To manage software and network vulnerabilities and protect university data and systems, Information Assurance (IA) works in partnership with units to identify vulnerabilities and ensure remediation in accordance with Vulnerability Management (DS-21) and other U-M policies (see Related Resources and Services below).
The following guidance offers a vulnerability management framework for teams that own, manage, or support university data and systems. Teams are encouraged to:
- Include required systems in the university’s enterprise vulnerability management system.
- Review vulnerability scanning reports and dashboards.
- Monitor IA alerts and follow IA recommendations.
- Remediate vulnerabilities within required timelines when remediation is available.
- Work with IA when additional risk-reduction action is needed.
Enterprise Vulnerability Management System
University-owned systems must be included in the university’s enterprise vulnerability management system unless an approved exception applies.
Tenable Vulnerability Management is currently a core component of this system. The enterprise system may also include other tools, data sources, or processes.
If a system cannot support a required component, such as the Tenable agent or an IA-approved alternative, the team must request an exception from IA through the approved process.
Vulnerability Scanning
IA university-wide monthly scans. Scans are designed to identify software vulnerabilities, missing system patches, and improper configurations. All U-M networks are scanned monthly by IA, using scanners positioned inside and outside the U-M network on alternating months.
Units enrolled in Tenable can create their own scans and will receive reports on those scans. Units have several options for scans they create, including scheduled or on-demand scans and agent scans. Units can also request assistance from IA for creating their scans or for on-demand and more frequent scans, at no charge.
Units receive full campus scan results and recommendations from IA based on the monthly scans. Units that create their own scans will also receive emailed reports of their results. Units are encouraged to use the Tenable console for a more robust view of monthly scans. Some benefits of the Tenable console include the ability to specify unique group parameters for scanning, high-level or granular views of the results, recommendations for remediation, and control of who in the unit can view the results of the scan. For more information, see Tenable Agent and Vulnerability Scanning for Units.
Units that need assistance creating scans or understanding scan results can receive assistance from IA.
See Vulnerability Scanning Capabilities for more information.
Notifications
IA may issue alerts or advisories for vulnerabilities that present a significant risk to the university. When IA provides specific remediation instructions or shorter timelines, those instructions supersede the standard timelines in this guidance.
- IA alerts units to new vulnerabilities. Teams are expected to monitor IA Advisories and Alerts and act on recommendations that apply to their systems or services. IA Alerts are published on the Alerts, Advisories & Notices page and sent via email to the appropriate IT staff groups.
- Units are expected to follow IA recommendations for addressing newly discovered vulnerabilities.
Remediation of Vulnerabilities
Units are expected to prioritize and remediate vulnerabilities within a timeframe based on the severity of the vulnerability. See Vulnerability Remediation for more information.
Units are expected to routinely update unit software and systems and apply vendor security patches after appropriate testing.
U-M IT providers, such as Information & Technology Services (ITS) and Health & Information Technology Services (HITS), are expected to remediate vulnerabilities in the services they provide and to routinely update software and systems and apply vendor security patches after appropriate testing.
Blocking and Other Risk-Reduction Actions
Systems or applications that remain unremediated past required timelines may be subject to additional risk-reduction actions when they pose a significant risk to U-M information resources. See Vulnerability Remediation for more information.
Exceptions
In limited situations, a team may be unable to meet a DS-21 requirement because of a documented technical or business limitation. In these cases, the unit must request an exception through the approved process. See Vulnerability Remediation for more information.
Support and Consultation
General vulnerability management assistance should be requested through the ITS-Network Vulnerability Scanning form. To engage with the Vulnerability Management exception process, please use the form by visiting ITS-Vulnerability Management Exception.
Teams should contact the Information Assurance Proactive team for help interpreting scan results, prioritizing remediation, understanding vulnerability priorities, requesting certain exceptions, or identifying compensating controls.
Related Resources and Services
- Information Security policy (SPG 601.27)
- Institutional Data Resource Management Policy (601.12)
- Penetration Testing
- Security of Enterprise Application Integration (DS-09)
- Security of Personally Owned Devices That Access or Maintain Sensitive University Data (SPG 601.33)
- Safely Use Sensitive Data
- Sensitive Data Discovery Scanning
- Vulnerability Management standard (DS-21)
- Web Application Security Scanning