Vulnerability and Threat Management PolicyMarketing Lama GmbH
Version 1.2
Date: 23 February 2026
Document owner: Technical lead
Approved by: Management1. ObjectiveThe objective of this policy is the systematic identification, assessment, treatment and monitoring of technical vulnerabilities and threats in order to reduce information security risks.This policy supports the implementation of the requirements of ISO/IEC 27001 in the areas of:technical vulnerabilitiesthreat managementrisk treatmentIt forms part of the information security management system (ISMS).2. ScopeThis policy applies to:cloud infrastructureserver systemsend-user devicesdevelopment and production environmentscontainer environmentsthird-party dependenciessoftware components and libraries in use3. Embedding in risk managementTechnical vulnerabilities and threats are taken into account as part of information security risk management.Identified vulnerabilities are assessed for likelihood of occurrence and potential damage.Treatment measures are prioritised on a risk basis.Residual risks are documented and either accepted or treated further.4. Patch and update management4.1 Operating systemsSecurity updates are enabled on end-user devices.Server systems are updated regularly.Security-critical updates are treated as a priority.4.2 Applications and dependenciesProject dependencies are reviewed and updated regularly.Security-relevant notices (e.g. CVE advisories) are monitored.Outdated or unmaintained components are replaced or removed.4.3 Response timesVulnerabilities are handled according to criticality:CriticalityResponse timeHighas quickly as possible, at the latest within 72 hMediumpromptly, as a rule within 14 daysLowwithin regular maintenance cycles5. Vulnerability handling5.1 IdentificationVulnerabilities can be identified through:security advisories from software or cloud providersinternal code reviewsmonitoring mechanismsreports from external partiesregular technical reviews5.2 AssessmentVulnerabilities are assessed and documented in terms of:technical exploitabilitypossible effects on availability, integrity and confidentialityaffected systems5.3 RemediationMeasures may include:installing security updatesconfiguration changesreplacing compromised credentialsrestricting or shutting down affected servicesimplementing additional protective mechanismsImplementation is documented.6. Threat monitoringThe following measures are used for early detection of potential threats:use of cloud-based monitoring mechanismslogging of security-relevant eventsregular review of log datamonitoring of unusual login attemptsminimisation of publicly reachable servicesDetected threats are handled in accordance with the incident management policy.7. Reducing the attack surfaceThe organisation follows the principle of minimal exposure:disabling services that are not neededno unnecessary open portsseparation of development and production environmentsuse of strong authentication mechanismsrestriction of privileged accessArchitecture decisions take security aspects into account at an early stage.8. Third-party and supply chain managementTrustworthy cloud and software providers are used.Providers' security standards are reviewed on a risk basis.Active integrations are reviewed regularly.Security-relevant changes at third parties are monitored.Dependencies in the software supply chain are taken into account.9. Documentation and evidenceIdentified vulnerabilities and the measures taken are documented in order to:ensure traceabilityminimise the risk of recurrenceidentify trendsassess the effectiveness of measuresDocumentation is retained as part of the ISMS.10. Monitoring and continuous improvementThe effectiveness of vulnerability and threat handling is reviewed regularly.Findings from:security incidentsvulnerability reportsinternal reviewsfeed into improvement measures.11. ReviewThis policy is reviewed at least once a year and whenever there are significant infrastructure or architecture changes.Changes are documented with version control. This English text is a convenience translation; the German version is the authoritative one.