MCMMCM DocsEngineering (Internal)
User StoriesMCM-57 — Legal & Compliance Readiness for Customer Deployment
v1.2 is unreleased — see v1.1 for the current stable release.

MCM-64 — Vulnerability Management & Incident/Breach Notification SLA

Documented severity SLAs and a contractual breach-notification window.

MCM-64 — Vulnerability Management & Incident/Breach Notification SLA

← Back to Legal & Compliance Readiness overview

As Compliance & Security Lead,
I want a documented vulnerability management process and a contractual incident/breach notification SLA,
so that customers know how quickly a discovered vulnerability is patched, and how quickly they're told if their data is affected.

Acceptance Criteria

  • A documented vulnerability management process defines severity classification (Critical/High/Medium/Low) and a maximum remediation time per severity.
  • A shareable security advisory process exists for disclosing patched vulnerabilities to customers.
  • The contract commits to a maximum breach-notification window (e.g., within 72 hours of confirmation, aligned with GDPR's own regulator-notification requirement) and defines what the notification must contain.
  • An incident response runbook exists and is tested — e.g., a tabletop exercise — at least annually.
  • A responsible-disclosure intake channel exists for external researchers to report vulnerabilities.

Technical Design

Vulnerability severity is assessed against whichever module is affected — discovery, finops, governance, secops, orchestration, or the AI assistant — and the remediation clock starts at confirmed severity. Breach notification is triggered the moment an incident is confirmed to have exposed customer data, independent of when the underlying fix ships, so a slow fix never delays the notification the contract commits to.

On this page