diff --git a/docs/policies/vulnerability_management_policy.md b/docs/policies/vulnerability_management_policy.md index f424036..2f58856 100644 --- a/docs/policies/vulnerability_management_policy.md +++ b/docs/policies/vulnerability_management_policy.md @@ -36,9 +36,9 @@ This policy is applicable to all DfE employees that produce, maintain or are res ## Responsibility The digital service teams and portfolios are responsible for ensuring they mitigate vulnerabilities within their software and infrastructure. -### Responsibile Accountable Consulted Informed (RACI) matrix +### Responsible Accountable Consulted Informed (RACI) matrix -| Tasks | CISO | SROs | Developers/DevOps | Vulnerability management team | Delivery managers (portfolio) | Architects | +| Role

Activity | CISO | SROs | Developers/DevOps | Vulnerability management team | Delivery managers (portfolio) | Architects | | ----------------------------------- | ----- | ----- | ----------------- | ----------------------------- | ----------------------------- | ---------- | | Patching Azure servers | A | A | R | C | I | C | | Patching software dependencies | A | A | R | C | I | C | @@ -235,7 +235,7 @@ The vulnerability management team: * must triage vulnerabilities from the vulnerability disclosure programme to development teams that ensures the teams can fix vulnerabilities within SLAs -## Revision history +## Revision history and decision records ### Revision table