What’s Included
After the initial implementation described in the Onboarding section, Managed Solution shall provide managed vulnerability scanning services utilizing VulScan to continuously assess and monitor Client’s security posture across internal networks and external perimeters. Subject to Client’s selected subscription, managed vulnerability scanning services may include ongoing oversight of vulnerability management operations such as automated scanning, threat detection, compliance reporting, and strategic remediation guidance to protect Client’s infrastructure from emerging threats.
Depending on the selected subscription, services will generally include:
-
Managed Solution will maintain all scanning infrastructure, including onsite or cloud-based scanning appliances or agents, keeping vulnerability definitions and CVE data current to ensure newly discovered security issues are promptly included in scan criteria. We will apply updates to scanning components, periodically review scan schedules, targets, and IP ranges, and update them to reflect changes in Client’s environment (e.g., newly added servers or network segments).
-
Managed Solution will conduct regular internal and external vulnerability scans on an agreed schedule (monthly or quarterly), examining Client’s internal network devices, servers, and workstations, as well as internet-facing systems and network perimeter assets, for security weaknesses including open ports, outdated software, and misconfigurations. We will promptly notify Client of high-severity vulnerabilities (e.g., CVSS score of 7.0 or above) or critical security gaps that pose an immediate risk.
-
The scanning tools and processes will be configured to generate real-time alerts to Consultant’s security team and/or Client’s designated contacts upon scan completion, with particular emphasis on critical or high-risk findings. Managed Solution will also provide periodic vulnerability assessment reports (monthly or quarterly, consistent with scan frequency) detailing identified vulnerabilities by severity and affected system, tracking the status of previously identified issues (new, remediated, or outstanding), and including trend analysis to reflect Client’s security posture over time.
-
Managed Solution will manage scanning accuracy and relevance by validating critical findings to reduce false positives, configuring authenticated scans where Client credentials are provided, and suppressing confirmed non-issue detections while maintaining comprehensive scanning coverage.
-
For significant vulnerabilities identified, We will advise Client on remediation steps, including security patching, configuration changes, or other risk mitigation strategies. Remediation assistance beyond advisory guidance may be provided under a separate service or project agreement upon request.