60d |
| Medium | 90d | 180d |
The reality check
Most enterprises miss SLAs. Reasons: legacy systems, vendor patching cycles, change-control bureaucracy. Acknowledge; manage exceptions explicitly.
Module Quiz · 5 questions
Pass with 80%+ to mark this module complete. Unlimited retries. Each question shows an explanation.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.