DNZ Consulting LLC · Effective August 27, 2026 · Next review August 27, 2027
This procedure states how DNZ Consulting LLC finds security weaknesses and how fast it fixes them.
1. Scope and ownership
This policy applies to every system, device, and person that DNZ Consulting LLC uses to do business. DNZ Consulting LLC is a small company. The Managing Member owns this policy. The Managing Member also acts as the Security Officer and the Data Protection Officer.
The Managing Member reviews this policy one time each year. The Managing Member also reviews it after any security incident.
2. How we find vulnerabilities
Operating systems report available security updates automatically.
GitHub Dependabot alerts us to a vulnerable dependency in a repository.
Our hosting and database suppliers send security advisories. We read them.
We use the CVSS score and the real exposure of the affected system.
Severity
CVSS
Fix within
Critical
9.0 - 10.0
7 days
High
7.0 - 8.9
30 days
Medium
4.0 - 6.9
90 days
Low
0.1 - 3.9
Next planned release
A vulnerability with a public exploit that touches personal data is Critical. We fix
it immediately, whatever the score says.
4. Patching
Automatic security updates stay on for every operating system.
We update dependencies at least every month.
We test a patch before we deploy it to production, when a test is possible.
We record the date of every applied patch.
5. Accepting a risk
We fix a vulnerability by default. The Managing Member may accept a risk instead.
That decision is written down. It states the reason, the compensating control, and a
review date. We review an accepted risk every 6 months.
6. Threat monitoring
We watch supplier status pages and security advisories.
We review access and error logs every month.
We investigate an unexpected administrative change immediately.
7. Review
The Managing Member reviews this procedure one time each year.