Vulnerability management

Last updated: Sep 6, 2023

Our Security team identifies, evaluates, and manages vulnerabilities across Redox, including corporate assets, applications, and cloud infrastructure. Our purpose is to reduce our risk exposure and support our goal to become the most trusted brand in healthcare technology.

It's important that all parties involved agree about how vulnerabilities should be handled (e.g., reporting, triage, and prioritization, including if and when vulnerabilities should be fixed).

Vulnerability intake sources

We identify vulnerabilities via several sources, including:

Vulnerability Risk Ratings (VRR) and resolution SLAs

It’s important that vulnerabilities are rated consistently and transparently to arrive at objective, mutually agreed-upon severity ratings. At the highest level, we rate the risk of vulnerabilities using a consistent calculation, where VRR = Likelihood + Impact to score the vulnerability as follows:

Final score
Priority
Generalized recommendation
SLA
51–60
P0 (“Critical”)
Remediation ASAP
72 hours
41–50
P1 (“High”)
Prioritized / OOB remediation
2 weeks
31–40
P2 (“Medium”)
Scheduled / routine remediation
6 weeks
21–30
P3 (“Low”)
Plan resolution, as resources permit
12 weeks
<=20
P4 (“Informational”)
No action currently necessary
None

SLA overrides, mitigations, and risk acceptance

Resolution options include remediation, SLA overrides, mitigations, and risk acceptance.

Tracking and engagement

When we identify a vulnerability, the team that owns that vulnerability decides how to address, what timeframe to expect (within established parameters), and how to document decisions and ultimate outcomes. Our Security team may schedule regular or ad-hoc discussions, provide consulting upon request, and periodically check in on open issues.

Our Security team is then encouraged to derive insights from vulnerabilities to drive their programs forward. For example, identifying the most common root causes of vulnerabilities and the affected functional areas by using custom labels and queries.

We also track and report metrics about identified vulnerabilities to our executive leadership.