TriageSLA

Vulnerability SLA tracking

Assigns every open finding an owner and a deadline, and escalates only the ones about to breach.

Tools

Qualys, Tenable.io, Rapid7 InsightVM, Jira Service Management

Outcomes

No finding past deadline without an approved exception • Repeat findings traced to one root cause • Oldest internet-facing finding under 7 days

Documentation

Instruction-ready detail below

Scanners produce tens of thousands of findings and nobody agrees which ones matter this month. Exceptions live in a spreadsheet, deadlines pass quietly, and the same finding on the same internet-facing host is patched for the fourth time without anyone looking at why it keeps coming back.

The workflow sorts the queue instead of adding to it. It joins each open finding to the asset, the business owner, how exposed that asset is, and a severity that reflects both. From that it assigns one owner and one deadline, and it refuses to accept an exception without a named approver, a reason and an expiry date. Findings that are three days from their deadline are escalated to the owner and their manager, so the escalation happens before the breach rather than after it. Findings that reappear on the same host are grouped together so the coverage gap behind them is fixed once rather than four times.

A human approves every exception, every deadline change, and every risk acceptance.

Automations

Choose the setup that matches your tools.

Problem this workflow solves

Scanners produce tens of thousands of findings and nobody agrees which ones matter this month. Exceptions live in a spreadsheet, deadlines pass quietly, and the same finding on the same internet-facing host is patched for the fourth time without anyone looking at why it keeps coming back.

Download

Start with one instruction file.

Download the app and begin with drafts and checklists before you write anything back.

  • •Plain-language instructions
  • •Runs on your machine
  • •Works with your existing setup
  • •Reviewable activity history
Download