DNZ Consulting LLC
Policies and compliance · NY registration 7798491
← All policies

Vulnerability and Threat Management Procedure

DNZ Consulting LLC · Effective August 27, 2026 · Next review August 27, 2027

This procedure states how DNZ Consulting LLC finds security weaknesses and how fast it fixes them.

1. Scope and ownership

This policy applies to every system, device, and person that DNZ Consulting LLC uses to do business. DNZ Consulting LLC is a small company. The Managing Member owns this policy. The Managing Member also acts as the Security Officer and the Data Protection Officer.

The Managing Member reviews this policy one time each year. The Managing Member also reviews it after any security incident.

2. How we find vulnerabilities

3. How we rank a vulnerability

We use the CVSS score and the real exposure of the affected system.

SeverityCVSSFix within
Critical9.0 - 10.07 days
High7.0 - 8.930 days
Medium4.0 - 6.990 days
Low0.1 - 3.9Next planned release

A vulnerability with a public exploit that touches personal data is Critical. We fix it immediately, whatever the score says.

4. Patching

5. Accepting a risk

We fix a vulnerability by default. The Managing Member may accept a risk instead. That decision is written down. It states the reason, the compensating control, and a review date. We review an accepted risk every 6 months.

6. Threat monitoring

7. Review

The Managing Member reviews this procedure one time each year.