Remediation SLA
The maximum time defined between finding a vulnerability and fixing it, by severity and asset criticality. A target you can be measured against.
Also calledremediation target · patch SLA · fix-by date
The maximum time your organisation has committed to between a vulnerability being identified and being fixed in production. Almost always a matrix rather than a single number: severity on one axis, asset criticality on the other.
Bank of Israel Directive 364 does not name a number of days. §61.4 requires application "within a timeframe commensurate with the criticality and sensitivity of the patch and of the information asset". That is a harder requirement than a fixed number, because it puts the burden of defining and justifying the targets on you.
Two common failures
- One blanket target for every asset. It is always too strict somewhere and too loose somewhere else.
- A target nobody measures against. An unmeasured target is a statement of intent, and an audit reads it as one.